For the complete documentation index, see llms.txt. This page is also available as Markdown.

AWS S3 bucket was exposed to public access

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

AWS Audit Log

Detection Modules

Cloud

Detector Tags

Cloud Data Asset Exfiltration, Cloud Data Asset Public Exposure, Data Detection & Response

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify Tools (T1685)

Severity

Low

Description

AWS S3 bucket was publicly shared.

Attacker's Goals

  • The attacker wants to maintain indirect control over the resource.

  • The attacker intends to allow public access, making it harder to detect future activity.

  • Attackers are constantly monitoring for public assets to steal sensitive information.

Investigative actions

  • Check if the identity intended to change the state of the bucket or object to public.

  • Review the bucket ACL policy.

  • Restrict permissions for the identity if needed.

Variations

AWS S3 bucket was exposed to public access by admin cloud identity

Synopsis

Field
Value

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify Tools (T1685)

Severity

Informational

Description

AWS S3 bucket was publicly shared.

Attacker's Goals

  • The attacker wants to maintain indirect control over the resource.

  • The attacker intends to allow public access, making it harder to detect future activity.

  • Attackers are constantly monitoring for public assets to steal sensitive information.

Investigative actions

  • Check if the identity intended to change the state of the bucket or object to public.

  • Review the bucket ACL policy.

  • Restrict permissions for the identity if needed.

AWS S3 bucket was exposed to public access containing sensitive information

Synopsis

Field
Value

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify Tools (T1685)

Severity

High

Description

AWS S3 bucket was publicly shared.

Attacker's Goals

  • The attacker wants to maintain indirect control over the resource.

  • The attacker intends to allow public access, making it harder to detect future activity.

  • Attackers are constantly monitoring for public assets to steal sensitive information.

Investigative actions

  • Check if the identity intended to change the state of the bucket or object to public.

  • Review the bucket ACL policy.

  • Restrict permissions for the identity if needed.

Was this helpful?