logo

How to find Amazon S3 bucket misconfigurations and fix them ASAP

ID: 335ed805-a967-5375-b3c5-d086cca7a4f9

STIX ID: report--335ed805-a967-5375-b3c5-d086cca7a4f9

Feed Name: Expel Blog

Threat Score
35/100

Date Published: 2019-03-06

Date Updated: 2026-04-27

Author: Peter Michalski

...
...

This report describes how accidental Amazon S3 bucket misconfigurations can expose data publicly, outlines how to detect and investigate such incidents (e.g., searching for PutBucketAcl events and ACLs granting AllUsers/AuthenticatedUsers), lists four red flags to prioritize (suspicious source IP, unusual user behavior, sensitive bucket names, and excessive permissions), presents an Expel case study, and recommends mitigations such as SIEM queries, AWS Config monitoring, and operational checks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.