{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/elastic-block-store/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Amazon Web Services","Elastic Block Store"],"_cs_severities":["medium"],"_cs_tags":["cloud","exfiltration","aws","monitoring"],"_cs_type":"advisory","_cs_vendors":["Amazon"],"content_html":"\u003cp\u003eAttackers target Amazon Web Services (AWS) environments by exploiting the \u003ccode\u003eModifySnapshotAttribute\u003c/code\u003e API to change the permissions of Amazon Elastic Block Store (EBS) snapshots. By adding external AWS account IDs or setting the snapshot attribute to \u003ccode\u003egroup=all\u003c/code\u003e (making the volume public), adversaries can copy and mount sensitive data volumes within their own attacker-controlled AWS environments. This technique is often a precursor to broader data exfiltration or persistence operations, as it allows attackers to bypass account-level isolation and staging of stolen data. Since snapshots often contain critical system data or database backups, unauthorized access represents a significant risk to organizational confidentiality and regulatory compliance. Defenders should monitor CloudTrail logs for successful modifications to snapshot permissions that do not align with authorized internal replication workflows or backup automation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the unauthorized extraction of data stored within EBS volumes, which may include database contents, configuration files, and sensitive application data. Once a snapshot is shared, the data can be fully replicated to an adversary's account, resulting in a complete breach of confidentiality. Publicly exposed snapshots (\u003ccode\u003egroup=all\u003c/code\u003e) are susceptible to automated discovery by third parties, exponentially increasing the risk of data compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement monitoring for \u003ccode\u003eModifySnapshotAttribute\u003c/code\u003e API calls in CloudTrail to identify when EBS snapshots are shared with non-authorized AWS accounts or made public.\u003c/li\u003e\n\u003cli\u003eApply Service Control Policies (SCPs) organization-wide to explicitly prohibit the public sharing of EBS snapshots.\u003c/li\u003e\n\u003cli\u003eUse AWS Config rules like \u003ccode\u003eebs-snapshot-public-restorable-check\u003c/code\u003e to automatically detect and remediate publicly accessible snapshots.\u003c/li\u003e\n\u003cli\u003eRestrict the \u003ccode\u003eec2:ModifySnapshotAttribute\u003c/code\u003e IAM permission to only a limited set of administrative roles and enforce the use of Multi-Factor Authentication (MFA).\u003c/li\u003e\n\u003cli\u003eConduct regular audits of EBS snapshot permissions to identify and remove unauthorized access entries.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T19:31:59Z","date_published":"2026-09-18T19:31:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-aws-ebs-snapshot-sharing/","summary":"Adversaries may exploit the ModifySnapshotAttribute API to share Amazon EBS snapshots with external accounts or the public, facilitating data exfiltration and unauthorized access to sensitive volume data.","title":"AWS EC2 EBS Snapshot Exfiltration via ModifySnapshotAttribute","url":"https://feed.craftedsignal.io/briefs/2026-09-aws-ebs-snapshot-sharing/"}],"language":"en","title":"CraftedSignal Threat Feed - Elastic Block Store","version":"https://jsonfeed.org/version/1.1"}