An identity performed a suspicious download of multiple cloud storage objects
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
5 Days
Required Data
Requires one of the following data sources: AWS Audit Log OR Azure Audit Log OR Gcp Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Exfiltration, Data Detection & Response
ATT&CK Tactic
Collection (TA0009), Exfiltration (TA0010)
ATT&CK Technique
Data from Cloud Storage (T1530), Automated Exfiltration (T1020)
Severity
Informational
Description
An identity downloaded multiple objects from cloud storage. This may indicate an attacker's attempt to download sensitive data from a bucket in the cloud environment.
Attacker's Goals
Exfiltrate sensitive data from the cloud environment.
Investigative actions
Check the accessed bucket and objects designation.
Verify that the identity did not download any sensitive information that it shouldn't.
Variations
Was this helpful?
