Analytics BIOC
Informational
✕
Foreign account was granted permissions to S3 bucket via resource-based policy
Foreign account was granted access to S3 bucket.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log
ATT&CK tactics: Exfiltration (TA0010)
ATT&CK techniques: Transfer Data to Cloud Account (T1537)
Detector tags: Cloud Data Asset Exfiltration Data Detection & Response
Attacker's goals:
The attacker wants to maintain control over the resource.
Investigative actions:
Check if the {cloud_best_identity_match} intended to modify {aws_s3bucket_identifier} policy. Check the permissions that were granted to the {aws_grantee_project}. Restrict permissions for the {aws_grantee_project} if needed.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
1 variation:
- Foreign account was granted permissions to S3 bucket containing sensitive information via resource-based policy Low (parent: Informational)