Analytics Informational

Unusual AWS S3 objects deletion

An identity deleted multiple S3 bucket objects from the project, considerably more than usual.

Module:
Cortex Cloud
Licensed by:
Cloud Runtime Security (CRS)
Data source:
AWS Audit Log
ATT&CK tactics: Impact (TA0040)
ATT&CK techniques: Inhibit System Recovery (T1490) Data Destruction (T1485)
Attacker's goals:

Adversaries may delete data to prevent the recovery of a corrupted system. They may also aim to interrupt availability to resources.

Investigative actions:

Identify the deleted objects and their containing bucket. Investigate the identity that performed the deletion and review recent related activity.

Test period:
1 Hour
Deduplication:
5 Days
2 variations:
  • A non administrative identity deleted multiple S3 objects from a project Low (parent: Informational)
  • An identity permanently deleted multiple S3 objects from a project Medium (parent: Informational)