S3

eventNameDescriptionSampleRule
anyCatch-all entry for S3 rules that match the service but not a specific eventName.NY
CopyObjectCopies an existing S3 object to a new location within S3; logged as a CloudTrail data event.YY
DeleteAccountPublicAccessBlockRemoves the public access block configuration for an AWS account; CloudTrail eventName for the DeletePublicAccessBlock API at the account level.NY
DeleteBucketPermanently deletes an empty S3 bucket owned by the authenticated sender.YN
DeleteBucketCorsDeletes the CORS configuration from a specified S3 bucket.YY
DeleteBucketEncryptionRemoves the server-side encryption configuration from a specified S3 bucket.YY
DeleteBucketLifecycleDeletes the lifecycle configuration of a specified S3 bucket.YY
DeleteBucketPolicyDeletes the resource-based bucket policy from a specified S3 bucket.YY
DeleteBucketPublicAccessBlockRemoves the public access block configuration for an S3 bucket; CloudTrail eventName for the DeletePublicAccessBlock API at the bucket level.YY
DeleteBucketReplicationDeletes the replication configuration from a specified S3 bucket.YY
DeleteObjectRemoves an object from a specified S3 bucket.YY
GetBucketAclReturns the access control list (ACL) of an S3 bucket.YY
GetBucketCorsRetrieves the CORS configuration for a specified S3 bucket.YN
GetBucketInventoryConfigurationRetrieves an inventory configuration for a specified S3 bucket.YN
GetBucketMetricsConfigurationRetrieves a metrics configuration for a specified S3 bucket.YN
GetBucketPolicyRetrieves the resource-based bucket policy for a specified S3 bucket.YY
GetBucketPolicyStatusReturns the policy status for a specific S3 bucket, indicating whether the bucket is public.YY
GetBucketPublicAccessBlockRetrieves the public access block configuration for a specified S3 bucket.YY
GetBucketTaggingRetrieves the tag set associated with a specified S3 bucket.YN
GetBucketVersioningReturns the versioning state of an S3 bucket.YY
GetObjectRetrieves an object from a specified S3 bucket.YY
ListBucketLists the objects in a specified S3 bucket.NY
ListBucketsLists all S3 buckets owned by the authenticated requester.YY
ListObjectsLists some or all objects in a specified S3 bucket.YY
PutAccountPublicAccessBlockCreates or modifies the public access block configuration for an AWS account.NY
PutBucketAclSets the permissions on an existing S3 bucket using access control lists (ACLs).YY
PutBucketLifecycleCreates or replaces the lifecycle configuration on an S3 bucket (can be abused to expire/delete objects).YY
PutBucketLoggingSets the logging parameters for a specified S3 bucket.YY
PutBucketPolicyApplies a resource-based bucket policy to an S3 bucket.YY
PutBucketPublicAccessBlockCreates or modifies the public access block configuration for an S3 bucket.YY
PutBucketReplicationCreates or replaces the replication configuration for an S3 bucket; CloudTrail eventName for the PutReplicationConfiguration API.YY
PutBucketVersioningSets the versioning state for a specified S3 bucket.YY
PutBucketWebsiteSets the configuration of the website for a specified S3 bucket.YY
PutEncryptionConfigurationSets the default server-side encryption configuration for a specified S3 bucket.NY
PutLifecycleConfigurationCreates or replaces the lifecycle configuration for a specified S3 bucket.NY
PutObjectAdds an object to a specified S3 bucket.YY
PutReplicationConfigurationCreates or replaces the replication configuration for a specified S3 bucket.NY
ReplicateObjectReplicates an object to a destination bucket as part of a replication configuration.NY
RestoreObjectRestores a temporarily deleted or archived object in a specified S3 bucket.YY
AbortMultipartUploadThis operation aborts a multipart upload.YN
CompleteMultipartUploadCompletes a multipart upload by assembling previously uploaded parts.YN
CreateBucketThis action creates an Amazon S3 bucket.YN
CreateBucketMetadataConfigurationCreates an S3 Metadata V2 metadata configuration for a general purpose bucket.NN
CreateBucketMetadataTableConfigurationWe recommend that you create your S3 Metadata configurations by using the V2 CreateBucketMetadataConfiguration API operation.NN
CreateMultipartUploadEnd of support notice: As of October 1, 2025, Amazon S3 has discontinued support for Email Grantee Access Control Lists (ACLs).YN
CreateSessionCreates a session that establishes temporary security credentials to support fast authentication and authorization for the Zonal endpoint API operations on directory buckets.NN
DeleteBucketAnalyticsConfigurationThis operation is not supported for directory buckets.YN
DeleteBucketIntelligentTieringConfigurationThis operation is not supported for directory buckets.YN
DeleteBucketInventoryConfigurationDeletes an S3 Inventory configuration (identified by the inventory ID) from the bucket.YN
DeleteBucketMetadataConfigurationDeletes an S3 Metadata configuration from a general purpose bucket.YN
DeleteBucketMetadataTableConfigurationWe recommend that you delete your S3 Metadata configurations by using the V2 DeleteBucketMetadataTableConfiguration API operation.YN
DeleteBucketMetricsConfigurationDeletes a metrics configuration for the Amazon CloudWatch request metrics (specified by the metrics configuration ID) from the bucket.YN
DeleteBucketOwnershipControlsThis operation is not supported for directory buckets.YN
DeleteBucketTaggingThis operation is not supported for directory buckets.YN
DeleteBucketWebsiteThis operation is not supported for directory buckets.YN
DeleteObjectAnnotationDeletes a specific annotation from an Amazon S3 object.YN
DeleteObjectsThis operation enables you to delete multiple objects from a bucket using a single HTTP request.YY
DeleteObjectTaggingThis operation is not supported for directory buckets.YN
DeletePublicAccessBlockThis operation is not supported for directory buckets.NN
GetBucketAbacReturns the attribute-based access control (ABAC) property of the general purpose bucket.YN
GetBucketAccelerateConfigurationThis operation is not supported for directory buckets.YN
GetBucketAnalyticsConfigurationThis operation is not supported for directory buckets.YN
GetBucketEncryptionReturns the default encryption configuration for an Amazon S3 bucket.YN
GetBucketIntelligentTieringConfigurationThis operation is not supported for directory buckets.YN
GetBucketLifecycleFor an updated version of this API, see GetBucketLifecycleConfiguration.YN
GetBucketLocationUsing the GetBucketLocation operation is no longer a best practice.YN
GetBucketLoggingThis operation is not supported for directory buckets.YN
GetBucketMetadataConfigurationRetrieves the S3 Metadata configuration for a general purpose bucket.YN
GetBucketMetadataTableConfigurationWe recommend that you retrieve your S3 Metadata configurations by using the V2 GetBucketMetadataTableConfiguration API operation.YN
GetBucketNotificationThis operation is not supported for directory buckets.YN
GetBucketOwnershipControlsThis operation is not supported for directory buckets.YN
GetBucketReplicationThis operation is not supported for directory buckets.YN
GetBucketRequestPaymentThis operation is not supported for directory buckets.YN
GetBucketWebsiteThis operation is not supported for directory buckets.YN
GetObjectAclThis operation is not supported for directory buckets.YY
GetObjectAnnotationRetrieves an annotation from an Amazon S3 object.NN
GetObjectAttributesRetrieves all of the metadata from an object without returning the object itself.NN
GetObjectLegalHoldThis operation is not supported for directory buckets.NN
GetObjectLockConfigurationThis operation is not supported for directory buckets.YN
GetObjectRetentionThis operation is not supported for directory buckets.NN
GetObjectTaggingThis operation is not supported for directory buckets.NN
GetObjectTorrentThis operation is not supported for directory buckets.NN
HeadBucketYou can use this operation to determine if a bucket exists and if you have permission to access it.NN
HeadObjectThe HEAD operation retrieves metadata from an object without returning the object itself.NN
ListDirectoryBucketsReturns a list of all Amazon S3 directory buckets owned by the authenticated sender of the request.NN
ListMultipartUploadsThis operation lists in-progress multipart uploads in a bucket.YN
ListObjectAnnotationsLists the annotations attached to an Amazon S3 object.NN
ListObjectsV2Returns some or all (up to 1,000) of the objects in a bucket with each request.NN
ListObjectVersionsThis operation is not supported for directory buckets.NN
ListPartsLists the parts that have been uploaded for a specific multipart upload.NN
PutBucketAbacSets the attribute-based access control (ABAC) property of the general purpose bucket.YN
PutBucketAccelerateConfigurationThis operation is not supported for directory buckets.NN
PutBucketAnalyticsConfigurationThis operation is not supported for directory buckets.YN
PutBucketCorsThis operation is not supported for directory buckets.YY
PutBucketEncryptionThis operation configures default encryption and Amazon S3 Bucket Keys for an existing bucket.YN
PutBucketIntelligentTieringConfigurationThis operation is not supported for directory buckets.YN
PutBucketInventoryConfigurationThis implementation of the PUT action adds an S3 Inventory configuration (identified by the inventory ID) to the bucket.YN
PutBucketLifecycleConfigurationCreates a new lifecycle configuration for the bucket or replaces an existing lifecycle configuration.NN
PutBucketMetricsConfigurationSets a metrics configuration (specified by the metrics configuration ID) for the bucket.YN
PutBucketNotificationThis operation is not supported for directory buckets.YN
PutBucketNotificationConfigurationThis operation is not supported for directory buckets.NN
PutBucketOwnershipControlsThis operation is not supported for directory buckets.YN
PutBucketRequestPaymentThis operation is not supported for directory buckets.YN
PutBucketTaggingThis operation is not supported for directory buckets.YN
PutObjectAclEnd of support notice: As of October 1, 2025, Amazon S3 has discontinued support for Email Grantee Access Control Lists (ACLs).YY
PutObjectAnnotationAttaches an annotation to an Amazon S3 object.YN
PutObjectLegalHoldThis operation is not supported for directory buckets.NN
PutObjectLockConfigurationThis operation is not supported for directory buckets.NN
PutObjectRetentionThis operation is not supported for directory buckets.NN
PutObjectTaggingThis operation is not supported for directory buckets.YN
PutPublicAccessBlockThis operation is not supported for directory buckets.NN
RenameObjectRenames an existing object in a directory bucket that uses the S3 Express One Zone storage class.NN
SelectObjectContentThis operation is not supported for directory buckets.NN
UpdateBucketMetadataAnnotationTableConfigurationUpdates the annotation table configuration for an Amazon S3 bucket's metadata configuration.YN
UpdateBucketMetadataInventoryTableConfigurationEnables or disables a live inventory table for an S3 Metadata configuration on a general purpose bucket.YN
UpdateBucketMetadataJournalTableConfigurationEnables or disables journal table record expiration for an S3 Metadata configuration on a general purpose bucket.YN
UpdateObjectEncryptionThis operation is not supported for directory buckets or Amazon S3 on Outposts buckets.NN
UploadPartUploads a part in a multipart upload.YN
UploadPartCopyUploads a part by copying data from an existing object as data source.YN
WriteGetObjectResponseThis operation is not supported for directory buckets.NN
GetAccountPublicAccessBlockRetrieves the public access block configuration for an AWS account; CloudTrail eventName for the GetPublicAccessBlock API at the account level.YN
GetMultiRegionAccessPointGetMultiRegionAccessPoint recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetMultiRegionAccessPointPolicyGetMultiRegionAccessPointPolicy recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetMultiRegionAccessPointPolicyStatusGetMultiRegionAccessPointPolicyStatus recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetStorageLensConfigurationGetStorageLensConfiguration recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
GetStorageLensConfigurationTaggingGetStorageLensConfigurationTagging recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListAccessGrantsListAccessGrants recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListAccessGrantsInstancesListAccessGrantsInstances recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListAccessGrantsLocationsListAccessGrantsLocations recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListAccessPointsListAccessPoints recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListMultiRegionAccessPointsListMultiRegionAccessPoints recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListStorageLensConfigurationsListStorageLensConfigurations recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
ListStorageLensGroupsListStorageLensGroups recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
PutAccessPointPolicyAssociates an access policy with the specified Amazon S3 access point, replacing any existing policy.NY
AssociateAccessGrantsIdentityCenterAssociate your S3 Access Grants instance with an Amazon Web Services IAM Identity Center instance.NN
CreateAccessGrantCreates an access grant that gives a grantee access to your S3 data.NN
CreateAccessGrantsInstanceCreates an S3 Access Grants instance, which serves as a logical grouping for access grants.NN
CreateAccessGrantsLocationThe S3 data location that you would like to register in your S3 Access Grants instance.NN
CreateAccessPointCreates an access point and associates it to a specified bucket.NN
CreateAccessPointForObjectLambdaThis operation is not supported by directory buckets.NN
CreateJobThis operation creates an S3 Batch Operations job.NN
CreateMultiRegionAccessPointThis operation is not supported by directory buckets.NN
CreateStorageLensGroupCreates a new S3 Storage Lens group and associates it with the specified Amazon Web Services account ID.NN
DeleteAccessGrantDeletes the access grant from the S3 Access Grants instance.NN
DeleteAccessGrantsInstanceDeletes your S3 Access Grants instance.NN
DeleteAccessGrantsInstanceResourcePolicyDeletes the resource policy of the S3 Access Grants instance.NN
DeleteAccessGrantsLocationDeregisters a location from your S3 Access Grants instance.NN
DeleteAccessPointDeletes the specified access point.NN
DeleteAccessPointForObjectLambdaThis operation is not supported by directory buckets.NN
DeleteAccessPointPolicyDeletes the access point policy for the specified access point.NN
DeleteAccessPointPolicyForObjectLambdaThis operation is not supported by directory buckets.NN
DeleteAccessPointScopeDeletes an existing access point scope for a directory bucket.NN
DeleteBucketLifecycleConfigurationThis action deletes an Amazon S3 on Outposts bucket's lifecycle configuration.NN
DeleteJobTaggingRemoves the entire tag set from the specified S3 Batch Operations job.NN
DeleteMultiRegionAccessPointThis operation is not supported by directory buckets.NN
DeleteStorageLensConfigurationThis operation is not supported by directory buckets.NN
DeleteStorageLensConfigurationTaggingThis operation is not supported by directory buckets.NN
DeleteStorageLensGroupDeletes an existing S3 Storage Lens group.NN
DescribeJobRetrieves the configuration parameters and status for a Batch Operations job.NN
DescribeMultiRegionAccessPointOperationThis operation is not supported by directory buckets.NN
DissociateAccessGrantsIdentityCenterDissociates the Amazon Web Services IAM Identity Center instance from the S3 Access Grants instance.NN
GetAccessGrantGet the details of an access grant from your S3 Access Grants instance.NN
GetAccessGrantsInstanceRetrieves the S3 Access Grants instance for a Region in your account.NN
GetAccessGrantsInstanceForPrefixRetrieve the S3 Access Grants instance that contains a particular prefix.NN
GetAccessGrantsInstanceResourcePolicyReturns the resource policy of the S3 Access Grants instance.NN
GetAccessGrantsLocationRetrieves the details of a particular location registered in your S3 Access Grants instance.NN
GetAccessPointReturns configuration information about the specified access point.NN
GetAccessPointConfigurationForObjectLambdaThis operation is not supported by directory buckets.NN
GetAccessPointForObjectLambdaThis operation is not supported by directory buckets.NN
GetAccessPointPolicyReturns the access point policy associated with the specified access point.NN
GetAccessPointPolicyForObjectLambdaThis operation is not supported by directory buckets.NN
GetAccessPointPolicyStatusThis operation is not supported by directory buckets.NN
GetAccessPointPolicyStatusForObjectLambdaThis operation is not supported by directory buckets.NN
GetAccessPointScopeReturns the access point scope for a directory bucket.NN
GetBucketGets an Amazon S3 on Outposts bucket.NN
GetDataAccessReturns a temporary access credential from S3 Access Grants to the grantee or client application.NN
GetJobTaggingReturns the tags on an S3 Batch Operations job.NN
GetMultiRegionAccessPointRoutesThis operation is not supported by directory buckets.NN
GetStorageLensGroupRetrieves the Storage Lens group configuration details.NN
ListAccessPointsForDirectoryBucketsReturns a list of the access points that are owned by the Amazon Web Services account and that are associated with the specified directory bucket.NN
ListAccessPointsForObjectLambdaThis operation is not supported by directory buckets.NN
ListCallerAccessGrantsUse this API to list the access grants that grant the caller access to Amazon S3 data through S3 Access Grants.NN
ListJobsLists current S3 Batch Operations jobs as well as the jobs that have ended within the last 90 days for the Amazon Web Services account making the request.NN
ListRegionalBucketsThis operation is not supported by directory buckets.NN
ListTagsForResourceThis operation allows you to list all of the tags for a specified resource.NN
PutAccessGrantsInstanceResourcePolicyUpdates the resource policy of the S3 Access Grants instance.NN
PutAccessPointConfigurationForObjectLambdaThis operation is not supported by directory buckets.NN
PutAccessPointPolicyForObjectLambdaThis operation is not supported by directory buckets.NN
PutAccessPointScopeCreates or replaces the access point scope for a directory bucket.NN
PutJobTaggingSets the supplied tag-set on an S3 Batch Operations job.NN
PutMultiRegionAccessPointPolicyThis operation is not supported by directory buckets.NN
PutStorageLensConfigurationThis operation is not supported by directory buckets.NN
PutStorageLensConfigurationTaggingThis operation is not supported by directory buckets.NN
SubmitMultiRegionAccessPointRoutesThis operation is not supported by directory buckets.NN
TagResourceCreates a new user-defined tag or updates an existing tag.NN
UntagResourceThis operation removes the specified user-defined tags from an S3 resource.NN
UpdateAccessGrantsLocationUpdates the IAM role of a registered location in your S3 Access Grants instance.NN
UpdateJobPriorityUpdates an existing S3 Batch Operations job's priority.NN
UpdateJobStatusUpdates the status for the specified job.NN
UpdateStorageLensGroupUpdates the existing Storage Lens group.NN

any: S3 (catch-all)

#
Service
s3

Description

Catch-all entry for S3 rules that match the service but not a specific eventName.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS S3 Bucket Enumeration or Brute Force source low: Identifies a high number of failed S3 operations against a single bucket from a single source address within a short timeframe. This activity can indicate attempts to collect bucket objects or cause an increase in billing to an account via internal "AccessDenied" errors.T1530, T1580, T1619, T1657

CopyObject

#
Service
s3

Description

Copies an existing S3 object to a new location within S3; logged as a CloudTrail data event.

