An S3 replication policy to an unknown bucket was created
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Exfiltration, Cloud Data Asset Configuration, Data Detection & Response
ATT&CK Tactic
Exfiltration (TA0010)
ATT&CK Technique
Transfer Data to Cloud Account (T1537)
Severity
Low
Description
An S3 replication policy was added to an S3 bucket. The referenced destination bucket was not seen in your tenant in the last 30 days.
Attacker's Goals
Exfiltrate data to an unknown bucket.
Investigative actions
Check the legitimacy of the referenced destination bucket.
Review further logs for the source bucket.
Review further actions performed by the identity.
Variations
PreviousAn RDS snapshot was exported to an unknown S3 bucket
NextAn uncommon executable was remotely written over SMB to an uncommon destination
Was this helpful?
