Product
low
advisory
Detection of Anomalous AWS DynamoDB Scan Operations
3 TTPsThis detection brief identifies potential data exfiltration or unauthorized collection by monitoring for unusual AWS DynamoDB Scan operations performed by users or roles exhibiting non-typical behavior.
DynamoDB
cloud
aws
exfiltration
detection
3t
high
advisory
AWS DynamoDB Table Exported to S3
1 rule 2 TTPsAdversaries may exfiltrate sensitive data by leveraging compromised AWS credentials to perform the DynamoDB ExportTableToPointInTime operation, moving database contents into an Amazon S3 bucket, which facilitates unauthorized collection and exfiltration of information.
DynamoDB +1
aws
cloud
exfiltration
1r
2t
low
advisory
AWS DynamoDB Scan by Unusual User
2 rules 3 TTPsDetection of unusual DynamoDB scan activity in AWS environments, potentially indicating exfiltration of sensitive information by an adversary using compromised credentials or a rogue insider.
DynamoDB
aws
exfiltration
cloudtrail
2r
3t