CloudTrail data event: not logged by a standard management-events trail. Requires explicit data-event configuration (an advanced event selector) on the trail or CloudTrail Lake; absence of this event does not prove the action did not occur. S3 data event. Requires S3 data-event logging. Generates events in both source and destination bucket trails (if different).

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SSEApplied": "SSE_KMS",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0.0,
    "bytesTransferredOut": 234.0,
    "x-amz-id-2": "fqzX1iZV6ImDtkFxbGvziOE6fUwryRa+PhnLckfVAkLNHdbCAHNq4l/yckUd1a2HNJPL6NAS01U="
  },
  "awsRegion": "us-west-2",
  "eventCategory": "Data",
  "eventID": "b20d43de-175d-4443-acd7-f5f3e587ae00",
  "eventName": "CopyObject",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2021-01-11T12:40:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": false,
  "readOnly": false,
  "recipientAccountId": "111111111111",
  "requestID": "6A7359F7A9414B02",
  "requestParameters": {
    "Host": "patricktestbucketencrypt.s3.us-west-2.amazonaws.com",
    "bucketName": "patricktestbucketencrypt",
    "key": "kms_aws_events_encrypted.json",
    "x-amz-copy-source": "patricktestbucketencrypt/kms_aws_events.json",
    "x-amz-server-side-encryption": "aws:kms",
    "x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1"
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::patricktestbucketencrypt/kms_aws_events_encrypted.json",
      "type": "AWS::S3::Object"
    },
    {
      "ARN": "arn:aws:s3:::patricktestbucketencrypt",
      "accountId": "111111111111",
      "type": "AWS::S3::Bucket"
    },
    {
      "ARN": "arn:aws:s3:::patricktestbucketencrypt",
      "accountId": "111111111111",
      "type": "AWS::S3::Bucket"
    },
    {
      "ARN": "arn:aws:s3:::patricktestbucketencrypt/kms_aws_events.json",
      "type": "AWS::S3::Object"
    }
  ],
  "responseElements": {
    "x-amz-server-side-encryption": "aws:kms",
    "x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1"
  },
  "sourceIPAddress": "95.90.199.65",
  "userAgent": "[aws-cli/2.0.45 Python/3.7.4 Darwin/20.2.0 exe/x86_64 command/s3.cp]",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E",
    "accountId": "111111111111",
    "arn": "arn:aws:iam::111111111111:user/patrick_cli",
    "principalId": "AIDAYTOGP2RLNALZHZ6KX",
    "type": "IAMUser",
    "userName": "patrick_cli"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws.cloudtrail.flattened.request_parameters.x-amz-server-side-encryption-customer-algorithm (elastic rule field)eqaes2562 ruleselastic
aws::sourceIPAddress (panther rule field)is_not_null1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Excessive AWS S3 Object Encryption with SSE-C source high: Identifies a high-volume of AWS S3 objects stored in a bucket using using Server-Side Encryption with Customer-Provided Keys (SSE-C). Adversaries with compromised AWS credentials can encrypt objects in an S3 bucket using their own encryption keys, rendering the objects unreadable or recoverable without the key. This can be used as a form of ransomware to extort the bucket owner for the decryption key. This is a Threshold rule that triggers when this behavior is observed multiple times for a specific bucket in a short time-window.T1486↳ also matches PutObject
  • AWS S3 Object Encryption Using External KMS Key source medium: Identifies use of the S3 CopyObject API where the destination object is encrypted using an AWS KMS key from an external AWS account. This behavior may indicate ransomware-style impact activity where an adversary with access to a misconfigured S3 bucket encrypts objects using a KMS key they control, preventing the bucket owner from decrypting their own data. This technique is a critical early signal of destructive intent or cross-account misuse.T1486
  • Unusual AWS S3 Object Encryption with SSE-C source high: Identifies when AWS S3 objects stored in a bucket are encrypted using Server-Side Encryption with Customer-Provided Keys (SSE-C). Adversaries with compromised AWS credentials can encrypt objects in an S3 bucket using their own encryption keys, rendering the objects unreadable or recoverable without the key. This can be used as a form of ransomware to extort the bucket owner for the decryption key. This is a New Terms rule that flags when this behavior is observed for the first time user and target bucket name.T1078, T1078.004, T1486↳ also matches PutObject

Splunk #

Panther #

References #

DeleteAccountPublicAccessBlock

#
Service
s3

Description

Removes the public access block configuration for an AWS account; CloudTrail eventName for the DeletePublicAccessBlock API at the account level.

CloudTrail management event, logged by default. Account-level S3 control API (s3control). Logged as a management event in the account's trail.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

Panther #

DeleteBucket

#
Service
s3

Description

Permanently deletes an empty S3 bucket owned by the authenticated sender.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:59:40Z",
  "eventSource": "s3.amazonaws.com",
  "eventName": "DeleteBucket",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "[aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#s3api.delete-bucket]",
  "requestParameters": {
    "bucketName": "dw-harn-s3-eb786637",
    "Host": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
  },
  "responseElements": null,
  "additionalEventData": {
    "SignatureVersion": "SigV4",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "bytesTransferredIn": 0,
    "AuthenticationMethod": "AuthHeader",
    "x-amz-id-2": "b+Lki7+mXZyvNK4ZjzI8HVCdrhPgCqiIQs5ySbvmYLN9ui/UdDIPpFCGFnOLB4zwKL7Q9wazW6g=",
    "bytesTransferredOut": 0
  },
  "requestID": "RDXBV8FZ46VC57G5",
  "eventID": "4a64a3bd-7ffc-4749-8684-d88e73d19d44",
  "readOnly": false,
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket",
      "ARN": "arn:aws:s3:::dw-harn-s3-eb786637"
    }
  ],
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
  }
}

DeleteBucketCors

#
Service
s3

Description

Deletes the CORS configuration from a specified S3 bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "RpNRqhkqgcK8sWz03N9lMveWojNWV5z5c1YwrpKFrVXNLEnksdy75pooJhGUKvkovApAlsArm2s="
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f5a248b7-f196-4ef8-a7e5-0668dd7166fa",
  "eventName": "DeleteBucketCors",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:08:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7Y2YA0ACYV5B12EM",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "cors": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS S3 Bucket Configuration Deletion source low: Identifies the deletion of critical Amazon S3 bucket configurations such as bucket policies, lifecycle configurations or encryption settings. These actions are typically administrative but may also represent adversarial attempts to remove security controls, disable data retention mechanisms, or conceal evidence of malicious activity. Adversaries who gain access to AWS credentials may delete logging, lifecycle, or policy configurations to disrupt forensic visibility and inhibit recovery. For example, deleting a bucket policy can open a bucket to public access or remove protective access restrictions, while deleting lifecycle rules can prevent object archival or automatic backups. Such actions often precede data exfiltration or destructive operations and should be reviewed in context with related S3 or IAM events.T1070, T1490, T1562, T1562.001, T1562.008↳ also matches DeleteBucketEncryption, DeleteBucketLifecycle, DeleteBucketPolicy, DeleteBucketReplication

Panther #

DeleteBucketEncryption

#
Service
s3

Description

Removes the server-side encryption configuration from a specified S3 bucket.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "hG2WYrbWlc/oCO+lcpulcsoZieRNMCONOypwMv9vQkS1pfqi03zvDY3IIEtDlwxlGzseOPAzq0s="
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "c0a8bd07-7b4e-4f81-aa34-67096a1f2325",
  "eventName": "DeleteBucketEncryption",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:08:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "CPH8E7CNKPWCGWFB",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "encryption": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS S3 Bucket Configuration Deletion source low: Identifies the deletion of critical Amazon S3 bucket configurations such as bucket policies, lifecycle configurations or encryption settings. These actions are typically administrative but may also represent adversarial attempts to remove security controls, disable data retention mechanisms, or conceal evidence of malicious activity. Adversaries who gain access to AWS credentials may delete logging, lifecycle, or policy configurations to disrupt forensic visibility and inhibit recovery. For example, deleting a bucket policy can open a bucket to public access or remove protective access restrictions, while deleting lifecycle rules can prevent object archival or automatic backups. Such actions often precede data exfiltration or destructive operations and should be reviewed in context with related S3 or IAM events.T1070, T1490, T1562, T1562.001, T1562.008↳ also matches DeleteBucketCors, DeleteBucketLifecycle, DeleteBucketPolicy, DeleteBucketReplication

Panther #

DeleteBucketLifecycle

#
Service
s3

Description

Deletes the lifecycle configuration of a specified S3 bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "ABu8KDu4dp2IbUOExQuYJCHxqjkkiuCoUOOIPMtnzSVZKjHOo6yF4T70mEsiFuWNKf7fkJLCPt4="
  },
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "8ec435c9-76d1-47d1-8eae-8a8864e3dff5",
  "eventName": "DeleteBucketLifecycle",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2023-07-10T12:07:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "0VTYVM320ZVNB8CM",
  "requestParameters": {
    "Host": "stratus-red-team-ctlr-bucket-zqfsvooxqj.s3.us-east-1.amazonaws.com",
    "bucketName": "stratus-red-team-ctlr-bucket-zqfsvooxqj",
    "lifecycle": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::stratus-red-team-ctlr-bucket-zqfsvooxqj",
      "accountId": "123837392027",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "stratus-red-team-ctlr-bucket-zqfsvooxqj.s3.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "[stratus-red-team_1807d824-ddbc-4a01-9249-8175115f1397]",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS S3 Bucket Configuration Deletion source low: Identifies the deletion of critical Amazon S3 bucket configurations such as bucket policies, lifecycle configurations or encryption settings. These actions are typically administrative but may also represent adversarial attempts to remove security controls, disable data retention mechanisms, or conceal evidence of malicious activity. Adversaries who gain access to AWS credentials may delete logging, lifecycle, or policy configurations to disrupt forensic visibility and inhibit recovery. For example, deleting a bucket policy can open a bucket to public access or remove protective access restrictions, while deleting lifecycle rules can prevent object archival or automatic backups. Such actions often precede data exfiltration or destructive operations and should be reviewed in context with related S3 or IAM events.T1070, T1490, T1562, T1562.001, T1562.008↳ also matches DeleteBucketCors, DeleteBucketEncryption, DeleteBucketPolicy, DeleteBucketReplication

Panther #

References #

DeleteBucketPolicy

#
Service
s3

Description

Deletes the resource-based bucket policy from a specified S3 bucket.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "ri2kYFQG4IDcZT+VgIXi/VJMZ4k7oSrx/E6+Tq4qICuZWzqo2/kFoqii+/nvMkPpYZBkPiNnPxQ="
  },
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "b921a62d-9241-42a2-bb3c-6821e55c20cd",
  "eventName": "DeleteBucketPolicy",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2023-07-10T12:28:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "Z8ACGF9H5JD4TYH9",
  "requestParameters": {
    "Host": "stratus-red-team-bdbp-lhfzvgcamn.s3.us-east-1.amazonaws.com",
    "bucketName": "stratus-red-team-bdbp-lhfzvgcamn",
    "policy": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::stratus-red-team-bdbp-lhfzvgcamn",
      "accountId": "123837392027",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "stratus-red-team-bdbp-lhfzvgcamn.s3.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "[stratus-red-team_b1d7e3ac-1a0f-40b2-b062-a4297558e42f]",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS S3 Bucket Configuration Deletion source low: Identifies the deletion of critical Amazon S3 bucket configurations such as bucket policies, lifecycle configurations or encryption settings. These actions are typically administrative but may also represent adversarial attempts to remove security controls, disable data retention mechanisms, or conceal evidence of malicious activity. Adversaries who gain access to AWS credentials may delete logging, lifecycle, or policy configurations to disrupt forensic visibility and inhibit recovery. For example, deleting a bucket policy can open a bucket to public access or remove protective access restrictions, while deleting lifecycle rules can prevent object archival or automatic backups. Such actions often precede data exfiltration or destructive operations and should be reviewed in context with related S3 or IAM events.T1070, T1490, T1562, T1562.001, T1562.008↳ also matches DeleteBucketCors, DeleteBucketEncryption, DeleteBucketLifecycle, DeleteBucketReplication

Panther #

References #

DeleteBucketPublicAccessBlock

#
Service
s3

Description

Removes the public access block configuration for an S3 bucket; CloudTrail eventName for the DeletePublicAccessBlock API at the bucket level.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 298,
    "x-amz-id-2": "piKxUz94ssEurGMC2tymwHbVLrAHmpLFxxm2/toOSt+gdXQe/cLfHZFBsbTf/nRzVky15hQMSAw="
  },
  "awsRegion": "us-west-1",
  "errorCode": "NoSuchBucket",
  "errorMessage": "The specified bucket does not exist",
  "eventCategory": "Management",
  "eventID": "fc922f9c-210d-48ba-9e45-a9023c47cde2",
  "eventName": "DeleteBucketPublicAccessBlock",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:26:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "S0YQXV8Q9GG3D4KZ",
  "requestParameters": {
    "Host": "dw-probe.s3.us-west-1.amazonaws.com",
    "bucketName": "dw-probe",
    "publicAccessBlock": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

Panther #

  • S3 Public Access Block Deleted source medium: Detects when S3 bucket public access block configuration is deleted, which could allow unauthorized public access to sensitive data or indicate preparation for data exfiltration.T1190, T1562

DeleteBucketReplication

#
Service
s3

Description

Deletes the replication configuration from a specified S3 bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 298,
    "x-amz-id-2": "Fb2rUZ+McIyCdhrL+WBN33uUnVtw8HzLWAWvA2+pISTvMhLyANwchng28q5uyEFM8Sp0oCqyFNQ="
  },
  "awsRegion": "us-west-1",
  "errorCode": "NoSuchBucket",
  "errorMessage": "The specified bucket does not exist",
  "eventCategory": "Management",
  "eventID": "a6c004af-5365-4289-96df-6da14e8b515d",
  "eventName": "DeleteBucketReplication",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:26:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "S0YXZNQP9HHA09FH",
  "requestParameters": {
    "Host": "dw-probe.s3.us-west-1.amazonaws.com",
    "bucketName": "dw-probe",
    "replication": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS S3 Bucket Configuration Deletion source low: Identifies the deletion of critical Amazon S3 bucket configurations such as bucket policies, lifecycle configurations or encryption settings. These actions are typically administrative but may also represent adversarial attempts to remove security controls, disable data retention mechanisms, or conceal evidence of malicious activity. Adversaries who gain access to AWS credentials may delete logging, lifecycle, or policy configurations to disrupt forensic visibility and inhibit recovery. For example, deleting a bucket policy can open a bucket to public access or remove protective access restrictions, while deleting lifecycle rules can prevent object archival or automatic backups. Such actions often precede data exfiltration or destructive operations and should be reviewed in context with related S3 or IAM events.T1070, T1490, T1562, T1562.001, T1562.008↳ also matches DeleteBucketCors, DeleteBucketEncryption, DeleteBucketLifecycle, DeleteBucketPolicy

Panther #

DeleteObject

#
Service
s3

Description

Removes an object from a specified S3 bucket.

CloudTrail data event: not logged by a standard management-events trail. Requires explicit data-event configuration (an advanced event selector) on the trail or CloudTrail Lake; absence of this event does not prove the action did not occur. S3 data event. Requires S3 data-event logging on the trail (advanced event selector on AWS::S3::Object).

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "ZFD39juNHPmj2SyQuQ1dAnhb1zdZ6FoQsJXsqdb/0gqdTh63T9vOMJJm8k6aEvWt2b/bvkMHncar7NPxuwHWuG6OtC9TGWuz"
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Data",
  "eventID": "72b60490-9d47-470e-ba87-5c18025cf501",
  "eventName": "DeleteObject",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:07:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": false,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7Y2X813VDT5T736Y",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "key": "dw2.txt"
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    },
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1/dw2.txt",
      "type": "AWS::S3::Object"
    }
  ],
  "responseElements": {
    "x-amz-delete-marker": "true",
    "x-amz-version-id": "tPT4tHw.vYXuNP6nw_.CmLbT6kLJd.i2"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS S3 Unauthenticated Bucket Access by Rare Source source medium: Identifies AWS CloudTrail events where an unauthenticated source is attempting to access an S3 bucket. This activity may indicate a misconfigured S3 bucket policy that allows public access to the bucket, potentially exposing sensitive data to unauthorized users. Adversaries can specify --no-sign-request in the AWS CLI to retrieve objects from an S3 bucket without authentication. This is a New Terms rule, which means it will trigger for each unique combination of the source.address and targeted bucket name that has not been seen making this API request.T1485, T1530, T1565, T1565.001, T1619↳ also matches GetObject, ListBucket, ListObjects, PutObject

Panther #

  • AWS S3 Delete Object Detection source informational: This rule detects when many objects are deleted from an S3 bucket. Such actions can be indicative of unauthorized data deletion or other suspicious activities.

