Detection of Unauthorized Public S3 Bucket Exposure via AWS CLI
This analytic identifies potential data exfiltration risks by monitoring AWS CloudTrail logs for 'PutBucketAcl' events that grant public access to S3 buckets using the AWS CLI.
This detection focuses on identifying the creation or modification of AWS S3 bucket Access Control Lists (ACLs) that result in public exposure. By monitoring AWS CloudTrail logs for the PutBucketAcl event, the detection specifically flags instances where the userAgent indicates the use of the AWS CLI, and permissions are modified to include "AllUsers" or "AuthenticatedUsers." This behavior is often associated with either administrative oversight or malicious attempts to stage data for unauthorized exfiltration. Because public S3 buckets provide a direct vector for data breaches, this detection is critical for maintaining cloud data governance and preventing accidental or intentional exposure of sensitive assets. Security teams should use this analytic to trigger immediate investigations into the intent behind newly public buckets and ensure that only authorized services remain accessible to external entities.
Impact
Successful exploitation of misconfigured or intentionally opened S3 buckets results in the exposure of sensitive organizational data, including PII, intellectual property, or internal configuration files. Such incidents can lead to large-scale data breaches, regulatory non-compliance, and significant reputational damage. The ability to monitor these modifications in real-time is vital for limiting the window of exposure and ensuring prompt remediation of insecure cloud storage configurations.
Recommendation
Prioritize the implementation of this detection logic within your SIEM environment to gain visibility into cloud configuration changes.
- Integrate AWS CloudTrail logs using the Splunk AWS Add-on or App for AWS to enable the search logic provided in this brief.
- Review the results of the detection to distinguish between legitimate administrative configurations and unauthorized activity; apply filters for known-safe service accounts.
- Monitor the
bucketNamefield reported by the detection to immediately audit the contents of newly exposed buckets. - Investigate the
userandprincipalIdassociated with the activity to ensure that the AWS CLI caller is authorized to modify bucket permissions.
Immediate actions
Deploy the Sigma rule to monitor for public ACL modification
Mitigations
Enable S3 Block Public Access at the account or bucket level
T1530
Detection coverage 1
Detect New Open S3 Buckets over AWS CLI
mediumDetects the creation or modification of S3 bucket ACLs to allow public or authenticated user access via AWS CLI
Detection queries are available on the platform. Get full rules →