AWS S3 bucket was exposed to public access
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Exfiltration, Cloud Data Asset Public Exposure, Data Detection & Response
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools (T1685)
Severity
Low
Description
AWS S3 bucket was publicly shared.
Attacker's Goals
The attacker wants to maintain indirect control over the resource.
The attacker intends to allow public access, making it harder to detect future activity.
Attackers are constantly monitoring for public assets to steal sensitive information.
Investigative actions
Check if the identity intended to change the state of the bucket or object to public.
Review the bucket ACL policy.
Restrict permissions for the identity if needed.
Variations
Was this helpful?