GetBucketAcl

#
Service
s3

Description

Returns the access control list (ACL) of an S3 bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 552,
    "x-amz-id-2": "DHHJ5nPs/IFMD8ZnPDTj7jK2Y5p9Lbi4Llx+0k5M+ryQha+ilD7Id4HYRCj5pTQlOEQEa8kqTnAclxWPpL/E8g=="
  },
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "d9a07e9d-28ac-45d9-b8ef-43433808f2f0",
  "eventName": "GetBucketAcl",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2023-07-10T11:42:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "NDWM1TJTAVTRM8FN",
  "requestParameters": {
    "Host": "baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w.s3.us-east-1.amazonaws.com",
    "acl": "",
    "bucketName": "baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w"
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w",
      "accountId": "123837392027",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "10.248.16.43",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w.s3.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "[S3Console/0.4, aws-internal/3 aws-sdk-java/1.12.488 Linux/5.4.247-169.350.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.372-b08 java/1.8.0_372 vendor/Oracle_Corporation cfg/retry-mode/standard]",
  "userIdentity": {
    "accessKeyId": "AKIATFQZ7NSC8Q4X21BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/benjamin",
    "principalId": "AIDATFQR7NSC5U6Q3TMDR",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T11:42:31Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "benjamin"
  },
  "vpcEndpointId": "vpce-f40dc59d"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::sessionCredentialFromConsole (elastic rule field)is_null1 ruleelastic
aws::userIdentity.type (elastic rule field)neawsservice1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

GetBucketCors

#
Service
s3

Description

Retrieves the CORS configuration for a specified S3 bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 354,
    "x-amz-id-2": "4RS9BMomnioURtCQrrrpCVvsqlbvRwVkrtj4kkN93TyW1xzrSFC1sm2AVhg4d0K1dnbr/XFYCszULdYRHCV8Yw=="
  },
  "awsRegion": "us-east-1",
  "errorCode": "NoSuchCORSConfiguration",
  "errorMessage": "The CORS configuration does not exist",
  "eventCategory": "Management",
  "eventID": "61b38ec9-0b96-44c4-a90b-d5a79439503e",
  "eventName": "GetBucketCors",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2023-07-10T12:00:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "DXX0S9N6W7MF8MP2",
  "requestParameters": {
    "Host": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
    "bucketName": "stratus-red-team-ctes-bucket-qyxyekjbtk",
    "cors": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::stratus-red-team-ctes-bucket-qyxyekjbtk",
      "accountId": "123837392027",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "[APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_1d949e3e-4092-4c96-a6ef-96a967510a46 HashiCorp-terraform-exec/0.17.3]",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

GetBucketInventoryConfiguration

#
Service
s3

Description

Retrieves an inventory configuration for a specified S3 bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 189,
    "x-amz-id-2": "v7IN8HkbTsFB6SUBbWpN1+GTkZgkEQhzGKJPaYy96IDDw0Mm7onMdht6Fe+P3O/lZenVUHEcO5s="
  },
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "383842a4-cd7a-40f9-bd3a-6e414b7ae089",
  "eventName": "GetBucketInventoryConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2021-07-07T17:59:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "AC28AN05GCG4Q2EK",
  "requestParameters": {
    "Host": "s3.us-east-2.amazonaws.com",
    "bucketName": "cado-response-cados3bucketalt-1v7p4ao8z6xku",
    "inventory": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::cado-response-cados3bucketalt-1v7p4ao8z6xku",
      "accountId": "797507667711",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "213.205.197.162",
  "userAgent": "[S3Console/0.4, aws-internal/3 aws-sdk-java/1.11.1002 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.282-b08 java/1.8.0_282 vendor/Oracle_Corporation cfg/retry-mode/legacy]",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI372QWMLG4E",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  },
  "vpcEndpointId": "vpce-eca44785"
}

References #

GetBucketMetricsConfiguration

#
Service
s3

Description

Retrieves a metrics configuration for a specified S3 bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "x-amz-id-2": "DRnthuB7AtIk5kz+AOQcA8Jl9kIaFL50WiHJ5mht47H48Nygl/zTsIEEy/jqZUNZYELix2nSoRU="
  },
  "awsRegion": "us-east-1",
  "errorCode": "NoSuchBucket",
  "errorMessage": "The specified bucket does not exist",
  "eventID": "00a9c555-72c5-477d-8850-feca9b5e8b1f",
  "eventName": "GetBucketMetricsConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2020-09-21T04:28:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "5E17183CBB69805",
  "requestParameters": {
    "Host": "s3.amazonaws.com",
    "bucketName": "dummy_data",
    "id": "dummy_data",
    "metrics": ""
  },
  "responseElements": null,
  "sourceIPAddress": "9.240.250.1",
  "userAgent": "[Boto3/1.14.51 Python/3.8.5 Linux/4.19.76-linuxkit Botocore/1.17.51]",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

GetBucketPolicy

#
Service
s3

Description

Retrieves the resource-based bucket policy for a specified S3 bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 373,
    "x-amz-id-2": "f2vaS6JPTLdKw37mgdFv5DyoXG70Bhv2oYdQdYMz5rhp297ibIqaToYq/m65r+tgjYs7KnXmTAk="
  },
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "c20d93d2-87e1-483d-9c6c-9cdfc35671d4",
  "eventName": "GetBucketPolicy",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2023-07-10T11:42:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "GXK985FFMWTE90RA",
  "requestParameters": {
    "Host": "baker221b-bucketsevidenceeeedc25d-1q9cl0tuy4gbm.s3.us-east-1.amazonaws.com",
    "bucketName": "baker221b-bucketsevidenceeeedc25d-1q9cl0tuy4gbm",
    "policy": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::baker221b-bucketsevidenceeeedc25d-1q9cl0tuy4gbm",
      "accountId": "123837392027",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "10.248.16.43",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "baker221b-bucketsevidenceeeedc25d-1q9cl0tuy4gbm.s3.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "[Boto3/1.26.165 Python/3.10.6 Linux/5.19.0-46-generic Botocore/1.29.165]",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSCUXC3DDDP",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/benjamin",
    "principalId": "AIDATFQR7NSC5U6Q3TMDR",
    "type": "IAMUser",
    "userName": "benjamin"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::sessionCredentialFromConsole (elastic rule field)is_null1 ruleelastic
aws::userIdentity.type (elastic rule field)neawsservice1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

GetBucketPolicyStatus

#
Service
s3

Description

Returns the policy status for a specific S3 bucket, indicating whether the bucket is public.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 142,
    "x-amz-id-2": "nLku2A0cBs+pH6IZJ3sXVsk7KOqQVqCKmaJIjQ68P/itPODLWmR7QT0+/tKDb3YGKv90+394cTWPli6TY065Kg=="
  },
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "aeeaa143-69ff-47d3-9d62-8356f01e9a8c",
  "eventName": "GetBucketPolicyStatus",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2023-07-10T11:42:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "NDWKK8R5MVJJW7RE",
  "requestParameters": {
    "Host": "baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w.s3.us-east-1.amazonaws.com",
    "bucketName": "baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w",
    "policyStatus": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w",
      "accountId": "123837392027",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "10.248.16.43",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w.s3.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "[S3Console/0.4, aws-internal/3 aws-sdk-java/1.12.488 Linux/5.4.247-169.350.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.372-b08 java/1.8.0_372 vendor/Oracle_Corporation cfg/retry-mode/standard]",
  "userIdentity": {
    "accessKeyId": "AKIATFQZ7NSC8Q4X21BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/benjamin",
    "principalId": "AIDATFQR7NSC5U6Q3TMDR",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T11:42:31Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "benjamin"
  },
  "vpcEndpointId": "vpce-f40dc59d"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::sessionCredentialFromConsole (elastic rule field)is_null1 ruleelastic
aws::userIdentity.type (elastic rule field)neawsservice1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

GetBucketPublicAccessBlock

#
Service
s3

Description

Retrieves the public access block configuration for a specified S3 bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 326,
    "x-amz-id-2": "6YyGGLKZXYf3vfASwZOXeSfV+THvl/YamrZ0rtLHzpt4vyqnkTLB3n1KJb2VdOujH+dvCFs2gbAH0hMUI3+0tw=="
  },
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "3c856bc0-1a07-4c18-89d9-4d9205856714",
  "eventName": "GetBucketPublicAccessBlock",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2023-07-10T11:42:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "NDWZRY56ZA5P31TT",
  "requestParameters": {
    "Host": "baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w.s3.us-east-1.amazonaws.com",
    "bucketName": "baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w",
    "publicAccessBlock": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w",
      "accountId": "123837392027",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "10.248.16.43",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w.s3.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "[S3Console/0.4, aws-internal/3 aws-sdk-java/1.12.488 Linux/5.4.247-169.350.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.372-b08 java/1.8.0_372 vendor/Oracle_Corporation cfg/retry-mode/standard]",
  "userIdentity": {
    "accessKeyId": "AKIATFQZ7NSC8Q4X21BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/benjamin",
    "principalId": "AIDATFQR7NSC5U6Q3TMDR",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T11:42:31Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "benjamin"
  },
  "vpcEndpointId": "vpce-f40dc59d"
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::sessionCredentialFromConsole (elastic rule field)is_null1 ruleelastic
aws::userIdentity.type (elastic rule field)neawsservice1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

GetBucketTagging

#
Service
s3

Description

Retrieves the tag set associated with a specified S3 bucket.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:59:30Z",
  "eventSource": "s3.amazonaws.com",
  "eventName": "GetBucketTagging",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "[aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#s3api.get-bucket-tagging]",
  "requestParameters": {
    "tagging": "",
    "bucketName": "dw-harn-s3-eb786637",
    "Host": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
  },
  "responseElements": null,
  "additionalEventData": {
    "SignatureVersion": "SigV4",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "bytesTransferredIn": 0,
    "AuthenticationMethod": "AuthHeader",
    "x-amz-id-2": "furHhP/N0aS78cZ1mzEGNyn7oF8eCfdX7Q/Oo0Mp6FQVrKeQNzhK+Q6AKPlWOBPIPpGhKO8597o=",
    "bytesTransferredOut": 181
  },
  "requestID": "08G14C4WBM93E9FG",
  "eventID": "0b479541-f1f3-422d-a90f-feff14ed1fdc",
  "readOnly": true,
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket",
      "ARN": "arn:aws:s3:::dw-harn-s3-eb786637"
    }
  ],
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
  }
}

GetBucketVersioning

#
Service
s3

Description

Returns the versioning state of an S3 bucket.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:59:33Z",
  "eventSource": "s3.amazonaws.com",
  "eventName": "GetBucketVersioning",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "[aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#s3api.get-bucket-versioning]",
  "requestParameters": {
    "bucketName": "dw-harn-s3-eb786637",
    "Host": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com",
    "versioning": ""
  },
  "responseElements": null,
  "additionalEventData": {
    "SignatureVersion": "SigV4",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "bytesTransferredIn": 0,
    "AuthenticationMethod": "AuthHeader",
    "x-amz-id-2": "N5rUdQvFFRmgPL2uGlRwVbug5ETcPRAfNRBPJbtaE33DHdPl8nI1SQjy/1oSbMozMXsGUtKtBJYMtG8/IeUHGM2Wh482UaG8",
    "bytesTransferredOut": 162
  },
  "requestID": "Q1V7FCJ1Q2GYKVS3",
  "eventID": "b0784fa3-900a-4d4b-b3ec-9b5f1409ca57",
  "readOnly": true,
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket",
      "ARN": "arn:aws:s3:::dw-harn-s3-eb786637"
    }
  ],
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::sessionCredentialFromConsole (elastic rule field)is_null1 ruleelastic
aws::userIdentity.type (elastic rule field)neawsservice1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

GetObject

#
Service
s3

Description

Retrieves an object from a specified S3 bucket.

CloudTrail data event: not logged by a standard management-events trail. Requires explicit data-event configuration (an advanced event selector) on the trail or CloudTrail Lake; absence of this event does not prove the action did not occur. S3 data event. NOT logged by a standard management-events trail: you must enable S3 data-event logging (an advanced event selector on AWS::S3::Object) on the trail or CloudTrail Lake. Absence of GetObject events does NOT mean no object was read, only that data-event logging was not configured. High volume in active buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 1056,
    "x-amz-id-2": "fMMbTGYfQkr9O2R7On0/sZu0Qyz98L+f8VIkEW4VUma85VwniXUkng/yorbrfhF8a7pr5aDlwJA="
  },
  "awsRegion": "us-west-2",
  "eventCategory": "Data",
  "eventID": "806e0fbd-756b-412a-933b-01839be21e95",
  "eventName": "GetObject",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2023-04-11T01:18:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": false,
  "readOnly": true,
  "recipientAccountId": "111111111111",
  "requestID": "GVS0GF82MTWWV0GM",
  "requestParameters": {
    "Host": "security-content.s3.us-west-2.amazonaws.com",
    "bucketName": "security-content",
    "key": "stories/use_of_cleartext_protocols.yml",
    "x-amz-request-payer": "requester"
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::security-content/stories/use_of_cleartext_protocols.yml",
      "type": "AWS::S3::Object"
    },
    {
      "ARN": "arn:aws:s3:::security-content",
      "accountId": "111111111111",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "12.26.0.38",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "security-content.s3.us-west-2.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "[aws-cli/2.11.2 Python/3.11.2 Darwin/22.3.0 exe/x86_64 prompt/off command/s3.cp]",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLF5EAXXXX",
    "accountId": "111111111111",
    "arn": "arn:aws:iam::111111111111:user/console",
    "principalId": "AIDAYTOGP2RLCNEAQXWZV",
    "type": "IAMUser",
    "userName": "console"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::errorCode (kusto rule field)is_not_null1 rulekusto
aws::errorCodeis_null3 ruleskusto, panther
aws::errorMessage (kusto rule field)is_not_null1 rulekusto
aws::errorMessage (kusto rule field)is_null2 ruleskusto
aws::sourceIPAddress (panther rule field)is_not_null1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS S3 Credential File Retrieved from Bucket source medium: Detects successful S3 GetObject calls targeting high-value credential and secret files commonly stored in S3 buckets: AWS credentials files (".aws/credentials", ".aws/config"), SSH private keys ("id_rsa", "id_ed25519", "id_ecdsa", "id_dsa"), environment files (".env"), PEM and PuTTY key files, and other private key patterns. These file types are high-yield targets for credential harvesting from S3. The rule excludes AWSService identity type to suppress S3 replication, Glacier restore, and other AWS-internal data movement that legitimately reads these files.T1530, T1552, T1552.001
  • AWS S3 Unauthenticated Bucket Access by Rare Source source medium: Identifies AWS CloudTrail events where an unauthenticated source is attempting to access an S3 bucket. This activity may indicate a misconfigured S3 bucket policy that allows public access to the bucket, potentially exposing sensitive data to unauthorized users. Adversaries can specify --no-sign-request in the AWS CLI to retrieve objects from an S3 bucket without authentication. This is a New Terms rule, which means it will trigger for each unique combination of the source.address and targeted bucket name that has not been seen making this API request.T1485, T1530, T1565, T1565.001, T1619↳ also matches DeleteObject, ListBucket, ListObjects, PutObject

Splunk #

Kusto #

Panther #

  • AWS S3 Large Download source informational linked query: AWS S3 Large Download: Detects when a user (IAM User, AssumedRole, or FederatedUser) downloads more than the configured threshold of data from S3 buckets within a time window. Configurable thresholds and bucket filtering allow customization for different organizational needs. This may indicate unauthorized data exfiltration or bulk data downloads for analysis.T1537
  • AWS S3 Large Download source: Returns S3 GetObject events where a user has downloaded more than the configured threshold of data within the specified time window. Supports filtering by bucket patterns and user types.
  • S3 Access Via VPC Endpoint From External IP source medium: Detects S3 data access through VPC endpoints from external/public IP addresses, which could indicate data exfiltration attempts. This rule can be customized with the following overrides: - S3_DATA_ACCESS_OPERATIONS: List of S3 operations to monitor↳ also matches CopyObject, PutObject, DeleteObjects, GetObjectAcl, PutObjectAcl

References #

ListBucket

#
Service
s3

Description

Lists the objects in a specified S3 bucket.

