---
title: Amazon EC2 AMI exfiltration attempt by IAM user
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > OOTB Rules > Amazon EC2 AMI exfiltration attempt by
  IAM user
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Amazon EC2 AMI exfiltration attempt by IAM user
Classification:attackTactic:[TA0010-exfiltration](https://attack.mitre.org/tactics/TA0010)Technique:[T1537-transfer-data-to-cloud-account](https://attack.mitre.org/techniques/T1537) 
## Goal{% #goal %}

Detect a user attempting to exfiltrate an Amazon EC2 AMI Snapshot.

## Strategy{% #strategy %}

This rule lets you monitor the [ModifyImageAttribute](https://docs.aws.amazon.com/AWSEC2/latest/APIReference/API_ModifyImageAttribute.html) CloudTrail API calls to detect when an Amazon EC2 AMI snapshot is made public or shared with an AWS account.

Making an AMI public is covered for calls made by an IAM user, an assumed role, a federated session, or the account root, since credential compromise most often surfaces as temporary session credentials rather than long-lived IAM user keys. Sharing an AMI with a specific AWS account remains scoped to IAM users, because automated cross-account image distribution runs almost entirely under assumed roles and would dominate that case. Calls invoked by the AWS Backup and EC2 Image Builder service principals are excluded as expected automation.

This rule also inspects:

- `@requestParameters.launchPermission.add.items.group` array to determine if the string `all` is contained. This is the indicator which means the RDS snapshot is made public.
- `@requestParameters.launchPermission.add.items.userId` array to determine if the string `*` is contained. This is the indicator which means the RDS snapshot was shared with a new or unknown AWS account.

## Triage and response{% #triage-and-response %}

1. Confirm if the user: `{{@userIdentity.arn}}` intended to make the RDS snaphsot public.
1. If the user did not make the API call:
   - Rotate the credentials.
   - Investigate if the same credentials made other unauthorized API calls.

## Changelog{% #changelog %}

- 10 August 2026 - Broadened the identity gate on `ec2_ami_made_public_by_iam_user` from `@userIdentity.type:IAMUser` to `(IAMUser OR AssumedRole OR FederatedUser OR Root)`. The exfiltration indicators are identity-agnostic, and the previous gate missed the assumed-role sessions that some credential compromises utilize. Changed `groupByFields` on both queries from `@userIdentity.userName` to `@userIdentity.arn`. CloudTrail does not populate `userIdentity.userName` for `AssumedRole`, `FederatedUser`, or unaliased `Root` identities, so the widened `made_public` case would not have produced signals without this change. For IAM users the two fields are equivalent within an account, and `@userIdentity.arn` additionally distinguishes identically named users across accounts. It is present for all four identity types and matches the triage text and the sibling rule `AWS AMI Made Public`.
