Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters.
Download CSV Show ATT&CK heatmapAWS S3 bucket was exposed to public access Low Cloud 2 variations
AWS S3 bucket was publicly shared.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Defense Evasion (TA0005)ATT&CK techniques: Impair Defenses (T1562)Required data: AWS Audit LogDetector tags: Cloud Data Asset Exfiltration, Cloud Data Asset Public Exposure, Data Detection & ResponseAttacker's goals: The attacker wants to maintain indirect control over the resource. The attacker intends to allow public access, making it harder to detect future activity. Attackers are constantly monitoring for public assets to steal sensitive information.Investigative actions: Check if the identity intended to change the state of the bucket or object to public. Review the bucket ACL policy. Restrict permissions for the identity if needed.Variations
AWS S3 bucket was exposed to public access by admin cloud identity
Informational overridden
AWS S3 bucket was publicly shared. overridden
AWS S3 bucket was exposed to public access containing sensitive information
High overridden
AWS S3 bucket was publicly shared. overridden