Skip to content

ModifySnapshotAttribute

AWS

ModifySnapshotAttribute

service: AWS - EC2
techniques:

Event

Can add or remove createVolumePermission or modify the description. Inspect the attribute and direction of change. Sharing authorizes use of a snapshot; it does not itself copy, mount, or read its contents. Encrypted snapshots cannot be public, and snapshots encrypted with the default AWS managed EBS key cannot be shared. Customer-managed-key sharing also requires suitable KMS access.

Security Context

Unauthorized external sharing can support T1537, while approved migration and recovery use the same API. A removed permission or changed description is not an exfiltration grant. Recipient ownership, encryption, and actual use determine the security outcome.

Log Source

AWS CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: ModifySnapshotAttribute. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.

Key Fields

FieldInvestigation value
requestParameters.snapshotIdSnapshot owner, source volume, encryption, and sensitivity.
requestParameters.attributeType, createVolumePermissionAttribute and added/removed account IDs or public group; casing is illustrative.
userIdentity, sourceIPAddress, userAgentCaller and supporting context; not proof of malicious intent.
eventTime, awsRegion, recipientAccountId, eventID, requestIDTimeline, scope, and correlation identifiers.

What to Investigate

  1. Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
  2. Compare permissions before and after the request, including public exposure and block-public-access controls.
  3. Verify recipient ownership and applicable customer-managed-key permissions. Do not assume a permission update alone enables decryption.
  4. Correlate recipient copy or volume-creation evidence, including SharedSnapshotVolumeCreated. Do not invent a mounted filesystem or recovered secrets.

Sample Event

Synthetic scenario. Draco adds an external account to a snapshot’s volume-creation permissions. The sample does not show encryption settings or any recipient copy, mount, or read.

Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T21:42:08Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T22:55:42Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "ModifySnapshotAttribute",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"snapshotId": "snap-0fedcba9876543210",
"attributeType": "CREATE_VOLUME_PERMISSION",
"createVolumePermission": {
"add": {
"items": [
{
"userId": "555666661337"
}
]
}
}
},
"responseElements": {
"requestId": "90000000-0000-4000-8000-000101011000",
"_return": true
},
"requestID": "90000000-0000-4000-8000-000101011000",
"eventID": "90000000-0000-4000-8000-000101011001",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Exfiltration

Techniques:
  • T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.