An adversary may create a snapshot or data backup within a cloud account to evade defenses. A snapshot is a point-in-time copy of an existing cloud compute component such as a virtual machine (VM), virtual hard drive, or volume. An adversary may leverage permissions to create a snapshot in order to bypass restrictions that prevent access to existing compute service infrastructure, unlike in [Revert Cloud Instance](https://attack.mitre.org/techniques/T1578/004) where an adversary may revert to a snapshot to evade detection and remove evidence of their presence. An adversary may [Create Cloud Instance](https://attack.mitre.org/techniques/T1578/002), mount one or more created snapshots to that instance, and then apply a policy that allows the adversary access to the created instance, such as a firewall policy that allows them inbound and outbound SSH access.(Citation: Mandiant M-Trends 2020)

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by Detection Strategy for Modify Cloud Compute Infrastructure: Create Snapshot
is blocked by Audit
is blocked by User Account Management
is blocked by Access Restriction For Change
is blocked by Secure Baseline Configurations
is blocked by Continuous Monitoring
is blocked by Separation of Duties (SoD)
is blocked by Identification & Authentication for Organizational Users
is blocked by Identifier Management (User Names)
is blocked by Authenticator Feedback
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Vulnerability Scanning
Impressum German English