CreateImage
CreateImage
Event
Creates an EBS-backed AMI from a running or stopped instance. Inspect block-device mappings for the included EBS volumes; it does not preserve running memory or instance-store contents. noReboot true avoids reboot but captures only written data and can leave application recovery necessary. The default permits reboot.
Security Context
Unauthorized backup creation can stage collection of sensitive data (contextual T1530). Approved backups, troubleshooting, and migrations are common. Creation alone does not transfer data to another account; identify subsequent access and handling before claiming exfiltration.
Log Source
AWS CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: CreateImage. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.instanceId, noReboot, blockDeviceMapping | Source and requested backup/image settings; exact paths are shown in the sample. |
responseElements | Returned resource ID and initial state, where present; track to completion. |
userIdentity, sourceIPAddress, userAgent | Caller and supporting context; not proof of malicious intent. |
eventTime, awsRegion, recipientAccountId, eventID, requestID | Timeline, scope, and correlation identifiers. |
What to Investigate
- Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
- Resolve the source’s owner, sensitivity, encryption, and expected backup or imaging schedule.
- Follow creation to completion and inspect the resulting resource and included storage. Do not infer contents from names.
- Correlate ModifyImageAttribute and actual recipient use; sharing and KMS permissions are separate evidence.
Sample Event
Synthetic scenario. Draco requests an AMI with noReboot true. The returned image ID does not prove readiness, stealth, external sharing, or recipient access.
Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T22:44:18Z", "eventSource": "ec2.amazonaws.com", "eventName": "CreateImage", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "instanceId": "i-0123456789abcdef0", "name": "occamy-prod-debug-666", "description": "Debug image for OCCAMY pipeline troubleshooting", "noReboot": true }, "responseElements": { "requestId": "90000000-0000-4000-8000-000010001000", "imageId": "ami-0123456789abcdef0" }, "requestID": "90000000-0000-4000-8000-000010001000", "eventID": "90000000-0000-4000-8000-000010001001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Collection
- T1530 — Data from Cloud Storage — Adversaries may access data from cloud storage.