Unusual AWS S3 objects deletion
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
1 Hour
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Impact (TA0040)
ATT&CK Technique
Inhibit System Recovery (T1490), Data Destruction (T1485)
Severity
Informational
Description
An identity deleted multiple S3 bucket objects from the project, considerably more than usual.
Attacker's Goals
Adversaries may delete data to prevent the recovery of a corrupted system.
They may also aim to interrupt availability to resources.
Investigative actions
Identify the deleted objects and their containing bucket.
Investigate the identity that performed the deletion and review recent related activity.
Variations
Was this helpful?
