ModifySnapshotAttribute
ModifySnapshotAttribute
Event
Can add or remove createVolumePermission or modify the description. Inspect the attribute and direction of change. Sharing authorizes use of a snapshot; it does not itself copy, mount, or read its contents. Encrypted snapshots cannot be public, and snapshots encrypted with the default AWS managed EBS key cannot be shared. Customer-managed-key sharing also requires suitable KMS access.
Security Context
Unauthorized external sharing can support T1537, while approved migration and recovery use the same API. A removed permission or changed description is not an exfiltration grant. Recipient ownership, encryption, and actual use determine the security outcome.
Log Source
AWS CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: ModifySnapshotAttribute. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.snapshotId | Snapshot owner, source volume, encryption, and sensitivity. |
requestParameters.attributeType, createVolumePermission | Attribute and added/removed account IDs or public group; casing is illustrative. |
userIdentity, sourceIPAddress, userAgent | Caller and supporting context; not proof of malicious intent. |
eventTime, awsRegion, recipientAccountId, eventID, requestID | Timeline, scope, and correlation identifiers. |
What to Investigate
- Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
- Compare permissions before and after the request, including public exposure and block-public-access controls.
- Verify recipient ownership and applicable customer-managed-key permissions. Do not assume a permission update alone enables decryption.
- Correlate recipient copy or volume-creation evidence, including SharedSnapshotVolumeCreated. Do not invent a mounted filesystem or recovered secrets.
Sample Event
Synthetic scenario. Draco adds an external account to a snapshot’s volume-creation permissions. The sample does not show encryption settings or any recipient copy, mount, or read.
Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T21:42:08Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T22:55:42Z", "eventSource": "ec2.amazonaws.com", "eventName": "ModifySnapshotAttribute", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "snapshotId": "snap-0fedcba9876543210", "attributeType": "CREATE_VOLUME_PERMISSION", "createVolumePermission": { "add": { "items": [ { "userId": "555666661337" } ] } } }, "responseElements": { "requestId": "90000000-0000-4000-8000-000101011000", "_return": true }, "requestID": "90000000-0000-4000-8000-000101011000", "eventID": "90000000-0000-4000-8000-000101011001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Exfiltration
- T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.