Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Collection/ T1530

T1530Data from Cloud Storage

T1530 — Data from Cloud Storage is a MITRE ATT&CK technique in the Collection tactic. Clankerusecase tracks 15 detection use cases covering it and 3 threat-intel articles citing it.

Collection
View on the matrix → Filter Detection Library MITRE official spec ↗
15Use cases
3Articles
0Sub-techniques
1Tactic

Use cases covering this technique (15)

[WEEKLY] OAuth Device-Code Consent Phish to Cross-IP Cloud Token Replay Internal c2 · alerting DSPDD [WEEKLY] Vendor / Third-Party OAuth App or SP Sign-in From Unbaselined Egress Followed by Bulk SaaS Object Read Internal actions · alerting DSPDD Cisco ASA - Device File Copy Activity ESCU actions · hunting P Detect GCP Storage access from a new IP ESCU actions · hunting P Detect New Open GCP Storage Buckets ESCU actions · alerting P Detect New Open S3 buckets ESCU actions · alerting P Detect New Open S3 Buckets over AWS CLI ESCU actions · alerting P Detect S3 access from a new IP ESCU actions · hunting P Detect Spike in S3 Bucket deletion ESCU actions · hunting P O365 Exfiltration via File Access ESCU actions · hunting P O365 Exfiltration via File Download ESCU actions · hunting P O365 Exfiltration via File Sync Download ESCU actions · hunting P [LLM] GitHub audit log bulk private-repo clone burst (post Nx Console compromise pattern) Bespoke actions · alerting DSPDD [LLM] Node.js process bulk-reading cloud & SCM credential files in single session Bespoke actions · hunting DSPDDCS [LLM] WAF-Role mass S3 bucket enumeration and object download Bespoke actions · alerting PDDCW

Articles citing this technique (3)