Techniques
Sample rules
AWS EC2 VM Export Failure
- source: elastic
- technicques:
- T1005
- T1537
Description
Identifies an attempt to export an AWS EC2 instance. A virtual machine (VM) export may indicate an attempt to extract or exfiltrate information.
Detection logic
event.dataset:aws.cloudtrail and event.provider:ec2.amazonaws.com and event.action:CreateInstanceExportTask and event.outcome:failure