CloudTrail data event: not logged by a standard management-events trail. Requires explicit data-event configuration (an advanced event selector) on the trail or CloudTrail Lake; absence of this event does not prove the action did not occur. ListBucket never appears as a CloudTrail eventName: it is the IAM permission name (s3:ListBucket) that governs object listing, and no S3 API operation carries that name. CloudTrail records bucket-object listing as the ListObjects data event. Detection rules that match eventName = ListBucket never fire; query ListObjects instead.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS S3 Unauthenticated Bucket Access by Rare Source source medium: Identifies AWS CloudTrail events where an unauthenticated source is attempting to access an S3 bucket. This activity may indicate a misconfigured S3 bucket policy that allows public access to the bucket, potentially exposing sensitive data to unauthorized users. Adversaries can specify --no-sign-request in the AWS CLI to retrieve objects from an S3 bucket without authentication. This is a New Terms rule, which means it will trigger for each unique combination of the source.address and targeted bucket name that has not been seen making this API request.T1485, T1530, T1565, T1565.001, T1619↳ also matches DeleteObject, GetObject, ListObjects, PutObject

ListBuckets

#
Service
s3

Description

Lists all S3 buckets owned by the authenticated requester.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:59:34Z",
  "eventSource": "s3.amazonaws.com",
  "eventName": "ListBuckets",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "[aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/n,Z,E,C,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#s3api.list-buckets]",
  "requestParameters": {
    "Host": "s3.us-west-1.amazonaws.com"
  },
  "responseElements": null,
  "additionalEventData": {
    "SignatureVersion": "SigV4",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "bytesTransferredIn": 0,
    "AuthenticationMethod": "AuthHeader",
    "x-amz-id-2": "NHQnVgVsQ01jR9WIB+5lsrLHd3cjCT2vR7YkwfRHNG5v9QeW2thlsxvpWslvdPKKqnrLtmrCtknbCELtiCHkpetfa1GNOdAs",
    "bytesTransferredOut": 619
  },
  "requestID": "300976TX1HKG5JCA",
  "eventID": "0b21e0da-b8ed-4104-89f8-3827bc34482d",
  "readOnly": true,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "s3.us-west-1.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • AWS Discovery API Calls from VPN ASN for the First Time by Identity source high: Flags the first time a given IAM principal invokes a narrow set of high-signal discovery APIs (credential check, account and IAM enumeration, bucket and compute inventory, logging introspection) from a source IP whose autonomous system number (ASN) matches a curated set commonly associated with consumer VPN brands, VPN-heavy hosting, and provider networks referenced in public reporting on TeamPCP activity (for example 31173 Services AB AS39351 and Oy Crea Nova Hosting Solution Ltd). Broad List*/Describe* patterns are intentionally omitted to reduce noise. Hosting ASNs are heavily dual-use; validate source.as.number in your data and extend event.action only when your baseline allows it.T1526, T1580

ListObjects

#
Service
s3

Description

Lists some or all objects in a specified S3 bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0.0,
    "bytesTransferredOut": 1350.0,
    "x-amz-id-2": "CDF4o3iABidxM7tObbdzljr2WXXJg4/T0D7FHMypp0GRb9/FGbpmEC0dT3/VSk/bJVzL2+8d2yc="
  },
  "awsRegion": "us-west-2",
  "eventCategory": "Data",
  "eventID": "0eb2f60e-de2a-4226-a209-7019880b96b4",
  "eventName": "ListObjects",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2021-04-13T17:15:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": false,
  "readOnly": true,
  "recipientAccountId": "760111141337",
  "requestID": "V2Q7GX963V7X07W8",
  "requestParameters": {
    "Host": "s3.us-west-2.amazonaws.com",
    "bucketName": "blackcert-results",
    "encoding-type": "url",
    "prefix": ""
  },
  "resources": [
    {
      "ARNPrefix": "arn:aws:s3:::blackcert-results/",
      "type": "AWS::S3::Object"
    },
    {
      "ARN": "arn:aws:s3:::blackcert-results",
      "accountId": "760111141337",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "167.172.217.29",
  "userAgent": "[aws-cli/1.14.44 Python/3.6.9 Linux/4.15.0-101-generic botocore/1.8.48]",
  "userIdentity": {
    "accessKeyId": "AKIAJ4HBMCEJQUGRUSWQ",
    "accountId": "760111141337",
    "arn": "arn:aws:iam::760111141337:user/jose_cli",
    "principalId": "AIDAJ6Q5I24S6JKLAVZDS",
    "type": "IAMUser",
    "userName": "jose_cli"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS S3 Unauthenticated Bucket Access by Rare Source source medium: Identifies AWS CloudTrail events where an unauthenticated source is attempting to access an S3 bucket. This activity may indicate a misconfigured S3 bucket policy that allows public access to the bucket, potentially exposing sensitive data to unauthorized users. Adversaries can specify --no-sign-request in the AWS CLI to retrieve objects from an S3 bucket without authentication. This is a New Terms rule, which means it will trigger for each unique combination of the source.address and targeted bucket name that has not been seen making this API request.T1485, T1530, T1565, T1565.001, T1619↳ also matches DeleteObject, GetObject, ListBucket, PutObject

References #

PutAccountPublicAccessBlock

#
Service
s3

Description

Creates or modifies the public access block configuration for an AWS account.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

PutBucketAcl

#
Service
s3

Description

Sets the permissions on an existing S3 bucket using access control lists (ACLs).

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 640,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "S8PMIlhbmqkangd8wjarKQ9cYX3NQPHTsIWtaBOmx6fY4x67RKIPZtcMDmM6Ft+LAcDBzUVnPTg="
  },
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "041673a9-6c38-4b94-859c-006cf6848cb7",
  "eventName": "PutBucketAcl",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2021-07-07T17:58:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "797507667711",
  "requestID": "CFZ8WDJ15W52Q77E",
  "requestParameters": {
    "AccessControlPolicy": {
      "AccessControlList": {
        "Grant": [
          {
            "Grantee": {
              "ID": "a6b38300126c5508f0638332394b6c926b20a00ff7165e645f4e9dc6accfceee",
              "xmlns:xsi": "http://www.w3.org/2001/XMLSchema-instance",
              "xsi:type": "CanonicalUser"
            },
            "Permission": "FULL_CONTROL"
          },
          {
            "Grantee": {
              "URI": "http://acs.amazonaws.com/groups/s3/LogDelivery",
              "xmlns:xsi": "http://www.w3.org/2001/XMLSchema-instance",
              "xsi:type": "Group"
            },
            "Permission": "FULL_CONTROL"
          }
        ]
      },
      "Owner": {
        "ID": "a6b38300126c5508f0638332394b6c926b20a00ff7165e645f4e9dc6accfceee"
      },
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "Host": "s3.us-east-2.amazonaws.com",
    "acl": "",
    "bucketName": "cado-response-cados3bucketalt-1v7p4ao8z6xku"
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::cado-response-cados3bucketalt-1v7p4ao8z6xku",
      "accountId": "797507667711",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "213.205.197.162",
  "userAgent": "[S3Console/0.4, aws-internal/3 aws-sdk-java/1.11.1002 Linux/5.4.122-66.218.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.282-b08 java/1.8.0_282 vendor/Oracle_Corporation cfg/retry-mode/legacy]",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI37VSLCHQMS",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  },
  "vpcEndpointId": "vpce-eca44785"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS S3 Bucket ACL Modified to Allow Public Access by New Identity source medium: Detects a principal modifying an S3 bucket ACL to grant public read or write access that has not been observed doing so within the history window, using canned ACLs such as public-read or public-read-write. ACL-based public access is a distinct API path (PutBucketAcl) that can bypass some Block Public Access controls. Monitoring for new identities performing this change helps surface freshly compromised credentials being used to stage data for exfiltration or inadvertently expose sensitive content.T1530

Splunk #

  • Detect New Open S3 buckets source: The following analytic identifies the creation of open/public S3 buckets in AWS. It detects this activity by analyzing AWS CloudTrail events for PutBucketAcl actions where the access control list (ACL) grants permissions to all users or…T1530
  • Detect New Open S3 Buckets over AWS CLI source: The following analytic detects the creation of open/public S3 buckets via the AWS CLI. It leverages AWS CloudTrail logs to identify events where a user has set bucket permissions to allow access to "AuthenticatedUsers" or "AllUsers." This…T1530

Kusto #

YARA-L #

Panther #

References #

PutBucketLifecycle

#
Service
s3

Description

Creates or replaces the lifecycle configuration on an S3 bucket (can be abused to expire/delete objects).

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 249,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "WLiCIIDMGhCCUp11YIClXMXz0UgUy/yxG2IjL8hJBz1omJBNImuBTSA6VSh6R7ygeDM0zBAH1b4="
  },
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "7823c70d-f7f9-4a04-b4c0-baa8fbe09ea3",
  "eventName": "PutBucketLifecycle",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2023-07-10T12:00:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "3WDNJTQG33KXSTM8",
  "requestParameters": {
    "Host": "stratus-red-team-ctlr-bucket-zqfsvooxqj.s3.us-east-1.amazonaws.com",
    "LifecycleConfiguration": {
      "Rule": {
        "Expiration": {
          "Days": 1
        },
        "Filter": {
          "Prefix": "*"
        },
        "ID": "nuke-cloudtrail-logs-after-1-day",
        "Status": "Enabled"
      },
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "bucketName": "stratus-red-team-ctlr-bucket-zqfsvooxqj",
    "lifecycle": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::stratus-red-team-ctlr-bucket-zqfsvooxqj",
      "accountId": "123837392027",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "stratus-red-team-ctlr-bucket-zqfsvooxqj.s3.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "[stratus-red-team_4990da05-9399-449e-b49f-82996a764ec9]",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
user_type (splunk rule field)eqiamuser1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS S3 Bucket Expiration Lifecycle Configuration Added source low: Identifies the addition of an expiration lifecycle configuration to an Amazon S3 bucket. S3 lifecycle rules can automatically delete or transition objects after a defined period. Adversaries can abuse them by configuring auto-deletion of logs, forensic evidence, or sensitive objects to cover their tracks. This rule detects the use of the PutBucketLifecycle or PutBucketLifecycleConfiguration APIs with Expiration parameters, which may indicate an attempt to automate the removal of data to hinder investigation or maintain operational secrecy after malicious activity.T1070, T1485, T1485.001, T1562, T1562.008

Splunk #

Panther #

References #

PutBucketLogging

#
Service
s3

Description

Sets the logging parameters for a specified S3 bucket.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "abc64d9c-f357-4f4b-966b-5bc6e2271ca3",
  "eventName": "PutBucketLogging",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2017-02-18T19:40:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "D9A3F030361A70B23",
  "requestParameters": {
    "BucketLoggingStatus": {
      "LoggingEnabled": {
        "TargetBucket": "flaws-logs",
        "TargetPrefix": "logs/flaws.cloud"
      },
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "bucketName": "flaws.cloud",
    "logging": [
      ""
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "255.253.125.115",
  "userAgent": "[S3Console/0.4]",
  "userIdentity": {
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:root",
    "principalId": "811596193553",
    "sessionContext": {
      "attributes": {
        "creationDate": "2017-02-18T19:20:48Z",
        "mfaAuthenticated": "true"
      }
    },
    "type": "Root"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
requestParameters.VersioningConfiguration.MfaDelete (panther rule field)eqDisabled1 rulepanther
requestParameters.VersioningConfiguration.Status (panther rule field)inDisabled1 rulepanther
requestParameters.VersioningConfiguration.Status (panther rule field)inSuspended1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • AWS S3 Bucket Server Access Logging Disabled source high: Identifies when server access logging is disabled for an Amazon S3 bucket. Server access logs provide a detailed record of requests made to an S3 bucket. When server access logging is disabled for a bucket, it could indicate an adversary's attempt to impair defenses by disabling logs that contain evidence of malicious activity.T1562, T1562.008

Panther #

  • S3 Bucket Logging Disabled source low: Detects when server access logging is disabled on an S3 bucket, removing audit trail capabilities that could indicate ransomware preparation activity or an attempt to evade detection.T1485, T1562
  • AWS S3 Security Control Disabling source high: Detects the disabling of 2 or more distinct S3 security controls (logging, versioning, and MFA delete protection) on the same bucket by the same actor within a short timeframe. Threshold is set to 2 rather than 3 because versioning and MFA delete can be disabled together in a single PutBucketVersioning API call, which produces only one unique value — making a threshold of 3 structurally unreachable in that scenario. This pattern is a strong indicator of preparation for ransomware or data destruction attacks, as attackers typically disable recovery mechanisms before encrypting or deleting data.T1485, T1562↳ also matches PutBucketVersioning

References #

PutBucketPolicy

#
Service
s3

Description

Applies a resource-based bucket policy to an S3 bucket.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 494,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "nYXxFQV/wJW6Q8m2FyK2HAI8cus359tlU7z9JFVzEsUpAMXvR6IOm2o/ukKHTitxkHKEsN4U/qU="
  },
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "988f1043-3e3d-4d84-803b-1b4d00e0df90",
  "eventName": "PutBucketPolicy",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2023-07-10T11:59:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "F0XQX2G7KS8GYAD2",
  "requestParameters": {
    "Host": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
    "bucketName": "stratus-red-team-ctes-bucket-qyxyekjbtk",
    "bucketPolicy": {
      "Statement": [
        {
          "Action": "s3:GetBucketAcl",
          "Effect": "Allow",
          "Principal": {
            "Service": "cloudtrail.amazonaws.com"
          },
          "Resource": "arn:aws:s3:::stratus-red-team-ctes-bucket-qyxyekjbtk",
          "Sid": "AWSCloudTrailAclCheck"
        },
        {
          "Action": "s3:PutObject",
          "Condition": {
            "StringEquals": {
              "s3:x-amz-acl": "bucket-owner-full-control"
            }
          },
          "Effect": "Allow",
          "Principal": {
            "Service": "cloudtrail.amazonaws.com"
          },
          "Resource": "arn:aws:s3:::stratus-red-team-ctes-bucket-qyxyekjbtk/*",
          "Sid": "AWSCloudTrailWrite"
        }
      ],
      "Version": "2012-10-17"
    },
    "policy": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::stratus-red-team-ctes-bucket-qyxyekjbtk",
      "accountId": "123837392027",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "[APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_1d949e3e-4092-4c96-a6ef-96a967510a46 HashiCorp-terraform-exec/0.17.3]",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::requestParameters (elastic rule field)containseffect=allow2 ruleselastic
aws::requestParameters (elastic rule field)containsprincipal=\*1 ruleelastic
Condition (kusto rule field)is_null1 rulekusto
Principal (kusto rule field)eq*1 rulekusto
Principal_aws (kusto rule field)eq*1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS S3 Bucket Policy Added to Share with External Account source medium: Detects when an Amazon S3 bucket policy is modified to share access with an external AWS account. This rule analyzes PutBucketPolicy events and compares the S3 bucket’s account ID to any account IDs referenced in the policy’s Effect=Allow statements. If the policy includes principals from accounts other than the bucket owner’s, the rule triggers an alert. This behavior may indicate an adversary backdooring a bucket for data exfiltration or cross-account persistence. For example, an attacker who compromises credentials could attach a policy allowing access from an external AWS account they control, enabling continued access even after credentials are rotated. Note: This rule will not alert if the account ID is part of the bucket’s name or appears in the resource ARN. Such cases are common in standardized naming conventions (e.g., “mybucket-123456789012”). To ensure full coverage, use complementary rules to monitor for suspicious PutBucketPolicy API requests targeting buckets with account IDs embedded in their names or resources.T1098, T1530, T1537
  • AWS S3 Bucket Policy Added to Allow Public Access source medium: Detects when an Amazon S3 bucket policy is modified to grant public access using a wildcard (Principal:"") statement. This rule analyzes PutBucketPolicy events that include both Effect=Allow and Principal:"" in the request parameters, indicating that permissions were extended to all identities, potentially making the bucket or its contents publicly accessible. Publicly exposing an S3 bucket is one of the most common causes of sensitive data leaks in AWS environments. Adversaries or misconfigurations can leverage this exposure to exfiltrate data, host malicious content, or collect credentials and logs left in open storage.T1530, T1537

Kusto #

Panther #

References #

PutBucketPublicAccessBlock

#
Service
s3

Description

Creates or modifies the public access block configuration for an S3 bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 287,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "FS8vDS7cjbByC0qmeR9OhqvhI0VU3UY///1pQvbNLPisX3wi5txQrmQYtecmgG6rid1JADKeJKA="
  },
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "a657aa02-d6ec-4b19-a028-7ed4738d494f",
  "eventName": "PutBucketPublicAccessBlock",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2021-07-07T18:17:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "797507667711",
  "requestID": "QAYF9XQRFR1XG4V6",
  "requestParameters": {
    "Host": "s3logssans.s3.us-east-2.amazonaws.com",
    "PublicAccessBlockConfiguration": {
      "BlockPublicAcls": true,
      "BlockPublicPolicy": true,
      "IgnorePublicAcls": true,
      "RestrictPublicBuckets": true,
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "bucketName": "s3logssans",
    "publicAccessBlock": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::s3logssans",
      "accountId": "797507667711",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "213.205.197.211",
  "userAgent": "[S3Console/0.4, aws-internal/3 aws-sdk-java/1.11.1002 Linux/5.4.122-66.218.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.282-b08 java/1.8.0_282 vendor/Oracle_Corporation cfg/retry-mode/legacy]",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI373B6VIGVS",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

References #

PutBucketReplication

#
Service
s3

Description

Creates or replaces the replication configuration for an S3 bucket; CloudTrail eventName for the PutReplicationConfiguration API.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 416,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "8UoliFe/sG2/v8qB2g763/g0Fy+kfaUqtKrzLHEILnHUisC3rL1dQfJ3NSIYcA/kzpIHQ955pGo="
  },
  "awsRegion": "us-west-2",
  "eventCategory": "Management",
  "eventID": "fbe079d1-bc6b-4ee0-8893-d2b412c5550f",
  "eventName": "PutBucketReplication",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2023-04-24T23:49:33Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "111111111111",
  "requestID": "14SAVMJNEJMTZN91",
  "requestParameters": {
    "Host": "s3.us-west-2.amazonaws.com",
    "ReplicationConfiguration": {
      "Role": "arn:aws:iam::111111111111:role/attack_range_bpatel",
      "Rule": {
        "DeleteMarkerReplication": {
          "Status": "Disabled"
        },
        "Destination": {
          "Bucket": "arn:aws:s3:::badpublicbuckettest"
        },
        "Filter": "",
        "ID": "replication_x_test",
        "Priority": 0,
        "Status": "Enabled"
      },
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "bucketName": "git-wild-hunt-results",
    "replication": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::git-wild-hunt-results",
      "accountId": "111111111111",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "23.93.193.6",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "s3.us-west-2.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "[S3Console/0.4, aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.238-155.347.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.362-b10 java/1.8.0_362 vendor/Oracle_Corporation cfg/retry-mode/standard]",
  "userIdentity": {
    "accessKeyId": "ASIAYTOGP2RLJOVYQHW2",
    "accountId": "111111111111",
    "arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/bpatel@splunk.com",
    "principalId": "AROAYTOGP2RLDF6WP4H11:bpatel@splunk.com",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-04-24T23:45:42Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "111111111111",
        "arn": "arn:aws:iam::111111111111:role/aws-reserved/sso.amazonaws.com/us-west-2/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f",
        "principalId": "AROAYTOGP2RLDF6WP4H11",
        "type": "Role",
        "userName": "AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  },
  "vpcEndpointId": "vpce-a0d039c9"
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS S3 Bucket Replicated to Another Account source high: Identifies the creation or modification of an S3 bucket replication configuration that sends data to a bucket in a different AWS account. Cross-account replication can be used legitimately for backup, disaster recovery, and multi-account architectures, but adversaries with write access to an S3 bucket may abuse replication rules to silently exfiltrate large volumes of data to attacker-controlled accounts. This rule detects "PutBucketReplication" events where the configured destination account differs from the source bucket's account, indicating potential unauthorized cross-account data movement.T1537, T1567, T1567.002

