Analytics
Informational
✕
Unusual AWS S3 objects deletion
An identity deleted multiple S3 bucket objects from the project, considerably more than usual.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Inhibit System Recovery (T1490) Data Destruction (T1485)
Attacker's goals:
Adversaries may delete data to prevent the recovery of a corrupted system. They may also aim to interrupt availability to resources.
Investigative actions:
Identify the deleted objects and their containing bucket. Investigate the identity that performed the deletion and review recent related activity.
- Test period:
- 1 Hour
- Deduplication:
- 5 Days
2 variations:
- A non administrative identity deleted multiple S3 objects from a project Low (parent: Informational)
- An identity permanently deleted multiple S3 objects from a project Medium (parent: Informational)