logo

Threat Hunting AWS CloudTrail with Sentinel: Part 2

ID: d7964523-5001-5f15-a95a-369dfc5288a8

STIX ID: report--d7964523-5001-5f15-a95a-369dfc5288a8

Feed Name: Binary Defense Blog

Threat Score
45/100

Date Published: 2025-08-12

Date Updated: 2026-04-27

...
...

**Detecting S3 Bucket Attack** — A lab simulation demonstrates exploitation of a publicly accessible, misconfigured S3 bucket (T1530) using the cloud_enum tool and AWS CLI to enumerate and exfiltrate files; an exposed file containing an Access Key ID and Secret Key provided initial foothold. The report includes CloudTrail-focused KQL hunting queries to detect ListAccessPoints, GetObject and suspicious SourceIpAddress/UserAgent activity and provides detection recommendations for SOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.