Skip to content
Threat Feed

Product

S3

16 briefs RSS
low advisory

AWS S3 Rapid Bucket Posture API Calls from a Single Principal

This detection rule identifies suspicious activity in AWS environments where a single principal, from a consistent source IP, rapidly performs read-only S3 control-plane API calls across more than 15 distinct S3 buckets within a 10-second window, indicative of automated reconnaissance, security scanning, or post-compromise enumeration aiming to map S3 bucket access, policies, and versioning.

S3 +1 aws cloudtrail discovery collection reconnaissance cloud
4t
high advisory

AWS S3 Bucket Replicated to External Account for Data Exfiltration

Adversaries with write access to an AWS S3 bucket can abuse replication rules via the PutBucketReplication API call to silently exfiltrate large volumes of data to attacker-controlled accounts, bypassing object-level access controls.

S3 cloud aws exfiltration threat-detection
1r 2t
high advisory

AWS DynamoDB Table Exported to S3

Adversaries may exfiltrate sensitive data by leveraging compromised AWS credentials to perform the DynamoDB ExportTableToPointInTime operation, moving database contents into an Amazon S3 bucket, which facilitates unauthorized collection and exfiltration of information.

DynamoDB +1 aws cloud exfiltration
1r 2t
high advisory

AWS S3 Exfiltration Behavior Identified

This analytic identifies potential AWS S3 exfiltration behavior by correlating multiple risk events related to Collection and Exfiltration techniques, leveraging AWS sources and focusing on instances where multiple unique analytics and distinct MITRE ATT&CK IDs are triggered for a specific risk object.

S3 +3 cloud exfiltration aws
2r 1t
medium advisory

AWS S3 Object Versioning Suspended

Detection of S3 bucket versioning suspension via PutBucketVersioning API call, potentially indicating an attempt to inhibit system recovery by making restoration of deleted or overwritten objects impossible.

S3 aws versioning impact
2r 1t
medium advisory

AWS S3 Bucket Server Access Logging Disabled

An adversary may disable server access logging for an Amazon S3 bucket in order to impair defenses by removing logs that contain evidence of malicious activity.

S3 cloud aws defense-evasion
2r 1t
medium advisory

Potential AWS S3 Bucket Ransomware Note Upload

An adversary may upload a ransomware note to an AWS S3 bucket by abusing compromised credentials or overly permissive bucket policies, potentially leading to data encryption or exfiltration.

S3 aws ransomware impact
3r 3t
medium advisory

AWS S3 Bucket Policy Modified to Share with External Account

An attacker modifies an Amazon S3 bucket policy to grant access to an external AWS account, potentially leading to unauthorized data access and exfiltration.

S3 aws bucket_policy exfiltration
2r 3t
low advisory

AWS S3 Data Exfiltration via Uncommon Clients

Detection of AWS API activity from rare S3 client applications (S3 Browser, Cyberduck), potentially indicating unauthorized data exfiltration by threat actors.

S3 aws exfiltration cloudtrail
2r 1t
medium advisory

AWS RDS Snapshot Export to S3 for Potential Data Exfiltration

An adversary may export RDS snapshots to Amazon S3 to exfiltrate sensitive data outside of RDS-managed storage, potentially bypassing database access controls and leading to unauthorized data theft.

RDS +1 aws s3 exfiltration cloudtrail
2r 1t
high advisory

AWS S3 Bucket Replication for Data Exfiltration

An attacker enables S3 bucket replication to exfiltrate data to an external AWS account by creating a bucket replication rule.

S3 aws exfiltration bucket-replication
2r 1t
medium advisory

AWS User Performing S3 Encryption with KMS Keys

A user with KMS keys is performing encryption operations on S3 buckets, potentially masking exfiltration or tampering efforts by encrypting sensitive data to evade detection or preparing it for exfiltration.

S3 +1 aws encryption ransomware
2r 1t
high advisory

AWS S3 Exfiltration Behavior Identified via Risk Correlation

This correlation identifies potential AWS S3 exfiltration behavior by correlating multiple risk events related to Collection and Exfiltration techniques, triggered when multiple analytics and distinct MITRE ATT&CK IDs are triggered for a specific risk object, indicating a potential data exfiltration attempt.

S3 +3 aws exfiltration cloud
2r 2t
high advisory

AWS S3 Bucket Versioning Disabled

An adversary disables AWS S3 bucket versioning, preventing recovery of deleted or modified data as a potential precursor to data exfiltration or ransomware activity.

S3 aws bucket_versioning data_protection ransomware
2r 1t
medium advisory

AWS EC2 Instance Export for Potential Exfiltration

An attacker with compromised AWS credentials or EC2 instance access can leverage EC2 export functionalities (CreateInstanceExportTask, ExportImage, or CreateStoreImageTask) to exfiltrate sensitive data by exporting EC2 instances or their images to external storage.

EC2 +2 aws exfiltration cloudtrail
2r 5t
medium advisory

AWS S3 Bucket Deletion Detected via CloudTrail

An AWS S3 bucket deletion event was detected via CloudTrail logs, potentially indicating data loss or unauthorized access attempts.

S3 cloud aws data_loss
3r 1t