For the complete documentation index, see llms.txt. This page is also available as Markdown.

AWS data asset shared public

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

5 Days

Required Data

AWS Audit Log

Detection Modules

Cloud

Detector Tags

Cloud Data Asset Exfiltration, Data Detection & Response

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify Tools (T1685)

Severity

Low

Description

A data asset was publicly shared.

Attacker's Goals

  • The attacker wants to maintain indirect control over the resource.

  • The attacker intends to allow public access, making it harder to detect future activity.

  • Attackers are constantly monitoring for public assets to steal sensitive information.

Investigative actions

  • Check if the identity intended to change the state of the data asset to public.

  • Change the access policy for the affected asset.

  • Restrict permissions for the identity if needed.

Was this helpful?