Cloud Storage Object Discovery T1619
Tactic: Discovery
Adversaries may enumerate objects in cloud storage infrastructure. Adversaries may use this information during automated discovery to shape follow-on behaviors, including requesting all or specific objects from cloud storage. Similar to File and Directory Discovery on a local host, after identifying available storage services (i.e. Cloud Infrastructure Discovery) adversaries may access the contents/objects stored in cloud infrastructure.
Authoring guide
These 7 rules share fields, values, and exclusions.
Fields filtered most (19 distinct)
These fields appear most often in rule filters.
Top indicator values (110 distinct)
These values appear most often in rule predicates.
Exclusions (2 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Domain: Cloud
Sigma 1 rule
Elastic 5 rules
- AWS S3 Bucket Enumeration or Brute Force
- AWS S3 Rapid Bucket Posture API Calls from a Single Principal
- AWS S3 Unauthenticated Bucket Access by Rare Source
- Azure Blob Storage Container Access Level Modified
- M365 SharePoint Search for Sensitive Content