Product
Detection of Unauthorized AWS Backup Recovery Point Deletion
1 rule 1 TTPUnauthorized deletion of AWS Backup recovery points via the DeleteRecoveryPoint API is an anti-recovery technique used by adversaries to prevent data restoration following destructive or ransomware attacks.
Detection of AWS Backup Resource Enumeration via Long-Term Access Keys
1 rule 1 TTPAdversaries may use compromised long-term IAM access keys (AKIA* prefix) to enumerate AWS Backup vaults, plans, and protected resources as a precursor to ransomware activities.
AWS Backup Recovery Point Deletion as Anti-Recovery Tactic
1 rule 1 TTPAdversaries are leveraging the AWS Backup `DeleteRecoveryPoint` API call by non-service principals to remove critical data backups, a high-signal anti-recovery technique observed in ransomware and data-destruction attacks that prevents victims from restoring associated data.
AWS Backup Vault Deleted or Vault Lock Removed
1 rule 2 TTPsAn adversary is detected performing anti-recovery actions in AWS Backup by deleting backup vaults or removing their Vault Lock configurations via the DeleteBackupVault or DeleteBackupVaultLockConfiguration API calls, serving as a strong precursor to ransomware or data destruction, preventing organizations from restoring critical data.