SharedSnapshotVolumeCreated
SharedSnapshotVolumeCreated
Event
AWS documents this CloudTrail notification for snapshot owners monitoring use of snapshots they shared. It is an AwsServiceEvent, not a customer-callable API. Volume creation does not prove attachment, a filesystem mount, or data reads. Correlate account and snapshot evidence with the consuming account’s operation records where available.
Security Context
Unexpected external use can support a transfer-to-cloud-account investigation (T1537). Approved backup/migration consumers generate the same notification. Do not infer individual user identity, complete data extraction, or a specific source/destination schema from an illustrative service event.
Log Source
CloudTrail service notification with eventSource: ec2.amazonaws.com and eventName: SharedSnapshotVolumeCreated. Check errors and resulting resource state; a null response does not by itself indicate failure.
Key Fields
| Field | Investigation value |
|---|---|
recipientAccountId, userIdentity | Owner/consumer attribution where available; validate the actual event schema. |
serviceEventDetails | Snapshot and operation details; the minimal sample intentionally omits unverified directional fields. |
eventTime, awsRegion, recipientAccountId, eventID | Timeline, service Region, account, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Resolve the shared snapshot, its owner, authorized consumers, encryption, and ModifySnapshotAttribute history.
- Verify the consuming account and correlate the initiating copy/volume operation. Preserve exact raw serviceEventDetails; do not assume source/destination mean account IDs.
- Confirm task/resource outcome and downstream use separately; distinguish permitted consumption from malicious transfer.
Sample Event
Synthetic scenario. A minimal synthetic owner-side notification names the shared snapshot and external account. Fields whose exact schema was not established are omitted; no copy completion or host access is claimed.
Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "AWSAccount", "accountId": "555666661337", "invokedBy": "AWS Internal" }, "eventTime": "2026-04-15T20:42:18Z", "eventSource": "ec2.amazonaws.com", "eventName": "SharedSnapshotVolumeCreated", "awsRegion": "us-east-1", "sourceIPAddress": "AWS Internal", "userAgent": "AWS Internal", "serviceEventDetails": { "snapshotId": "snap-0123456789abcdef0" }, "eventID": "90000000-0000-4000-8000-000110110001", "readOnly": false, "eventType": "AwsServiceEvent", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management"}Sources
MITRE ATT&CK Mapping
Tactics: Exfiltration
- T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.