Cross-source coverage
T1619 / ATT&CK
Cloud Storage Object Discovery
7 rules across 3 sources.
From MITRE ATT&CK 19.2
Adversaries may enumerate objects in cloud storage infrastructure. Adversaries may use this information during automated discovery to shape follow-on behaviors, including requesting all or specific objects from cloud storage. Similar to File and Directory Discovery on a local host, after identifying available storage services (i.e. Cloud Infrastructure Discovery) adversaries may access the contents/objects stored in cloud infrastructure.
Cloud service providers offer APIs allowing users to enumerate objects stored within cloud storage. Examples include ListObjectsV2 in AWS and List Blobs in Azure.
- Tactics
- Discovery
- Platforms
- IaaS
- Telemetry
-
AWS:CloudTrail
How MITRE says to detect it DET0578
Detection Strategy for Cloud Storage Object Discovery
IaaS Analytic 1594
Detection of suspicious enumeration of cloud storage objects via API calls such as AWS S3 ListObjectsV2, Azure List Blobs, or GCP ListObjects. Correlate access with account role, user context, and prior authentication activity to identify anomalous usage patterns (e.g., unusual account, unexpected regions, or large-scale enumeration in short time windows).
AWS:CloudTrailListObjectsV2AWS:CloudTrailGetObject, CopyObject
elastic/detection-rules
5 rules| Detection | Severity | Format |
|---|---|---|
| AWS S3 Unauthenticated Bucket Access by Rare Source | Medium | Elastic TOML |
| AWS S3 Bucket Enumeration or Brute Force | Low | Elastic TOML |
| AWS S3 Rapid Bucket Posture API Calls from a Single Principal | Low | Elastic TOML |
| Azure Blob Storage Container Access Level Modified | Low | Elastic TOML |
| M365 SharePoint Search for Sensitive Content | Low | Elastic TOML |
SigmaHQ/sigma
1 rule| Detection | Severity | Format |
|---|---|---|
| Potential Bucket Enumeration on AWS | Low | Sigma |
panther-labs/panther-analysis
1 rule| Detection | Severity | Format |
|---|---|---|
| AWS S3 Access Error | Informational | Panther Python |