Threat Hunting AWS CloudTrail with Sentinel: Part 2
ID: d7964523-5001-5f15-a95a-369dfc5288a8
STIX ID: report--d7964523-5001-5f15-a95a-369dfc5288a8
Feed Name: Binary Defense Blog
**Detecting S3 Bucket Attack** — A lab simulation demonstrates exploitation of a publicly accessible, misconfigured S3 bucket (T1530) using the cloud_enum tool and AWS CLI to enumerate and exfiltrate files; an exposed file containing an Access Key ID and Secret Key provided initial foothold. The report includes CloudTrail-focused KQL hunting queries to detect ListAccessPoints, GetObject and suspicious SourceIpAddress/UserAgent activity and provides detection recommendations for SOCs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