Splunk #

Panther #

References #

PutBucketVersioning

#
Service
s3

Description

Sets the versioning state for a specified S3 bucket.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:59:31Z",
  "eventSource": "s3.amazonaws.com",
  "eventName": "PutBucketVersioning",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "[aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/n,W,Z,E,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#s3api.put-bucket-versioning]",
  "requestParameters": {
    "bucketName": "dw-harn-s3-eb786637",
    "Host": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com",
    "versioning": "",
    "VersioningConfiguration": {
      "Status": "Enabled",
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    }
  },
  "responseElements": null,
  "additionalEventData": {
    "SignatureVersion": "SigV4",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "bytesTransferredIn": 123,
    "AuthenticationMethod": "AuthHeader",
    "x-amz-id-2": "gEG86qFly9JkUkrhMZUfGCciyRv82OHgdEuSwCCBz4WC9cITSFxr8O0eD43/ZAvA03zzw82OLZQ=",
    "bytesTransferredOut": 0
  },
  "requestID": "XK540GW32E7DK3GD",
  "eventID": "f29d4719-3236-4572-9fc5-191402d20bc3",
  "readOnly": false,
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket",
      "ARN": "arn:aws:s3:::dw-harn-s3-eb786637"
    }
  ],
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
requestParameters.VersioningConfiguration.MfaDelete (panther rule field)eqDisabled2 rulespanther
requestParameters.VersioningConfiguration.Status (panther rule field)inDisabled2 rulespanther
requestParameters.VersioningConfiguration.Status (panther rule field)inSuspended2 rulespanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • AWS S3 Object Versioning Suspended source medium: Identifies when object versioning is suspended for an Amazon S3 bucket. Object versioning allows for multiple versions of an object to exist in the same bucket. This allows for easy recovery of deleted or overwritten objects. When object versioning is suspended for a bucket, it could indicate an adversary's attempt to inhibit system recovery following malicious activity. Additionally, when versioning is suspended, buckets can then be deleted.T1490

Splunk #

  • ASL AWS Disable Bucket Versioning source: The following analytic detects when AWS S3 bucket versioning is suspended by a user. It leverages AWS CloudTrail logs to identify PutBucketVersioning events with the VersioningConfiguration.Status set to Suspended. This activity is…T1490
  • AWS Disable Bucket Versioning source: The following analytic detects when AWS S3 bucket versioning is suspended by a user. It leverages AWS CloudTrail logs to identify PutBucketVersioning events with the VersioningConfiguration.Status set to Suspended. This activity is…T1490

Panther #

  • S3 MFA Delete Disabled source low: Detects when MFA Delete is disabled on an S3 bucket, removing an important security control that prevents accidental or malicious deletion of versioned objects and could indicate ransomware preparation activity.T1485, T1562
  • S3 Bucket Versioning Suspended source low: Detects when S3 bucket versioning is suspended or disabled, which removes the ability to recover previous versions of objects and is a common precursor to ransomware attacks or data destruction.T1485, T1562
  • AWS S3 Security Control Disabling source high: Detects the disabling of 2 or more distinct S3 security controls (logging, versioning, and MFA delete protection) on the same bucket by the same actor within a short timeframe. Threshold is set to 2 rather than 3 because versioning and MFA delete can be disabled together in a single PutBucketVersioning API call, which produces only one unique value — making a threshold of 3 structurally unreachable in that scenario. This pattern is a strong indicator of preparation for ransomware or data destruction attacks, as attackers typically disable recovery mechanisms before encrypting or deleting data.T1485, T1562↳ also matches PutBucketLogging

PutBucketWebsite

#
Service
s3

Description

Sets the configuration of the website for a specified S3 bucket.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "43f300874-24b8-4780-9e2b-97667ba6aa2a",
  "eventName": "PutBucketWebsite",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2017-02-12T20:38:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "5DC5980F7FF809774",
  "requestParameters": {
    "WebsiteConfiguration": {
      "IndexDocument": {
        "Suffix": "index.html"
      },
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "bucketName": "level3-b5677c799b465420d8e7b0a6689a0bb0c4afbc9e.flaws.cloud",
    "website": [
      ""
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "255.253.125.115",
  "userAgent": "[S3Console/0.4]",
  "userIdentity": {
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:root",
    "principalId": "811596193553",
    "sessionContext": {
      "attributes": {
        "creationDate": "2017-02-12T19:57:05Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "Root"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

References #

PutEncryptionConfiguration

#
Service
s3

Description

Sets the default server-side encryption configuration for a specified S3 bucket.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

PutLifecycleConfiguration

#
Service
s3

Description

Creates or replaces the lifecycle configuration for a specified S3 bucket.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

PutObject

#
Service
s3

Description

Adds an object to a specified S3 bucket.

CloudTrail data event: not logged by a standard management-events trail. Requires explicit data-event configuration (an advanced event selector) on the trail or CloudTrail Lake; absence of this event does not prove the action did not occur. S3 data event. Requires S3 data-event logging on the trail (advanced event selector on AWS::S3::Object). High volume in active buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SSEApplied": "Default_SSE_S3",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 43,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "15HDa9GEVKlgDYna3aD/2L11PmcDEVbA7W2EXaqkjeLSWIK49Dk++hGzFOkAPn+BFc8v86Qut8mBG1BnCl9RnzsJZVzf/CCW"
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Data",
  "eventID": "684812d8-9430-4388-b6f9-54bd3dc6dab9",
  "eventName": "PutObject",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:07:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": false,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7Y2Q3EQ0WGPPKXG9",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "key": "dw.txt"
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    },
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1/dw.txt",
      "type": "AWS::S3::Object"
    }
  ],
  "responseElements": {
    "x-amz-expiration": "expiry-date=\"Thu, 30 Jul 2026 00:00:00 GMT\", rule-id=\"dw\"",
    "x-amz-server-side-encryption": "AES256",
    "x-amz-version-id": "XqF3Ks1g6Dl23X61f0Jx4ONJSggFg4Gm"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/U,Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
event.outcome (elastic rule field)eqsuccess5 ruleselastic
aws.cloudtrail.flattened.request_parameters.x-amz-server-side-encryption-customer-algorithm (elastic rule field)eqaes2562 ruleselastic
aws::sourceIPAddress (panther rule field)is_not_null1 rulepanther
aws::userIdentity.type (elastic rule field)iniamuser1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • Potential AWS S3 Bucket Ransomware Note Uploaded source medium: Identifies potential ransomware note being uploaded to an AWS S3 bucket. This rule detects the PutObject S3 API call with an object name commonly associated with ransomware notes. The keywords detected here rarely overlap with common file names and have been attributed to ransomware notes with high-confidence. Adversaries with access to a misconfigured S3 bucket may retrieve, delete, and replace objects with ransom notes to extort victims.T1485, T1486, T1565, T1565.001
  • AWS S3 Static Site JavaScript File Uploaded source high: This rule detects when a JavaScript file is uploaded in an S3 static site directory (static/js/) by an IAM user or assumed role. This can indicate suspicious modification of web content hosted on S3, such as injecting malicious scripts into a static website frontend.T1491, T1491.002, T1565, T1565.001
  • AWS S3 Unauthenticated Bucket Access by Rare Source source medium: Identifies AWS CloudTrail events where an unauthenticated source is attempting to access an S3 bucket. This activity may indicate a misconfigured S3 bucket policy that allows public access to the bucket, potentially exposing sensitive data to unauthorized users. Adversaries can specify --no-sign-request in the AWS CLI to retrieve objects from an S3 bucket without authentication. This is a New Terms rule, which means it will trigger for each unique combination of the source.address and targeted bucket name that has not been seen making this API request.T1485, T1530, T1565, T1565.001, T1619↳ also matches DeleteObject, GetObject, ListBucket, ListObjects

Kusto #

Panther #

PutReplicationConfiguration

#
Service
s3

Description

Creates or replaces the replication configuration for a specified S3 bucket.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

ReplicateObject

#
Service
s3

Description

Replicates an object to a destination bucket as part of a replication configuration.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

RestoreObject

#
Service
s3

Description

Restores a temporarily deleted or archived object in a specified S3 bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 161,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "8/tY+7hf58o12doq2mROm+tiSzGbN0PG10qTDaF4fm63uvJRjVuourkwC16GsalDIlQqpMobA68="
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Data",
  "eventID": "39fc7155-eb18-4383-9c50-8d151c9ab4fb",
  "eventName": "RestoreObject",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T20:58:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": false,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9B51PNZWBFH74MS3",
  "requestParameters": {
    "Host": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
    "RestoreRequest": {
      "Days": 1,
      "GlacierJobParameters": {
        "Tier": "Standard"
      },
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "bucketName": "dwfix-main-921c7279",
    "key": "glacier-object.txt",
    "restore": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-main-921c7279",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    },
    {
      "ARN": "arn:aws:s3:::dwfix-main-921c7279/glacier-object.txt",
      "type": "AWS::S3::Object"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,Z,U,D cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

AbortMultipartUpload

#
Service
s3

Description

This operation aborts a multipart upload.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "bqf6uKPy6MUpT45ui/nUSpvo9CIGNZGntcn0RZJ5C6+QV4ae5m1prvLoBnLFgsEvjAn1bzHn/DMDwJSPjk0lVh343lJ62MI1"
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Data",
  "eventID": "cf76a5a6-7ee8-431d-80cb-f3f7156ac6c8",
  "eventName": "AbortMultipartUpload",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:07:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": false,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7Y2TWFYB1RN8E448",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "key": "mp.txt",
    "uploadId": "vjrRU8b9IkTn.BdpAS76xpfkVVBa0mQqYz8sgwPnWhMa2DzTN3jWbTfqfJuTPBj2GanWuDpdI9CGRS9KGhHPMD17mhoeHmAffPo6EHWGnznmWp7y0zNt9x4Ja1HMh6Y5"
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    },
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1/mp.txt",
      "type": "AWS::S3::Object"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CompleteMultipartUpload

#
Service
s3

Description

Completes a multipart upload by assembling previously uploaded parts.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 271,
    "bytesTransferredOut": 442,
    "x-amz-id-2": "yCnpCd+16KzCfNSBD8uE2Non0GMOm/0oBBQkAnUL5NI3Ik0CesRRxEuWcwxUvtJz2beydLTB0vE="
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Data",
  "eventID": "8dd6386d-48cc-41c3-ad8e-3e2c1fe0499c",
  "eventName": "CompleteMultipartUpload",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T20:58:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": false,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "794PXSXQNVC8VYPB",
  "requestParameters": {
    "CompleteMultipartUpload": {
      "Part": [
        {
          "ETag": "\"4f08eef4096726bff1125e1b1b734644\"",
          "PartNumber": 1
        },
        {
          "ETag": "\"5eb63bbbe01eeed093cb22bb8f5acdc3\"",
          "PartNumber": 2
        }
      ],
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "Host": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
    "bucketName": "dwfix-main-921c7279",
    "key": "mpu-object.txt",
    "uploadId": "adI6a0ON5uIMbksUQjUaQDIyquNC_OPDf7eor8NZkSLr0WAKY.L8Blodil..WUaqF3ZciTtepqPeWerPn1q1CC5YZlnZExQeW.JfIRqg2yd9lO07ZmIU.f0TfMFZh3.F"
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-main-921c7279",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    },
    {
      "ARN": "arn:aws:s3:::dwfix-main-921c7279/mpu-object.txt",
      "type": "AWS::S3::Object"
    }
  ],
  "responseElements": {
    "x-amz-expiration": "expiry-date=\"Wed, 01 Jul 2026 00:00:00 GMT\", rule-id=\"dwfix-expire\"",
    "x-amz-server-side-encryption": "AES256"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateBucket

#
Service
s3

Description

This action creates an Amazon S3 bucket.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:59:24Z",
  "eventSource": "s3.amazonaws.com",
  "eventName": "CreateBucket",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "[aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#s3api.create-bucket]",
  "requestParameters": {
    "CreateBucketConfiguration": {
      "LocationConstraint": "us-west-1",
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "bucketName": "dw-harn-s3-eb786637",
    "Host": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
  },
  "responseElements": null,
  "additionalEventData": {
    "SignatureVersion": "SigV4",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "bytesTransferredIn": 153,
    "AuthenticationMethod": "AuthHeader",
    "x-amz-id-2": "OUmTxv7dGAXNvcHPAfgAqqxqrMbrr55zjZlQAp2Ja6+X/73Y6xFgv8DBlKZodqgKax7VaDf6/2DIAiimCS3M5aGb8eYm3zU+",
    "bytesTransferredOut": 0
  },
  "requestID": "P3TPCVWXT4CM673R",
  "eventID": "6449085a-0a89-41cd-9102-8981d350de44",
  "readOnly": false,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
  }
}

CreateBucketMetadataConfiguration

#
Service
s3

Description

Creates an S3 Metadata V2 metadata configuration for a general purpose bucket.

CreateBucketMetadataTableConfiguration

#
Service
s3

Description

We recommend that you create your S3 Metadata configurations by using the V2 CreateBucketMetadataConfiguration API operation.

CreateMultipartUpload

#
Service
s3

Description

End of support notice: As of October 1, 2025, Amazon S3 has discontinued support for Email Grantee Access Control Lists (ACLs).

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SSEApplied": "Default_SSE_S3",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 358,
    "x-amz-id-2": "yhDDl31+cAMDRVhh5UKqrv3/tQDsDmYXYMvKWP6UAl8Amur9AXiChW9rjNv60k5Ef3yQCt+V8/vVIOdk7gCFKJEqZiNhoq6q"
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Data",
  "eventID": "8afbdeaa-8adb-489c-aef9-9acda10c6a59",
  "eventName": "CreateMultipartUpload",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:07:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": false,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7Y2NZSCVBM6AY99A",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "key": "mp.txt",
    "uploads": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    },
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1/mp.txt",
      "type": "AWS::S3::Object"
    }
  ],
  "responseElements": {
    "x-amz-server-side-encryption": "AES256"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateSession

#
Service
s3

Description

Creates a session that establishes temporary security credentials to support fast authentication and authorization for the Zonal endpoint API operations on directory buckets.

DeleteBucketAnalyticsConfiguration

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "M+Xb8JVl4T2/TACp1wrJrtWXScelhegFp74Yd0K73j03RqtRUnZtYyge9T/tmXyzwmlazGBrTb8="
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "a6b20e8b-0f12-4080-a924-ef4abb34c33a",
  "eventName": "DeleteBucketAnalyticsConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:08:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "CPH5GH9B5C74S5GV",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "analytics": "",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "id": "dw"
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteBucketIntelligentTieringConfiguration

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "PMD0B72+Ka69VbrfgNJRo2VpzwSOQVAamS2eGq+9QcxWVHuLOUwmK5qQ25VO3q4QunvvhmQ+7+g="
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "47074cc9-7b90-47e9-a01f-106b9a652e85",
  "eventName": "DeleteBucketIntelligentTieringConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:08:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "MDB1N7DS3WTQ7FFH",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "id": "dw",
    "intelligent-tiering": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteBucketInventoryConfiguration

#
Service
s3

Description

Deletes an S3 Inventory configuration (identified by the inventory ID) from the bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 298,
    "x-amz-id-2": "HGRJEd1EGs7zw5luD+DE/2TdGZjGfVIwt3/RMS5rO578PuCaLYWlhq6xf+RoeB5r8lxb01pAZf0="
  },
  "awsRegion": "us-west-1",
  "errorCode": "NoSuchBucket",
  "errorMessage": "The specified bucket does not exist",
  "eventCategory": "Management",
  "eventID": "25d257d0-2358-4136-941d-517cf6a6ffe8",
  "eventName": "DeleteBucketInventoryConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:26:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "S0YNPQ9MQPJVH3VS",
  "requestParameters": {
    "Host": "dw-probe.s3.us-west-1.amazonaws.com",
    "bucketName": "dw-probe",
    "id": "dw-probe",
    "inventory": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteBucketMetadataConfiguration

#
Service
s3

Description

Deletes an S3 Metadata configuration from a general purpose bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 298,
    "x-amz-id-2": "JHldfB8XmOSozqAFVxvdSBncyr9F+k/yJCzco9O9RDCga9Y2K/GktqOWT2HJpCT3QWw2XNjnqWQ="
  },
  "awsRegion": "us-west-1",
  "errorCode": "NoSuchBucket",
  "errorMessage": "The specified bucket does not exist",
  "eventCategory": "Management",
  "eventID": "9d305051-e643-40fa-85fc-6289ae14a714",
  "eventName": "DeleteBucketMetadataConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:26:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "S0YV22SS3MCSXP0Q",
  "requestParameters": {
    "Host": "dw-probe.s3.us-west-1.amazonaws.com",
    "bucketName": "dw-probe",
    "metadataConfiguration": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteBucketMetadataTableConfiguration

#
Service
s3

Description

We recommend that you delete your S3 Metadata configurations by using the V2 DeleteBucketMetadataTableConfiguration API operation.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 298,
    "x-amz-id-2": "qJy9oBzVo/zykg9kVcLsHrwXtqwCt4w9252NnGL0GSM3IXSTH2hpDwRLbzL9oWYfG51kJFnkEN8="
  },
  "awsRegion": "us-west-1",
  "errorCode": "NoSuchBucket",
  "errorMessage": "The specified bucket does not exist",
  "eventCategory": "Management",
  "eventID": "b85ba33f-154b-46de-a965-525bcee63832",
  "eventName": "DeleteBucketMetadataTableConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:26:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "S0YRYYV1Z91NC7RK",
  "requestParameters": {
    "Host": "dw-probe.s3.us-west-1.amazonaws.com",
    "bucketName": "dw-probe",
    "metadataTable": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteBucketMetricsConfiguration

#
Service
s3

Description

Deletes a metrics configuration for the Amazon CloudWatch request metrics (specified by the metrics configuration ID) from the bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "lnYZrJuF2jDXMFfVEmBe8jA1VcdT1IORhJe6i3zY5WMSFU6qUfU7qJ0sjB7A5S5fBEa/1ATqCxw="
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "0df08b06-9f9a-40ff-9a2d-5dc16c5c23a9",
  "eventName": "DeleteBucketMetricsConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:08:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "CPH5B068694QAPG5",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "id": "dw",
    "metrics": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteBucketOwnershipControls

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "lSC4p0594sHAQ/bO11MPQaIKeKS/QFnCBuKRGW5JKUGCe9N1XpX1y83xh69e0FtUFFj7svmDK5I="
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "6a718578-6f1d-4d2d-be83-dd5b9b4b5d5f",
  "eventName": "DeleteBucketOwnershipControls",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:08:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "MDB1ZT594Y4N1RCP",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "ownershipControls": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteBucketTagging

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "5s6g1Q0J1bQubRPsrtvjNxYZ+URWG79YAyf0rm+NWJ+nqupHLlXUDaugKibX+wKHsoWtuHP+8JQ="
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "d72670e0-bf0c-4ea1-a0e3-1332ea3be48f",
  "eventName": "DeleteBucketTagging",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:08:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "CPH0YJW255Y75RFD",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "tagging": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteBucketWebsite

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "XboDA8Op8eKbwefkdBt7fQTBBDYX29kG/wyJHLe/Moe748VeBTCAxbYMky+ip7BJT2vjKIfzj4c="
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "b91dc754-5abe-4f80-9a9a-b21e9660847f",
  "eventName": "DeleteBucketWebsite",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:08:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "CPHFETRPXBQTS36W",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "website": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteObjectAnnotation

#
Service
s3

Description

Deletes a specific annotation from an Amazon S3 object.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "PGI9xpCmBfllscU6eHev1WmEe7rHqxFRbkhHnpl7/vZXzt4vc/iSESqEeuYDR/jhvFZ8dT2aAEY="
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Data",
  "eventID": "9432d252-fcad-43dc-b644-47ac12e144d0",
  "eventName": "DeleteObjectAnnotation",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T20:58:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": false,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "794QWWDTKGRRCFWF",
  "requestParameters": {
    "Host": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
    "annotation": "",
    "annotationName": "dwfix-annotation",
    "bucketName": "dwfix-main-921c7279",
    "key": "test-object.txt"
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-main-921c7279",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    },
    {
      "ARN": "arn:aws:s3:::dwfix-main-921c7279/test-object.txt",
      "type": "AWS::S3::Object"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteObjects

#
Service
s3

Description

This operation enables you to delete multiple objects from a bucket using a single HTTP request.

