CreateInstanceExportTask
CreateInstanceExportTask
Event
Starts an asynchronous VM export for an eligible instance. The destination bucket must belong to the exporting account and be in the export Region. This export path requires the documented bucket ACL setup and does not support Bucket owner enforced Object Ownership. Instance-export restrictions include encrypted EBS snapshots, instance-store mappings, and more than one virtual disk; it is not a universal multi-disk backup.
Security Context
Unauthorized export can stage collection (T1530). Export to a same-account bucket is not by itself transfer to another account. Legitimate migrations use this API, and an active task does not establish a completed object or subsequent access.
Log Source
AWS CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: CreateInstanceExportTask. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.instanceId, targetEnvironment | Instance and virtualization target; validate eligibility. |
requestParameters.exportToS3 | Bucket, prefix, disk format, and container format. |
responseElements.exportTask | Task ID and state to follow through completion. |
userIdentity, sourceIPAddress, userAgent | Caller and supporting context; not proof of malicious intent. |
eventTime, awsRegion, recipientAccountId, eventID, requestID | Timeline, scope, and correlation identifiers. |
What to Investigate
- Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
- Verify source eligibility, requested formats, and the approved migration purpose.
- Confirm destination bucket ownership, Region, ACL/Object Ownership configuration, and task outcome. A service-principal policy alone does not establish export eligibility.
- Correlate output objects and GetObject or CopyObject activity before claiming data left the account.
Sample Event
Synthetic scenario. Draco requests an export to a fictional bucket assumed to be in the exporting account. The active response does not show a finished OVA, multiple data disks, or a cross-account destination.
Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T22:55:43Z", "eventSource": "ec2.amazonaws.com", "eventName": "CreateInstanceExportTask", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "description": "Maintenance export", "instanceId": "i-0123456789abcdef0", "targetEnvironment": "vmware", "exportToS3": { "diskImageFormat": "VMDK", "containerFormat": "ova", "s3Bucket": "draco-exfil-bucket-666", "s3Prefix": "exports/" } }, "responseElements": { "requestId": "90000000-0000-4000-8000-000010001010", "exportTask": { "exportTaskId": "export-i-0123456789abcdef0", "description": "Maintenance export", "state": "active", "statusMessage": "Running", "instanceExport": { "instanceId": "i-0123456789abcdef0", "targetEnvironment": "vmware" }, "exportToS3": { "diskImageFormat": "VMDK", "containerFormat": "ova", "s3Bucket": "draco-exfil-bucket-666", "s3Key": "exports/export-i-0123456789abcdef0.ova" } } }, "requestID": "90000000-0000-4000-8000-000010001010", "eventID": "90000000-0000-4000-8000-000010001011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Collection
- T1530 — Data from Cloud Storage — Adversaries may access data from cloud storage.