Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Collection/ T1530

T1530Data from Cloud Storage

T1530 — Data from Cloud Storage is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 18 detection use cases covering it and 6 threat-intel articles citing it.

Collection
View on the matrix → Filter Detection Library MITRE official spec ↗
18Use cases
6Articles
0Sub-techniques
1Tactic

Use cases covering this technique (18)

[WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Internal c2 · alerting DSPDD [WEEKLY] Vendor / Third-Party OAuth App or SP Sign-in From Unbaselined Egress Followed by Bulk SaaS Object Read Internal actions · alerting DSPDD Cisco ASA - Device File Copy Activity ESCU actions · hunting P Detect GCP Storage access from a new IP ESCU actions · hunting P Detect New Open GCP Storage Buckets ESCU actions · alerting P Detect New Open S3 buckets ESCU actions · alerting P Detect New Open S3 Buckets over AWS CLI ESCU actions · alerting P Detect S3 access from a new IP ESCU actions · hunting P Detect Spike in S3 Bucket deletion ESCU actions · hunting P O365 Exfiltration via File Access ESCU actions · hunting P O365 Exfiltration via File Download ESCU actions · hunting P O365 Exfiltration via File Sync Download ESCU actions · hunting P [LLM] High-volume scripted access to Tchap Matrix endpoint (bulk public-room scraping) Bespoke actions · hunting DSPDDCS [LLM] AWS CloudTrail UpdateTrail config tampering (S3 destination swap or validation disabled) Bespoke c2 · alerting DSPDDCW [LLM] praisonai-platform CVE-2026-47416: Bulk agent/issue/project/comment enumeration immediately after a workspace role-change PATCH Bespoke actions · hunting SPDD [LLM] PraisonAI Platform cross-workspace nested-resource enumeration (CVE-2026-47407 IDOR) Bespoke actions · alerting SPDDCW [LLM] GitHub audit log bulk private-repo clone burst (post Nx Console compromise pattern) Bespoke actions · alerting DSPDD [LLM] Node.js process bulk-reading cloud & SCM credential files in single session Bespoke actions · hunting DSPDDCS

Articles citing this technique (6)