Analytics BIOC Low

An S3 replication policy to an unknown bucket was created

An S3 replication policy was added to an S3 bucket. The referenced destination bucket was not seen in your tenant in the last 30 days.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Transfer Data to Cloud Account (T1537)
Detector tags: Cloud Data Asset Exfiltration Cloud Data Asset Configuration Data Detection & Response
Attacker's goals:

Exfiltrate data to an unknown bucket.

Investigative actions:

Check the legitimacy of the referenced destination bucket. Review further logs for the source bucket. Review further actions performed by the identity.

Test period:
N/A (single event)
Deduplication:
1 Day
3 variations:
  • Unusual S3 replication policy to an unknown bucket was created Low
  • An S3 replication policy to an unknown bucket was created by an admin identity Informational (parent: Low)
  • An S3 replication policy to an unknown bucket was created - denied attempt Low