how to find public EBS snapshots in your account
Shows how to find EBS snapshots shared publicly in an AWS account before strangers copy your data. Use this when auditing account hygiene and you want to catch snapshots with public create-volume permissions. Not for sharing snapshots on purpose or for backup strategy.
TL;DR
EBS snapshots can be shared publicly, and it happens by accident more often than people think. List your snapshots, check each one's create-volume permissions for the "all" group, and make the public ones private. Run this check on a schedule because the setting drifts.
The query
how to find public EBS snapshots in your accountUse this when
- You are auditing an AWS account for accidentally exposed data
- You need a recurring check on snapshot sharing permissions
- Someone cloned a snapshot-sharing runbook wrong and you want to verify nothing is public
- Compliance asks for evidence that no snapshots are publicly shared
Not for
- Sharing snapshots intentionally with specific accounts; that is a different, legitimate flow
- Backup or disaster recovery design; this is only the sharing-permission audit
- Non-AWS clouds; the concept exists elsewhere but the commands differ
Steps
- List all snapshots you own. Use the AWS CLI describe-snapshots with owner-ids set to self and save the output. Expected output: a complete list of snapshot IDs in the account.
- Check create-volume permissions on each one. Run describe-snapshot-attribute for the createVolumePermission attribute per snapshot and look for the group "all". Expected output: each snapshot flagged as public or private.
- Make public snapshots private immediately. Run modify-snapshot-attribute to remove the "all" group from any snapshot that does not need to be shared. Expected output: re-checking shows no "all" group on the fixed snapshots.
- Check for sensitive data in ones that were public. If a snapshot was public, assume it was copied; rotate credentials and keys that lived on those volumes. Expected output: a list of rotated secrets for every snapshot that was ever public.
- Review intentional shares too. Snapshots shared with specific account IDs should still have owners and reasons documented. Expected output: every shared snapshot has a documented owner and purpose.
- Automate the scan. Run the permission check on a schedule and alert when a snapshot gains public permissions. Expected output: new public snapshots get flagged within a day of appearing.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_0Sxn3MjqL8OLWmPPadU6Fg
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.