AWS Storage Gateway file share enumeration
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
Cloud Infrastructure Discovery (T1580), Cloud Service Discovery (T1526)
Severity
Informational
Description
AWS Storage Gateway file shares were enumerated.
Attacker's Goals
Enumerate the organizational structure to plan lateral movement.
Investigative actions
Review recent activity related to the identity and the affected cloud environment.
Check for other enumeration activity or attempts to access sensitive resources.
Was this helpful?
