Skip to content

SharedSnapshotVolumeCreated

AWS

SharedSnapshotVolumeCreated

service: AWS - EC2
techniques:

Event

AWS documents this CloudTrail notification for snapshot owners monitoring use of snapshots they shared. It is an AwsServiceEvent, not a customer-callable API. Volume creation does not prove attachment, a filesystem mount, or data reads. Correlate account and snapshot evidence with the consuming account’s operation records where available.

Security Context

Unexpected external use can support a transfer-to-cloud-account investigation (T1537). Approved backup/migration consumers generate the same notification. Do not infer individual user identity, complete data extraction, or a specific source/destination schema from an illustrative service event.

Log Source

CloudTrail service notification with eventSource: ec2.amazonaws.com and eventName: SharedSnapshotVolumeCreated. Check errors and resulting resource state; a null response does not by itself indicate failure.

Key Fields

FieldInvestigation value
recipientAccountId, userIdentityOwner/consumer attribution where available; validate the actual event schema.
serviceEventDetailsSnapshot and operation details; the minimal sample intentionally omits unverified directional fields.
eventTime, awsRegion, recipientAccountId, eventIDTimeline, service Region, account, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Resolve the shared snapshot, its owner, authorized consumers, encryption, and ModifySnapshotAttribute history.
  3. Verify the consuming account and correlate the initiating copy/volume operation. Preserve exact raw serviceEventDetails; do not assume source/destination mean account IDs.
  4. Confirm task/resource outcome and downstream use separately; distinguish permitted consumption from malicious transfer.

Sample Event

Synthetic scenario. A minimal synthetic owner-side notification names the shared snapshot and external account. Fields whose exact schema was not established are omitted; no copy completion or host access is claimed.

Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "AWSAccount",
"accountId": "555666661337",
"invokedBy": "AWS Internal"
},
"eventTime": "2026-04-15T20:42:18Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "SharedSnapshotVolumeCreated",
"awsRegion": "us-east-1",
"sourceIPAddress": "AWS Internal",
"userAgent": "AWS Internal",
"serviceEventDetails": {
"snapshotId": "snap-0123456789abcdef0"
},
"eventID": "90000000-0000-4000-8000-000110110001",
"readOnly": false,
"eventType": "AwsServiceEvent",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management"
}

Sources

MITRE ATT&CK Mapping

Tactics: Exfiltration

Techniques:
  • T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.