CloudTrail data event: not logged by a standard management-events trail. Requires explicit data-event configuration (an advanced event selector) on the trail or CloudTrail Lake; absence of this event does not prove the action did not occur. S3 data event. Requires S3 data-event logging on the trail. A single DeleteObjects call can delete up to 1000 keys, so each event represents bulk destruction.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "ULC5G/XSktS5ug9eGxT8oYJs/tXQypLbfFH295M5U5bQfZzXdw1WKqBS11xKAYcr0c+jgcguuyA+DOMKKuOITsTyszihDS5o"
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Data",
  "eventID": "d440c448-f01b-4e15-b31c-32d8e650dd47",
  "eventName": "DeleteObjects",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:07:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": false,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7Y2WK0V00AHY1537",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "delete": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    },
    {
      "ARNPrefix": "arn:aws:s3:::dwfix-s3-123456789012-uw1/",
      "type": "AWS::S3::Object"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/U,Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::sourceIPAddress (panther rule field)is_not_null1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DeleteObjectTagging

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "U15qE7yLnF+QfrrsRJf3+JY1Tkqyeq5K7IqMUddofrxpL3ySH5UBo2oe3U42fr4UOCycDA2fdjR1OKS/YyedoTfO6duX3e+E"
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Data",
  "eventID": "3e3649eb-dafe-483e-954e-383869f7b4ab",
  "eventName": "DeleteObjectTagging",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:07:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": false,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7Y2W5G2WBVKDZXWS",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "key": "dw.txt",
    "tagging": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    },
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1/dw.txt",
      "type": "AWS::S3::Object"
    }
  ],
  "responseElements": {
    "x-amz-version-id": "XqF3Ks1g6Dl23X61f0Jx4ONJSggFg4Gm"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeletePublicAccessBlock

#
Service
s3

Description

This operation is not supported for directory buckets.

GetBucketAbac

#
Service
s3

Description

Returns the attribute-based access control (ABAC) property of the general purpose bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 298,
    "x-amz-id-2": "0csWxa2uwb9T4l14iZPX3zPaQzokEy+t+rv0E3+mbMBlS9KcWA0TVps66A+xafSH8PAPTSxGz5Q="
  },
  "awsRegion": "us-west-1",
  "errorCode": "NoSuchBucket",
  "errorMessage": "The specified bucket does not exist",
  "eventCategory": "Management",
  "eventID": "d5bc2f5b-ebbd-48c0-ac47-acbde29a769f",
  "eventName": "GetBucketAbac",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T18:46:07Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "03F9DAESV8T2ZQV9",
  "requestParameters": {
    "Host": "dw-probe.s3.us-west-1.amazonaws.com",
    "abac": "",
    "bucketName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetBucketAccelerateConfiguration

#
Service
s3

Description

This operation is not supported for directory buckets.

CloudTrail logs this operation under the eventName GetAccelerateConfiguration; the catalog keys on the SDK operation name GetBucketAccelerateConfiguration. A detection rule may use either name.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 298,
    "x-amz-id-2": "4UM30snOSKvRkvVrzOgNTDmFjuCyZyNwXgVfE2O8P2ReyQRE7+TmaspeF9Gb8IZOaT0fIleW6yU="
  },
  "awsRegion": "us-west-1",
  "errorCode": "NoSuchBucket",
  "errorMessage": "The specified bucket does not exist",
  "eventCategory": "Management",
  "eventID": "340256ff-7a7f-4536-b7d7-9b65aed0a1c9",
  "eventName": "GetAccelerateConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T18:46:07Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "03F10NZRJPYD8M3G",
  "requestParameters": {
    "Host": "dw-probe.s3.us-west-1.amazonaws.com",
    "accelerate": "",
    "bucketName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetBucketAnalyticsConfiguration

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "x-amz-id-2": "i09xXQ2MKcrLDhQzAfnGC/gLINoTjDo3Y3hG9TIUiAY7xRnJ6F5kileIlo3KWscZRstLfHChN5Q="
  },
  "awsRegion": "us-east-1",
  "errorCode": "NoSuchBucket",
  "errorMessage": "The specified bucket does not exist",
  "eventID": "fee449117-f1bd-49c5-a24a-f9b36127b272",
  "eventName": "GetBucketAnalyticsConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2020-09-21T04:28:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "readOnly": true,
  "recipientAccountId": "811596193553",
  "requestID": "0P5Z2XBQAWCN2PDP",
  "requestParameters": {
    "Host": "s3.amazonaws.com",
    "analytics": "",
    "bucketName": "dummy_data",
    "id": "dummy_data"
  },
  "responseElements": null,
  "sourceIPAddress": "9.240.250.1",
  "userAgent": "[Boto3/1.14.51 Python/3.8.5 Linux/4.19.76-linuxkit Botocore/1.17.51]",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

GetBucketEncryption

#
Service
s3

Description

Returns the default encryption configuration for an Amazon S3 bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 321,
    "x-amz-id-2": "/KLysnkOpdyQBFMRu9dFVipzhAtT/tn6O5ytClX9jn/4wnOBtTTmBJ6bp4tn1iWai61r6P5l4Jk="
  },
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "204a9beb-9b1c-4083-9279-51bd05eb94aa",
  "eventName": "GetBucketEncryption",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2023-07-10T12:00:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "FAG1V07V67D44H44",
  "requestParameters": {
    "Host": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
    "bucketName": "stratus-red-team-ctes-bucket-qyxyekjbtk",
    "encryption": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::stratus-red-team-ctes-bucket-qyxyekjbtk",
      "accountId": "123837392027",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "[APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_1d949e3e-4092-4c96-a6ef-96a967510a46 HashiCorp-terraform-exec/0.17.3]",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

GetBucketIntelligentTieringConfiguration

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 298,
    "x-amz-id-2": "95aKcqYBtukGeWh289G48EQwszPvZHg7+IufMB3k7fzIByoaSzJN/XKjwz8cLkjI+OehS87TnV4="
  },
  "awsRegion": "us-west-1",
  "errorCode": "NoSuchBucket",
  "errorMessage": "The specified bucket does not exist",
  "eventCategory": "Management",
  "eventID": "3f9c2377-51b0-4d05-bc81-f6a39084d701",
  "eventName": "GetBucketIntelligentTieringConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T18:46:07Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "03F058CVBQDF7QXX",
  "requestParameters": {
    "Host": "dw-probe.s3.us-west-1.amazonaws.com",
    "bucketName": "dw-probe",
    "id": "dw-probe",
    "intelligent-tiering": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetBucketLifecycle

#
Service
s3

Description

For an updated version of this API, see GetBucketLifecycleConfiguration.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 313,
    "x-amz-id-2": "CTiNTOXxtLbBJFQ9ITNWSQPJrkE19NKVi1pT2uzI1Sodn7DL9UnobYxm6kbkbT4+uKxhu3a6MoM="
  },
  "awsRegion": "us-east-1",
  "errorCode": "NoSuchLifecycleConfiguration",
  "errorMessage": "The lifecycle configuration does not exist",
  "eventCategory": "Management",
  "eventID": "0aba48a0-49f4-4bbd-ab3f-6c75c8efb1ce",
  "eventName": "GetBucketLifecycle",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2023-07-10T12:00:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "6T7WWC4P2D4GPWQN",
  "requestParameters": {
    "Host": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
    "bucketName": "stratus-red-team-ctes-bucket-qyxyekjbtk",
    "lifecycle": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::stratus-red-team-ctes-bucket-qyxyekjbtk",
      "accountId": "123837392027",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "[APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_1d949e3e-4092-4c96-a6ef-96a967510a46 HashiCorp-terraform-exec/0.17.3]",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

GetBucketLocation

#
Service
s3

Description

Using the GetBucketLocation operation is no longer a best practice.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 108,
    "x-amz-id-2": "W6I1woNC4SkUGvYtfXAoAV7nYN5J3T9dpikLLl8JTNP/XA0acaLFd5mYN6etSxvZ6AIiuqevRP0="
  },
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "1f07ad67-b44f-4f8f-87b4-3bcf4d2fdb46",
  "eventName": "GetBucketLocation",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2023-07-10T11:43:08Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "XWA4G86RD2987F7J",
  "requestParameters": {
    "Host": "s3.us-east-1.amazonaws.com",
    "bucketName": "invictus-aws-2022-10-27-8aukl",
    "location": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::invictus-aws-2022-10-27-8aukl",
      "accountId": "123837392027",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "10.248.16.43",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "s3.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "[Boto3/1.26.165 Python/3.10.6 Linux/5.19.0-46-generic Botocore/1.29.165]",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSCUXC3DDDP",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/benjamin",
    "principalId": "AIDATFQR7NSC5U6Q3TMDR",
    "type": "IAMUser",
    "userName": "benjamin"
  }
}

References #

GetBucketLogging

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 289,
    "x-amz-id-2": "nCX0RuWZsl0hDNCONzAYqBJhruBw6bSHijA3R/7kWXrThHLww4fET3Gpafft53c3ujXoMsWlh+I="
  },
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "b89b5aad-a778-47ab-a9bf-9cb0842f81b5",
  "eventName": "GetBucketLogging",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2023-07-10T11:43:07Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "PQRSYJBACCRHAVPA",
  "requestParameters": {
    "Host": "invictus-aws-2022-10-27-8aukl.s3.us-east-1.amazonaws.com",
    "bucketName": "invictus-aws-2022-10-27-8aukl",
    "logging": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::invictus-aws-2022-10-27-8aukl",
      "accountId": "123837392027",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "10.248.16.43",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "invictus-aws-2022-10-27-8aukl.s3.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "[Boto3/1.26.165 Python/3.10.6 Linux/5.19.0-46-generic Botocore/1.29.165]",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSCUXC3DDDP",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/benjamin",
    "principalId": "AIDATFQR7NSC5U6Q3TMDR",
    "type": "IAMUser",
    "userName": "benjamin"
  }
}

References #

GetBucketMetadataConfiguration

#
Service
s3

Description

Retrieves the S3 Metadata configuration for a general purpose bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 298,
    "x-amz-id-2": "3p6/B7yUfaq6WDPL9vZaSfF0df8r+REKHKaO273VEW3KWBlRQHpcM4KUJVfJNvsFsBfKJW3Aqz0="
  },
  "awsRegion": "us-west-1",
  "errorCode": "NoSuchBucket",
  "errorMessage": "The specified bucket does not exist",
  "eventCategory": "Management",
  "eventID": "8827138b-cfbc-4b47-91aa-35ba04703615",
  "eventName": "GetBucketMetadataConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T18:46:07Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "03F6SAY1N5XGY73Q",
  "requestParameters": {
    "Host": "dw-probe.s3.us-west-1.amazonaws.com",
    "bucketName": "dw-probe",
    "metadataConfiguration": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetBucketMetadataTableConfiguration

#
Service
s3

Description

We recommend that you retrieve your S3 Metadata configurations by using the V2 GetBucketMetadataTableConfiguration API operation.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 298,
    "x-amz-id-2": "XW/QPuksGkGcASQ4AvADHimZwWHWDBFhXt9B+S7u9f0P8AI/wVN8sH5C0kno5zf5goXx7j+w4xQ="
  },
  "awsRegion": "us-west-1",
  "errorCode": "NoSuchBucket",
  "errorMessage": "The specified bucket does not exist",
  "eventCategory": "Management",
  "eventID": "15b0694b-ba4b-4a9b-a74b-4e9dba66e949",
  "eventName": "GetBucketMetadataTableConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T18:46:07Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "03F8B8W9RRR4NKG6",
  "requestParameters": {
    "Host": "dw-probe.s3.us-west-1.amazonaws.com",
    "bucketName": "dw-probe",
    "metadataTable": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetBucketNotification

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "13a08591-5451-4920-8e54-f63c3e89efb3",
  "eventName": "GetBucketNotification",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2017-02-12T20:38:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "DA7A691249E0886",
  "requestParameters": {
    "bucketName": "level3-b5677c799b465420d8e7b0a6689a0bb0c4afbc9e.flaws.cloud",
    "notification": [
      ""
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "AWS Internal",
  "userAgent": "[aws-internal/3]",
  "userIdentity": {
    "accessKeyId": "ASIALDOGXGOQA5IF2TC7",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:root",
    "principalId": "811596193553",
    "sessionContext": {
      "attributes": {
        "creationDate": "2017-02-12T19:57:05Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "Root"
  }
}

References #

GetBucketOwnershipControls

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 321,
    "x-amz-id-2": "QqR5FlH9No3Y5lAD3cCh6DcgYNEFz4RXHThsszajJ2To9oNBMhnZ4B+CId8uVZWVm1JQAloj+mA="
  },
  "awsRegion": "us-east-2",
  "errorCode": "OwnershipControlsNotFoundError",
  "errorMessage": "The bucket ownership controls were not found",
  "eventCategory": "Management",
  "eventID": "6604c21d-19f6-4b76-ae93-b07b5d89d31e",
  "eventName": "GetBucketOwnershipControls",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2021-07-07T17:24:39Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "ZBKPDA19T3VTTYSB",
  "requestParameters": {
    "Host": "s3.us-east-2.amazonaws.com",
    "bucketName": "cado-response-cados3bucketalt-1v7p4ao8z6xku",
    "ownershipControls": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::cado-response-cados3bucketalt-1v7p4ao8z6xku",
      "accountId": "797507667711",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "167.98.108.182",
  "userAgent": "[S3Console/0.4, aws-internal/3 aws-sdk-java/1.11.1002 Linux/5.4.122-66.218.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.282-b08 java/1.8.0_282 vendor/Oracle_Corporation cfg/retry-mode/legacy]",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI37UYLMS4UD",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/sean",
    "principalId": "AIDA3TLZJI375TCG5FSRI",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:56:28Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "sean"
  },
  "vpcEndpointId": "vpce-eca44785"
}

References #

GetBucketReplication

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 362,
    "x-amz-id-2": "Z/W18FkXcg2VxLJ8rmaXFJaPCA22bkMXHNhc0hsWCoj4rFTzMx+Ce434/AW6gnB7+rWB7ISgZmk="
  },
  "awsRegion": "us-east-1",
  "errorCode": "ReplicationConfigurationNotFoundError",
  "errorMessage": "The replication configuration was not found",
  "eventCategory": "Management",
  "eventID": "933e890c-59c2-4b02-94f9-d897105774d7",
  "eventName": "GetBucketReplication",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2023-07-10T12:00:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "FAG47VW6DAV6HNSS",
  "requestParameters": {
    "Host": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
    "bucketName": "stratus-red-team-ctes-bucket-qyxyekjbtk",
    "replication": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::stratus-red-team-ctes-bucket-qyxyekjbtk",
      "accountId": "123837392027",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "[APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_1d949e3e-4092-4c96-a6ef-96a967510a46 HashiCorp-terraform-exec/0.17.3]",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

GetBucketRequestPayment

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 172,
    "x-amz-id-2": "McA1LBXhV/96SQf7L/oNPu62KbafpSo3thi3aOG64fOm8XKguL3bFgiMninRP/mULpWTF4+U/So="
  },
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "a8f9c9ca-2699-4671-95b3-c65680fe169f",
  "eventName": "GetBucketRequestPayment",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2023-07-10T12:00:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "6T7PEWH8YDPMZYNJ",
  "requestParameters": {
    "Host": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
    "bucketName": "stratus-red-team-ctes-bucket-qyxyekjbtk",
    "requestPayment": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::stratus-red-team-ctes-bucket-qyxyekjbtk",
      "accountId": "123837392027",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "[APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_1d949e3e-4092-4c96-a6ef-96a967510a46 HashiCorp-terraform-exec/0.17.3]",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

GetBucketWebsite

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 366,
    "x-amz-id-2": "TpdrYTET2hjtrOYFH2msTUMMJGTyBLbUjPHnR7tILNDTnm9gpXY/e1Bud6AeXDl0YNa/BemTD6U="
  },
  "awsRegion": "us-east-1",
  "errorCode": "NoSuchWebsiteConfiguration",
  "errorMessage": "The specified bucket does not have a website configuration",
  "eventCategory": "Management",
  "eventID": "ac58e122-51a4-420a-a5c5-0db11a29829f",
  "eventName": "GetBucketWebsite",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2023-07-10T12:00:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "DXXBR7T8B17BENKA",
  "requestParameters": {
    "Host": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
    "bucketName": "stratus-red-team-ctes-bucket-qyxyekjbtk",
    "website": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::stratus-red-team-ctes-bucket-qyxyekjbtk",
      "accountId": "123837392027",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "[APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_1d949e3e-4092-4c96-a6ef-96a967510a46 HashiCorp-terraform-exec/0.17.3]",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

GetObjectAcl

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T21:18:50Z",
  "eventSource": "s3.amazonaws.com",
  "eventName": "GetObjectAcl",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "[aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#s3api.get-object-acl]",
  "requestParameters": {
    "bucketName": "dw-harn-s3-e59db69d",
    "Host": "dw-harn-s3-e59db69d.s3.us-west-1.amazonaws.com",
    "acl": "",
    "key": "dw-harn-e59db69d"
  },
  "responseElements": null,
  "additionalEventData": {
    "SignatureVersion": "SigV4",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "bytesTransferredIn": 0,
    "AuthenticationMethod": "AuthHeader",
    "x-amz-id-2": "ef9W/ZwMg+T2iKNth1mx4P8ytM1XXQlJX6FvvbZPjnoxJI49vzcgO0p6imoKvBKTNo5hiI383ZgDaDyedpAecg6eyslY1fHs",
    "bytesTransferredOut": 480
  },
  "requestID": "WPXBWJA1AFWJ1FJR",
  "eventID": "f16b17ed-f962-4bcc-8de2-6b4a2f7767af",
  "readOnly": true,
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket",
      "ARN": "arn:aws:s3:::dw-harn-s3-e59db69d"
    },
    {
      "type": "AWS::S3::Object",
      "ARN": "arn:aws:s3:::dw-harn-s3-e59db69d/dw-harn-e59db69d"
    }
  ],
  "eventType": "AwsApiCall",
  "managementEvent": false,
  "recipientAccountId": "123456789012",
  "eventCategory": "Data",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-harn-s3-e59db69d.s3.us-west-1.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

GetObjectAnnotation

#
Service
s3

Description

Retrieves an annotation from an Amazon S3 object.

