CreateSnapshot
CreateSnapshot
Event
Creates an EBS snapshot asynchronously. It captures blocks written to the volume, not unflushed application or OS buffers. Encrypted source volumes produce encrypted snapshots. A pending result is not a completed recovery point.
Security Context
Unauthorized backup creation can stage collection of sensitive data (contextual T1530). Approved backups, troubleshooting, and migrations are common. Creation alone does not transfer data to another account; identify subsequent access and handling before claiming exfiltration.
Log Source
AWS CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: CreateSnapshot. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.volumeId, description | Source and requested backup/image settings; exact paths are shown in the sample. |
responseElements | Returned resource ID and initial state, where present; track to completion. |
userIdentity, sourceIPAddress, userAgent | Caller and supporting context; not proof of malicious intent. |
eventTime, awsRegion, recipientAccountId, eventID, requestID | Timeline, scope, and correlation identifiers. |
What to Investigate
- Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
- Resolve the source’s owner, sensitivity, encryption, and expected backup or imaging schedule.
- Follow creation to completion and inspect the resulting resource and included storage. Do not infer contents from names.
- Correlate ModifySnapshotAttribute and actual recipient use; sharing and KMS permissions are separate evidence.
Sample Event
Synthetic scenario. Draco requests a snapshot and the response is pending. The volume’s alleged PII contents and a later external share are not shown.
Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-16T01:05:09Z", "eventSource": "ec2.amazonaws.com", "eventName": "CreateSnapshot", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "volumeId": "vol-0123456789abcdef0", "description": "Daily Backup" }, "responseElements": { "requestId": "90000000-0000-4000-8000-000010100000", "snapshotId": "snap-0123456789abcdef0", "volumeId": "vol-0123456789abcdef0", "ownerId": "555123456789", "volumeSize": 500, "description": "Daily Backup", "encrypted": true, "kmsKeyId": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000001", "status": "pending", "startTime": "Apr 16, 2026, 1:05:09 AM", "progress": "0%" }, "requestID": "90000000-0000-4000-8000-000010100000", "eventID": "90000000-0000-4000-8000-000010100001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Collection
- T1530 — Data from Cloud Storage — Adversaries may access data from cloud storage.