Product
medium
advisory
Detecting S3 Ransomware via Cross-Account KMS Encryption
1 TTPAdversaries leverage S3 CopyObject API calls to encrypt data within victim buckets using external, attacker-controlled KMS keys, effectively denying access to the bucket owner.
S3 +3
cloud
aws
ransomware
impact
1t
updated
medium
advisory
AWS KMS Customer Managed Key Lifecycle Manipulation
1 rule 1 TTPAdversaries may disable or schedule the deletion of AWS KMS keys to sabotage business operations, render encrypted data unrecoverable, and obstruct forensic investigation or incident response efforts.
AWS Key Management Service +1
impact
cloud-security
aws-kms
incident-response
1r
1t
updated
medium
advisory
AWS KMS Key User Performing S3 Encryption
2 rules 1 TTPDetection of AWS users employing KMS keys for S3 encryption, potentially indicating suspicious data handling within cloud environments.
AWS Identity and Access Management +2
aws
kms
s3
cloud
encryption
2r
1t
high
advisory
AWS KMS Key Creation with Public Encryption Policy
2 rules 1 TTPAn attacker may create AWS KMS keys with a permissive encryption policy, granting `kms:Encrypt` permissions to all principals, potentially leading to unauthorized encryption and data compromise across multiple organizations.
AWS Key Management Service
aws
kms
encryption
misconfiguration
ransomware
2r
1t