Snapshot

A point-in-time copy of cloud volumes (files, settings, etc.) that can be created and/or deployed in cloud environments[1][2]

ID: DS0020
Platform: IaaS
Collection Layer: Cloud Control Plane
Contributors: Center for Threat-Informed Defense (CTID)
Version: 1.0
Created: 20 October 2021
Last Modified: 10 November 2021

Data Components

Snapshot: Snapshot Creation

Initial construction of a new snapshot (ex: AWS create-snapshot)

Snapshot: Snapshot Creation

Initial construction of a new snapshot (ex: AWS create-snapshot)

Domain ID Name
Enterprise T1578 Modify Cloud Compute Infrastructure
.001 Create Snapshot
Enterprise T1537 Transfer Data to Cloud Account

Snapshot: Snapshot Deletion

Removal of a snapshot (ex: AWS delete-snapshot)

Snapshot: Snapshot Deletion

Removal of a snapshot (ex: AWS delete-snapshot)

Domain ID Name
Enterprise T1485 Data Destruction
Enterprise T1578 Modify Cloud Compute Infrastructure

Snapshot: Snapshot Enumeration

An extracted list of snapshops within a cloud environment (ex: AWS describe-snapshots)

Snapshot: Snapshot Enumeration

An extracted list of snapshops within a cloud environment (ex: AWS describe-snapshots)

Domain ID Name
Enterprise T1580 Cloud Infrastructure Discovery

Snapshot: Snapshot Metadata

Contextual data about a snapshot, which may include information such as ID, type, and status

Snapshot: Snapshot Metadata

Contextual data about a snapshot, which may include information such as ID, type, and status

Domain ID Name
Enterprise T1580 Cloud Infrastructure Discovery

Snapshot: Snapshot Modification

Changes made to a snapshop, such as metadata and control data (ex: AWS modify-snapshot-attribute)

Snapshot: Snapshot Modification

Changes made to a snapshop, such as metadata and control data (ex: AWS modify-snapshot-attribute)

Domain ID Name
Enterprise T1578 Modify Cloud Compute Infrastructure
Enterprise T1537 Transfer Data to Cloud Account

References