GetObjectAttributes

#
Service
s3

Description

Retrieves all of the metadata from an object without returning the object itself.

GetObjectLegalHold

#
Service
s3

Description

This operation is not supported for directory buckets.

GetObjectLockConfiguration

#
Service
s3

Description

This operation is not supported for directory buckets.

CloudTrail logs this operation under the eventName GetBucketObjectLockConfiguration; the catalog keys on the SDK operation name GetObjectLockConfiguration. A detection rule may use either name.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 298,
    "x-amz-id-2": "Nh6IyrFQGZEodtqaawSuwt9CoiQL2nzqXpwVg2POMcqu1sN3Xu2EX/a+jxiNnEwPBtzktJcDaeA="
  },
  "awsRegion": "us-west-1",
  "errorCode": "NoSuchBucket",
  "errorMessage": "The specified bucket does not exist",
  "eventCategory": "Management",
  "eventID": "7d606875-d767-4cfd-a1cf-72a0c9158394",
  "eventName": "GetBucketObjectLockConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T18:46:07Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "03F0MG45QN31TZTW",
  "requestParameters": {
    "Host": "dw-probe.s3.us-west-1.amazonaws.com",
    "bucketName": "dw-probe",
    "object-lock": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetObjectRetention

#
Service
s3

Description

This operation is not supported for directory buckets.

GetObjectTagging

#
Service
s3

Description

This operation is not supported for directory buckets.

GetObjectTorrent

#
Service
s3

Description

This operation is not supported for directory buckets.

HeadBucket

#
Service
s3

Description

You can use this operation to determine if a bucket exists and if you have permission to access it.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "7d7132d9-dbf7-4c3b-bf59-d804bd23b40c",
  "eventSource": "s3.amazonaws.com",
  "eventName": "HeadBucket",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": false,
  "requestID": "0F4Q66B4Q5TMQXF6",
  "userAgent": "trustedadvisor.amazonaws.com",
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket",
      "ARN": "arn:aws:s3:::EXAMPLE"
    },
    {
      "type": "AWS::S3::Object",
      "ARNPrefix": "arn:aws:s3:::EXAMPLE"
    }
  ]
}

HeadObject

#
Service
s3

Description

The HEAD operation retrieves metadata from an object without returning the object itself.

ListDirectoryBuckets

#
Service
s3

Description

Returns a list of all Amazon S3 directory buckets owned by the authenticated sender of the request.

ListMultipartUploads

#
Service
s3

Description

This operation lists in-progress multipart uploads in a bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-SHA",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 417,
    "x-amz-id-2": "Xbutbtlu9df9s7R2NmZG5GQtASbe2v5MI09KBmXcC5tQ+GvnIYwPXy7iUdVaYxv/wOT/gRWs9pw="
  },
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "1ae13b3c-966b-4747-b35c-6909fea1d451",
  "eventName": "ListMultipartUploads",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2021-07-07T18:14:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "V5JH5QBF7SZ75RM7",
  "requestParameters": {
    "Host": "cado-response-cados3bucketalt-1v7p4ao8z6xku.s3.dualstack.us-east-2.amazonaws.com",
    "bucketName": "cado-response-cados3bucketalt-1v7p4ao8z6xku",
    "delimiter": "/",
    "prefix": "",
    "uploads": "",
    "x-amz-request-payer": "requester"
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::cado-response-cados3bucketalt-1v7p4ao8z6xku",
      "accountId": "797507667711",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "167.98.108.182",
  "userAgent": "[Cyberduck/7.9.1.34974 (Windows 10/10.0) (amd64)]",
  "userIdentity": {
    "accessKeyId": "AKIA3TLZJI372BTFKEHQ",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/sean",
    "principalId": "AIDA3TLZJI375TCG5FSRI",
    "type": "IAMUser",
    "userName": "sean"
  }
}

References #

ListObjectAnnotations

#
Service
s3

Description

Lists the annotations attached to an Amazon S3 object.

ListObjectsV2

#
Service
s3

Description

Returns some or all (up to 1,000) of the objects in a bucket with each request.

ListObjectVersions

#
Service
s3

Description

This operation is not supported for directory buckets.

ListParts

#
Service
s3

Description

Lists the parts that have been uploaded for a specific multipart upload.

PutBucketAbac

#
Service
s3

Description

Sets the attribute-based access control (ABAC) property of the general purpose bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 97,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "dgKfePm8EB/ngIQAddiHrJEqIyMCpYIHJtInBBt0aUIA/xBGBslUrl/HNsgqpU7WkGJTZ/1xA+k="
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "e1d0d6fa-8315-4867-b01e-8d6d4edfd9a1",
  "eventName": "PutBucketAbac",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T20:58:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "794PVFCEKXF18JJ1",
  "requestParameters": {
    "AbacStatus": {
      "Status": "Enabled",
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "Host": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
    "abac": "",
    "bucketName": "dwfix-main-921c7279"
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-main-921c7279",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,Z,U,D cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutBucketAccelerateConfiguration

#
Service
s3

Description

This operation is not supported for directory buckets.

PutBucketAnalyticsConfiguration

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 132,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "NmhKDLBFbN46zMoQPpbwaB14DgjkpoMu3+8r/TNPJzb0hIZ7qqtIQQy0c9sMAoxgm3jo8VD0nRWbXSrDWJPPej3Mj52bMxi8"
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "dc78e3ca-5c95-4025-abf7-697f0dc9312a",
  "eventName": "PutBucketAnalyticsConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:07:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7Y2ZGZECGKQ5P8F8",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "analytics": "",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "id": "dw"
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutBucketCors

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4"
  },
  "awsRegion": "us-west-2",
  "errorCode": "AccessDenied",
  "errorMessage": "Access Denied",
  "eventID": "3b80225a-902b-481f-990e-346cd6344335",
  "eventName": "PutBucketCors",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2019-05-07T15:06:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "80F0EAB4B0DE97F4",
  "requestParameters": {
    "CORSConfiguration": {
      "CORSRule": {
        "AllowedMethod": "GET",
        "AllowedOrigin": "*"
      },
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "bucketName": "flaws.cloud",
    "cors": [
      ""
    ],
    "host": [
      "s3.us-west-2.amazonaws.com"
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "107.164.125.91",
  "userAgent": "[Boto3/1.4.7 Python/2.7.15rc1 Linux/4.15.0-1035-aws Botocore/1.7.48]",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

PutBucketEncryption

#
Service
s3

Description

This operation configures default encryption and Amazon S3 Bucket Keys for an existing bucket.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 240,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "PqdKdvrPL3dHT4syTYbCiVI5FFSHZH3RDFRIevWpOlGYKiU3HN9I4pHkaYSZtJ7D2g8QpFlzWim1ykF+4rfXlV/HvseiMLbU"
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "42d9418e-426e-4fee-91af-e8fcde481686",
  "eventName": "PutBucketEncryption",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:07:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "G4Z47EF5KQ5YQCX3",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "ServerSideEncryptionConfiguration": {
      "Rule": {
        "ApplyServerSideEncryptionByDefault": {
          "SSEAlgorithm": "AES256"
        }
      },
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "bucketName": "dwfix-s3-123456789012-uw1",
    "encryption": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/U,Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutBucketIntelligentTieringConfiguration

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 223,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "P4yTAwaW+/Cf6qWvTR5RZqLgFAZqqPaW881zT7gz8WJpkqsZJWup9WuHIEWQCX41aZ9dGTQPKmFhJ1SBFo5QnSP2kjaToeTw"
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "6b3e010e-9889-448e-91e6-bfcc90f33bee",
  "eventName": "PutBucketIntelligentTieringConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:07:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7Y2YE395GNB2KGD1",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "IntelligentTieringConfiguration": {
      "Id": "dw",
      "Status": "Enabled",
      "Tiering": {
        "AccessTier": "ARCHIVE_ACCESS",
        "Days": 90
      },
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "bucketName": "dwfix-s3-123456789012-uw1",
    "id": "dw",
    "intelligent-tiering": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutBucketInventoryConfiguration

#
Service
s3

Description

This implementation of the PUT action adds an S3 Inventory configuration (identified by the inventory ID) to the bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 454,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "iL8qcEQ6LrPUeL8ufkVshXTQ5GquoF6lyVaHFw0PtPQDdB9rJK3HBoumSgipk39Ug/AmzUcQSzE="
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "c4ba6fe8-cabd-475a-a6e6-37f6eae00fc6",
  "eventName": "PutBucketInventoryConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T20:58:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9B5FZDYXKN62HEDG",
  "requestParameters": {
    "Host": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
    "InventoryConfiguration": {
      "Destination": {
        "S3BucketDestination": {
          "AccountId": 123456789012,
          "Bucket": "arn:aws:s3:::dwfix-main-921c7279",
          "Format": "CSV",
          "Prefix": "inventory/"
        }
      },
      "Id": "dwfix-inventory",
      "IncludedObjectVersions": "Current",
      "IsEnabled": true,
      "Schedule": {
        "Frequency": "Daily"
      },
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "bucketName": "dwfix-main-921c7279",
    "id": "dwfix-inventory",
    "inventory": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-main-921c7279",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutBucketLifecycleConfiguration

#
Service
s3

Description

Creates a new lifecycle configuration for the bucket or replaces an existing lifecycle configuration.

PutBucketMetricsConfiguration

#
Service
s3

Description

Sets a metrics configuration (specified by the metrics configuration ID) for the bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 104,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "wh8K294tnDPj1Xe6S/eZaMwUUNW3Yc8/8bD23v3+JdUH6g3jE4PndUWvIZDWRX1rw2Q+2lziJVYrU/vGfXFqHs9SFYGXBHaH"
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "ff7b5a73-1aaf-48c0-9fd5-53420a73ee0c",
  "eventName": "PutBucketMetricsConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:07:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7Y2VWTA7AKZET7CA",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "id": "dw",
    "metrics": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutBucketNotification

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4"
  },
  "awsRegion": "us-west-2",
  "errorCode": "AccessDenied",
  "errorMessage": "Access Denied",
  "eventID": "97f9c0f7-c285-4653-b6bb-313e676c21ef",
  "eventName": "PutBucketNotification",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2019-05-07T15:07:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "E1347D268AA5D801",
  "requestParameters": {
    "NotificationConfiguration": {
      "TopicConfiguration": {
        "Event": "s3:ReducedRedundancyLostObject",
        "Topic": "arn:aws:sns:us-west-2:005412338514:sns-topic-one"
      },
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "bucketName": "flaws.cloud",
    "host": [
      "s3.us-west-2.amazonaws.com"
    ],
    "notification": [
      ""
    ]
  },
  "responseElements": null,
  "sourceIPAddress": "107.164.125.91",
  "userAgent": "[Boto3/1.4.7 Python/2.7.15rc1 Linux/4.15.0-1035-aws Botocore/1.7.48]",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

PutBucketNotificationConfiguration

#
Service
s3

Description

This operation is not supported for directory buckets.

PutBucketOwnershipControls

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 155,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "EDHRFFl4Cd+WIdTaHx80bWNIrig52W0tsCI2YYK1ebZjWhdH1NYmbDdMtjYJ6ipKBTCTnsKt12qipghIi3LFlxrHZoPQa3Yf"
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "0fe7b60a-8843-457e-804e-2c78b32c0597",
  "eventName": "PutBucketOwnershipControls",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:07:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "W6T1TQ9Z7GKHR4Z7",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "OwnershipControls": {
      "Rule": {
        "ObjectOwnership": "BucketOwnerPreferred"
      },
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "bucketName": "dwfix-s3-123456789012-uw1",
    "ownershipControls": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/U,Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutBucketRequestPayment

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 133,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "DI0fzy+xnJciTtQizE5pRiUeHIhFkUwDk9xXabnlHGjqFa3rolVE3RiFmWiDAwg07Zi+T+rmb3djrh6LOjOzZjwjhf1hlMDB"
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f0eea530-158e-48be-8164-6800e7b4a2cc",
  "eventName": "PutBucketRequestPayment",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:07:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "W6TFCRGJKFF6PG8D",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "RequestPaymentConfiguration": {
      "Payer": "BucketOwner",
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "bucketName": "dwfix-s3-123456789012-uw1",
    "requestPayment": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/U,Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutBucketTagging

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:59:29Z",
  "eventSource": "s3.amazonaws.com",
  "eventName": "PutBucketTagging",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "[aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/n,W,Z,E,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#s3api.put-bucket-tagging]",
  "requestParameters": {
    "Tagging": {
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/",
      "TagSet": {
        "Tag": {
          "Value": "aws_harness",
          "Key": "dw-harness"
        }
      }
    },
    "tagging": "",
    "bucketName": "dw-harn-s3-eb786637",
    "Host": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
  },
  "responseElements": null,
  "additionalEventData": {
    "SignatureVersion": "SigV4",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "bytesTransferredIn": 142,
    "AuthenticationMethod": "AuthHeader",
    "x-amz-id-2": "fmIErzGMti7rperNyTlBoli7aZfaWF43fclVRHTGqvtZih47cpMq08bL47YaFMpZ75EUkOzTmj9Z2IZmwvehw0b/CfJpJYXI",
    "bytesTransferredOut": 0
  },
  "requestID": "0QPXGGBB5FPG1337",
  "eventID": "2095f7a8-2908-4cf7-a156-d2971508ff35",
  "readOnly": false,
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket",
      "ARN": "arn:aws:s3:::dw-harn-s3-eb786637"
    }
  ],
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
  }
}

PutObjectAcl

#
Service
s3

Description

End of support notice: As of October 1, 2025, Amazon S3 has discontinued support for Email Grantee Access Control Lists (ACLs).

CloudTrail data event: not logged by a standard management-events trail. Requires explicit data-event configuration (an advanced event selector) on the trail or CloudTrail Lake; absence of this event does not prove the action did not occur. S3 data event. Requires S3 data-event logging on the trail.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "aclRequired": "Yes",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "WdQ2bx6z/QbIBlYUc8eugUivzwtd8wxE17nIjLta7J2PrihHWlRy/4F6vyeRUsBM4aiZCWwqfzBu1o7PU5btEis7TN1UvsdJ"
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Data",
  "eventID": "9b8364bc-b232-483b-b6c9-c76313c0b20d",
  "eventName": "PutObjectAcl",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:07:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": false,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7Y2QA4BVSJQ6ZE64",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "acl": "",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "key": "dw.txt",
    "x-amz-acl": "private"
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    },
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1/dw.txt",
      "type": "AWS::S3::Object"
    }
  ],
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/U,Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

Panther #

PutObjectAnnotation

#
Service
s3

Description

Attaches an annotation to an Amazon S3 object.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 61,
    "bytesTransferredOut": 179,
    "x-amz-id-2": "7uLxIbYWknSnU9IpNdvoyzcX1obO9fYR/lPF7DUs+5QHvb1L0L3bG6brtiVsqHnOYENNesggk5s="
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Data",
  "eventID": "b730a2b2-cdc7-4672-804f-b9007905e193",
  "eventName": "PutObjectAnnotation",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T20:58:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": false,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "794N704X7Z5BT4WS",
  "requestParameters": {
    "Host": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
    "annotation": "",
    "annotationName": "dwfix-annotation",
    "bucketName": "dwfix-main-921c7279",
    "key": "test-object.txt"
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-main-921c7279",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    },
    {
      "ARN": "arn:aws:s3:::dwfix-main-921c7279/test-object.txt",
      "type": "AWS::S3::Object"
    }
  ],
  "responseElements": {
    "x-amz-server-side-encryption": "AES256"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,Z,U,D cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutObjectLegalHold

#
Service
s3

Description

This operation is not supported for directory buckets.

PutObjectLockConfiguration

#
Service
s3

Description

This operation is not supported for directory buckets.

