An AWS S3 bucket configuration was modified
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Configuration, Data Detection & Response
ATT&CK Tactic
Impact (TA0040), Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools (T1685), Data Encrypted for Impact (T1486)
Severity
Informational
Description
An AWS S3 bucket configuration has been modified.
Attacker's Goals
Modify storage configuration to detection or allow access to sensitive information.
Investigative actions
Examine AWS S3 access to identify any suspicious activity.* Check which S3 buckets were affected.
PreviousAn AWS Route 53 domain was transferred to another AWS account
NextAn AWS SAML provider was modified
Was this helpful?
