Analytics BIOC Informational

Foreign account was granted permissions to S3 bucket via resource-based policy

Foreign account was granted access to S3 bucket.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Transfer Data to Cloud Account (T1537)
Detector tags: Cloud Data Asset Exfiltration Data Detection & Response
Attacker's goals:

The attacker wants to maintain control over the resource.

Investigative actions:

Check if the {cloud_best_identity_match} intended to modify {aws_s3bucket_identifier} policy. Check the permissions that were granted to the {aws_grantee_project}. Restrict permissions for the {aws_grantee_project} if needed.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Foreign account was granted permissions to S3 bucket containing sensitive information via resource-based policy Low (parent: Informational)