Detecting Cloud Backup Theft: Sentinel and GuardDuty Detections
Retrospective: this article looks back at events from December 2022, written in 2026 with the benefit of hindsight.
Attackers increasingly target backups — to steal data or to delete it before ransomware. These detections watch for unusual backup access and changes.
Signals worth watching
- Access to backup storage from unfamiliar IPs, devices or identities.
- Large downloads or copies of backup data.
- Changes to backup retention, vault lock settings, soft delete or immutability policies.
- Deletion of recovery points or backup vaults.
- Privileged backup roles activated outside change windows.
Where the data lives
- AWS: CloudTrail events for AWS Backup (
DeleteRecoveryPoint,DeleteBackupVault,PutBackupVaultLockConfiguration) and S3 (GetObjecton backup buckets,PutObjectLockConfiguration). - Azure: Azure Activity logs for Recovery Services and Backup vault operations; Defender for Cloud alerts; Azure Backup alerts.
- Identity logs for administrator sign-ins.
A starting query
AWS Backup deletion and lock changes:
AWSCloudTrail
| where EventSource == "backup.amazonaws.com"
| where EventName in ("DeleteRecoveryPoint", "DeleteBackupVault", "DeleteBackupPlan",
"PutBackupVaultLockConfiguration", "DeleteBackupVaultLockConfiguration")
| project TimeGenerated, EventName, UserIdentityArn, SourceIpAddress, RequestParameters
Response
- Treat unexpected backup deletion or retention changes as a likely ransomware precursor.
- Disable the identity and investigate.
- Verify backup integrity and immutability.
- Check for other signs of ransomware staging across the environment.