Analytics Informational

AWS S3 Buckets enumeration activity

Enumeration of S3 buckets, suggesting potential cloud storage reconnaissance.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Cloud Infrastructure Discovery (T1580)
Attacker's goals:

Discover available S3 buckets in the environment. Enumerate objects within buckets to determine the type and structure of stored data. Evaluate public access configurations of buckets to identify potential exposure or misconfigurations.

Investigative actions:

Identify the identity performing the calls and determine if this behavior aligns with their typical access patterns. Check access control policies and public access settings on the enumerated buckets for misconfigurations or unauthorized access attempts.

Test period:
1 Hour
Deduplication:
1 Day