S3 configuration deletion
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Data Asset Disaster Recovery Risks, Cloud Data Asset Stealth Tactics, Cloud Data Asset Configuration, Data Detection & Response
ATT&CK Tactic
Impact (TA0040)
ATT&CK Technique
Data Encrypted for Impact (T1486)
Severity
Informational
Description
An S3 bucket configuration has been deleted. This may affect the S3 access, and the objects it contains.
Attacker's Goals
Modify the S3 configuration and expose stored sensitive data.
Investigative actions
Check what data is stored on the S3.
Check which configuration change has been made.
Verify this change did not make this S3 publicly available.
PreviousRundll32.exe spawns conhost.exe
NextSAAS - Email was reported by the user or administrator as a phishing attempt
Was this helpful?