PutObjectRetention

#
Service
s3

Description

This operation is not supported for directory buckets.

PutObjectTagging

#
Service
s3

Description

This operation is not supported for directory buckets.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 126,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "II6G4NY0RPbtQDQprMxlx4CG8iGcYB4TO3TuIJznMgbkmHMqRRIwiVb9bpn8eYJd4WuOvcDGR4vreCElxkGDw2PZLZhxxvO8"
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Data",
  "eventID": "d5703205-cd0f-4afe-b04f-33c5a5f8348d",
  "eventName": "PutObjectTagging",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:07:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": false,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7Y2YPHQ36N6X484H",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "key": "dw.txt",
    "tagging": ""
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    },
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1/dw.txt",
      "type": "AWS::S3::Object"
    }
  ],
  "responseElements": {
    "x-amz-version-id": "XqF3Ks1g6Dl23X61f0Jx4ONJSggFg4Gm"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/U,Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

PutPublicAccessBlock

#
Service
s3

Description

This operation is not supported for directory buckets.

RenameObject

#
Service
s3

Description

Renames an existing object in a directory bucket that uses the S3 Express One Zone storage class.

SelectObjectContent

#
Service
s3

Description

This operation is not supported for directory buckets.

UpdateBucketMetadataAnnotationTableConfiguration

#
Service
s3

Description

Updates the annotation table configuration for an Amazon S3 bucket's metadata configuration.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 157,
    "bytesTransferredOut": 298,
    "x-amz-id-2": "AR8hoJ2grjBSlgpEL9z8Z241L24jVd9XaApl7bsEy75BSEiE50AQ7eUTvsqDBCY76arnf0jeHPo="
  },
  "awsRegion": "us-west-1",
  "errorCode": "NoSuchBucket",
  "errorMessage": "The specified bucket does not exist",
  "eventCategory": "Management",
  "eventID": "26bd1f25-9018-47bc-a9c3-ba5efd59c209",
  "eventName": "UpdateBucketMetadataAnnotationTableConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:26:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "S0YQQP98VQ9BB483",
  "requestParameters": {
    "AnnotationTableConfiguration": {
      "ConfigurationState": "ENABLED",
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "Host": "dw-probe.s3.us-west-1.amazonaws.com",
    "bucketName": "dw-probe",
    "metadataAnnotationTable": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,U,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateBucketMetadataInventoryTableConfiguration

#
Service
s3

Description

Enables or disables a live inventory table for an S3 Metadata configuration on a general purpose bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 155,
    "bytesTransferredOut": 318,
    "x-amz-id-2": "TJQe+WtXM+HQ7HfWd7YLAtb3Z/utiD8c/M2Ywz5fvKbIOIIn6AGKS5oOAOtCJILyr5a0Mp0gZUT/IvPTOlKvWoJuuZ5r3mp7"
  },
  "awsRegion": "us-west-1",
  "errorCode": "NoSuchBucket",
  "errorMessage": "The specified bucket does not exist",
  "eventCategory": "Management",
  "eventID": "83b9f1ec-9157-4bd2-80fc-ced4104dff0d",
  "eventName": "UpdateBucketMetadataInventoryTableConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:26:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "S0YR36KPW9CCH223",
  "requestParameters": {
    "Host": "dw-probe.s3.us-west-1.amazonaws.com",
    "InventoryTableConfiguration": {
      "ConfigurationState": "ENABLED",
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "bucketName": "dw-probe",
    "metadataInventoryTable": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,U,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateBucketMetadataJournalTableConfiguration

#
Service
s3

Description

Enables or disables journal table record expiration for an S3 Metadata configuration on a general purpose bucket.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 172,
    "bytesTransferredOut": 298,
    "x-amz-id-2": "UD2KgCUdbRw4VGqLaCP3qvN7Vu+VtjXiFpNuoHHLmwtlHhWrKBdTK7Qp0DdP33O2myiejNDwyy4="
  },
  "awsRegion": "us-west-1",
  "errorCode": "NoSuchBucket",
  "errorMessage": "The specified bucket does not exist",
  "eventCategory": "Management",
  "eventID": "7c722329-ef76-425c-93bb-b09c16a1b9dc",
  "eventName": "UpdateBucketMetadataJournalTableConfiguration",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:26:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "S0YWRJ9RPRHVXGEV",
  "requestParameters": {
    "Host": "dw-probe.s3.us-west-1.amazonaws.com",
    "JournalTableConfiguration": {
      "RecordExpiration": {
        "Expiration": "ENABLED"
      },
      "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
    },
    "bucketName": "dw-probe",
    "metadataJournalTable": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,U,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateObjectEncryption

#
Service
s3

Description

This operation is not supported for directory buckets or Amazon S3 on Outposts buckets.

UploadPart

#
Service
s3

Description

Uploads a part in a multipart upload.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 47,
    "bytesTransferredOut": 0,
    "x-amz-id-2": "LdXCdhcGAHHLCNi21E/pqSQOh6ODsM0ygdHgLrRXvEZvjCgCjb6S5pVWvfo4lAA4tQ1RiAXeGZjLV1hvz31U1yOZu0E2a88z"
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Data",
  "eventID": "1a9c4e28-1d20-47fe-94f6-5fab2c9b3713",
  "eventName": "UploadPart",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T19:07:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": false,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7Y2ZPGHMXKWHGVA9",
  "requestParameters": {
    "Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "bucketName": "dwfix-s3-123456789012-uw1",
    "key": "mp.txt",
    "partNumber": "1",
    "uploadId": "vjrRU8b9IkTn.BdpAS76xpfkVVBa0mQqYz8sgwPnWhMa2DzTN3jWbTfqfJuTPBj2GanWuDpdI9CGRS9KGhHPMD17mhoeHmAffPo6EHWGnznmWp7y0zNt9x4Ja1HMh6Y5"
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    },
    {
      "ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1/mp.txt",
      "type": "AWS::S3::Object"
    }
  ],
  "responseElements": {
    "x-amz-server-side-encryption": "AES256"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/U,Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UploadPartCopy

#
Service
s3

Description

Uploads a part by copying data from an existing object as data source.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "TLS_AES_128_GCM_SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 220,
    "x-amz-id-2": "542/NnTtkq7OLim3CV+u/UrtiSfcMVGcD5fqdacxAZ7UpNPNQlZOsI3bkAloFoVOySWCRdA/1qU="
  },
  "awsRegion": "us-west-1",
  "eventCategory": "Data",
  "eventID": "96d051f6-0918-4747-b060-a40c836e5be4",
  "eventName": "UploadPartCopy",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2026-06-29T20:58:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": false,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "794VJ8B04MVN34T4",
  "requestParameters": {
    "Host": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
    "bucketName": "dwfix-main-921c7279",
    "key": "mpu-object.txt",
    "partNumber": "2",
    "uploadId": "adI6a0ON5uIMbksUQjUaQDIyquNC_OPDf7eor8NZkSLr0WAKY.L8Blodil..WUaqF3ZciTtepqPeWerPn1q1CC5YZlnZExQeW.JfIRqg2yd9lO07ZmIU.f0TfMFZh3.F",
    "x-amz-copy-source": "dwfix-main-921c7279/test-object.txt"
  },
  "resources": [
    {
      "ARN": "arn:aws:s3:::dwfix-main-921c7279",
      "accountId": "123456789012",
      "type": "AWS::S3::Bucket"
    },
    {
      "ARN": "arn:aws:s3:::dwfix-main-921c7279/mpu-object.txt",
      "type": "AWS::S3::Object"
    },
    {
      "ARN": "arn:aws:s3:::dwfix-main-921c7279/test-object.txt",
      "type": "AWS::S3::Object"
    }
  ],
  "responseElements": {
    "x-amz-server-side-encryption": "AES256"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

WriteGetObjectResponse

#
Service
s3

Description

This operation is not supported for directory buckets.

GetAccountPublicAccessBlock

#
Service
s3

Description

Retrieves the public access block configuration for an AWS account; CloudTrail eventName for the GetPublicAccessBlock API at the account level.

Example CloudTrail Event #

{
  "additionalEventData": {
    "AuthenticationMethod": "AuthHeader",
    "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "SignatureVersion": "SigV4",
    "bytesTransferredIn": 0,
    "bytesTransferredOut": 274,
    "x-amz-id-2": "rfW4obUXUJPAoQs2hnZDo3sb9F/kP1rMAGCXUBLTCRb2sjNdwDUnl4hFRRAs2ABSt4yrghlZkSk="
  },
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "Access Denied",
  "eventCategory": "Management",
  "eventID": "15349b87-ec43-44b8-bf51-2381e6dd8552",
  "eventName": "GetAccountPublicAccessBlock",
  "eventSource": "s3.amazonaws.com",
  "eventTime": "2021-04-13T11:36:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "731544447609",
  "requestID": "X1DWMM0KGEZEND7W",
  "requestParameters": {
    "Host": "731544447609.s3-control.us-east-1.amazonaws.com"
  },
  "responseElements": null,
  "sourceIPAddress": "34.12.134.20",
  "userAgent": "[aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback]",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
    "accountId": "731544447609",
    "arn": "arn:aws:iam::731544447609:user/cloudsploit",
    "principalId": "AIDAYTOGP2RLMDEPWZWMJ",
    "type": "IAMUser",
    "userName": "cloudsploit"
  }
}

References #

GetMultiRegionAccessPoint

#
Service
s3

Description

GetMultiRegionAccessPoint recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "fc41dbf5-d94c-4ace-b648-d3f38750d700",
  "eventSource": "s3.amazonaws.com",
  "eventName": "GetMultiRegionAccessPoint",
  "awsRegion": "us-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "8B58F99GM56QS3NK",
  "userAgent": "access-analyzer.amazonaws.com"
}

GetMultiRegionAccessPointPolicy

#
Service
s3

Description

GetMultiRegionAccessPointPolicy recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "f78e99c1-6098-441d-9d48-5defa6012afc",
  "eventSource": "s3.amazonaws.com",
  "eventName": "GetMultiRegionAccessPointPolicy",
  "awsRegion": "us-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "62ZNHDDW37AVGTRC",
  "userAgent": "[aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/s3control#1.69.0 m/E,i]",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "123456789012.s3-control.us-west-2.amazonaws.com"
  }
}

GetMultiRegionAccessPointPolicyStatus

#
Service
s3

Description

GetMultiRegionAccessPointPolicyStatus recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "ec2cb003-5b29-4943-ad1f-072d3c3cbfad",
  "eventSource": "s3.amazonaws.com",
  "eventName": "GetMultiRegionAccessPointPolicyStatus",
  "awsRegion": "us-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "7R79J4DHBFXT4YW6",
  "userAgent": "access-analyzer.amazonaws.com"
}

GetStorageLensConfiguration

#
Service
s3

Description

GetStorageLensConfiguration recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "c510cadf-dc12-4383-b50c-9b5a7b47288a",
  "eventSource": "s3.amazonaws.com",
  "eventName": "GetStorageLensConfiguration",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "RDZM8XKCG2TX8W5F",
  "userAgent": "[aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/s3control#1.69.0 m/E]",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "123456789012.s3-control.us-east-1.amazonaws.com"
  }
}

GetStorageLensConfigurationTagging

#
Service
s3

Description

GetStorageLensConfigurationTagging recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d2decef5-890d-4fef-bd82-2c88df3370a9",
  "eventSource": "s3.amazonaws.com",
  "eventName": "GetStorageLensConfigurationTagging",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "RDZRGP91PD4B0J26",
  "userAgent": "[aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/s3control#1.69.0 m/E]",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "123456789012.s3-control.us-east-1.amazonaws.com"
  }
}

ListAccessGrants

#
Service
s3

Description

ListAccessGrants recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "bdc10e4a-3744-4b8f-881c-d57553a6e3e7",
  "eventSource": "s3.amazonaws.com",
  "eventName": "ListAccessGrants",
  "awsRegion": "eu-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "0E26GC92ECKMDHN4",
  "userAgent": "config.amazonaws.com",
  "errorCode": "AccessGrantsInstanceNotExistsError"
}

ListAccessGrantsInstances

#
Service
s3

Description

ListAccessGrantsInstances recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "93796275-2155-4e1f-86cd-8e9318a4bdce",
  "eventSource": "s3.amazonaws.com",
  "eventName": "ListAccessGrantsInstances",
  "awsRegion": "us-west-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "4KY08KNBX1G0DP8R",
  "userAgent": "config.amazonaws.com"
}

ListAccessGrantsLocations

#
Service
s3

Description

ListAccessGrantsLocations recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "296a2947-9112-4a06-8e2c-06a42f02389b",
  "eventSource": "s3.amazonaws.com",
  "eventName": "ListAccessGrantsLocations",
  "awsRegion": "ap-southeast-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "W08NCHB8NH903M1X",
  "userAgent": "config.amazonaws.com",
  "errorCode": "AccessGrantsInstanceNotExistsError"
}

ListAccessPoints

#
Service
s3

Description

ListAccessPoints recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "722996e2-9bf1-4560-8014-69ec04a47466",
  "eventSource": "s3.amazonaws.com",
  "eventName": "ListAccessPoints",
  "awsRegion": "eu-central-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "TJEAMJEEQTH6SP8C",
  "userAgent": "cloudformation.amazonaws.com"
}

ListMultiRegionAccessPoints

#
Service
s3

Description

ListMultiRegionAccessPoints recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "43802c1d-c034-4e04-8fc0-e1844d075df3",
  "eventSource": "s3.amazonaws.com",
  "eventName": "ListMultiRegionAccessPoints",
  "awsRegion": "us-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "KTBPRNHZMGEWEFAN",
  "userAgent": "access-analyzer.amazonaws.com"
}

ListStorageLensConfigurations

#
Service
s3

Description

ListStorageLensConfigurations recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "d0a36151-e582-433f-ac2c-261acfe5d2b3",
  "eventSource": "s3.amazonaws.com",
  "eventName": "ListStorageLensConfigurations",
  "awsRegion": "ca-central-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "RDZZFD9VTGE3NPK1",
  "userAgent": "[aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/s3control#1.69.0 m/C,E]",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "123456789012.s3-control.ca-central-1.amazonaws.com"
  }
}

ListStorageLensGroups

#
Service
s3

Description

ListStorageLensGroups recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "f0952ac1-ec11-422a-8b30-67892856bb22",
  "eventSource": "s3.amazonaws.com",
  "eventName": "ListStorageLensGroups",
  "awsRegion": "us-west-2",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "FKNKT3R4TEYYHQFS",
  "userAgent": "config.amazonaws.com"
}

PutAccessPointPolicy

#
Service
s3

Description

Associates an access policy with the specified Amazon S3 access point, replacing any existing policy.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Condition (kusto rule field)is_null1 rulekusto
Effect (kusto rule field)eqallow1 rulekusto
Principal (kusto rule field)eq*1 rulekusto
Principal_aws (kusto rule field)eq*1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

AssociateAccessGrantsIdentityCenter

#
Service
s3

Description

Associate your S3 Access Grants instance with an Amazon Web Services IAM Identity Center instance.

CreateAccessGrant

#
Service
s3

Description

Creates an access grant that gives a grantee access to your S3 data.

CreateAccessGrantsInstance

#
Service
s3

Description

Creates an S3 Access Grants instance, which serves as a logical grouping for access grants.

CreateAccessGrantsLocation

#
Service
s3

Description

The S3 data location that you would like to register in your S3 Access Grants instance.

CreateAccessPoint

#
Service
s3

Description

Creates an access point and associates it to a specified bucket.

CreateAccessPointForObjectLambda

#
Service
s3

Description

This operation is not supported by directory buckets.

CreateJob

#
Service
s3

Description

This operation creates an S3 Batch Operations job.

CreateMultiRegionAccessPoint

#
Service
s3

Description

This operation is not supported by directory buckets.

CreateStorageLensGroup

#
Service
s3

Description

Creates a new S3 Storage Lens group and associates it with the specified Amazon Web Services account ID.

DeleteAccessGrant

#
Service
s3

Description

Deletes the access grant from the S3 Access Grants instance.

DeleteAccessGrantsInstance

#
Service
s3

Description

Deletes your S3 Access Grants instance.

DeleteAccessGrantsInstanceResourcePolicy

#
Service
s3

Description

Deletes the resource policy of the S3 Access Grants instance.

DeleteAccessGrantsLocation

#
Service
s3

Description

Deregisters a location from your S3 Access Grants instance.

DeleteAccessPoint

#
Service
s3

Description

Deletes the specified access point.

DeleteAccessPointForObjectLambda

#
Service
s3

Description

This operation is not supported by directory buckets.

DeleteAccessPointPolicy

#
Service
s3

Description

Deletes the access point policy for the specified access point.

DeleteAccessPointPolicyForObjectLambda

#
Service
s3

Description

This operation is not supported by directory buckets.

DeleteAccessPointScope

#
Service
s3

Description

Deletes an existing access point scope for a directory bucket.

DeleteBucketLifecycleConfiguration

#
Service
s3

Description

This action deletes an Amazon S3 on Outposts bucket's lifecycle configuration.

DeleteJobTagging

#
Service
s3

Description

Removes the entire tag set from the specified S3 Batch Operations job.

DeleteMultiRegionAccessPoint

#
Service
s3

Description

This operation is not supported by directory buckets.

DeleteStorageLensConfiguration

#
Service
s3

Description

This operation is not supported by directory buckets.

DeleteStorageLensConfigurationTagging

#
Service
s3

Description

This operation is not supported by directory buckets.

DeleteStorageLensGroup

#
Service
s3

Description

Deletes an existing S3 Storage Lens group.

DescribeJob

#
Service
s3

Description

Retrieves the configuration parameters and status for a Batch Operations job.

DescribeMultiRegionAccessPointOperation

#
Service
s3

Description

This operation is not supported by directory buckets.

DissociateAccessGrantsIdentityCenter

#
Service
s3

Description

Dissociates the Amazon Web Services IAM Identity Center instance from the S3 Access Grants instance.

GetAccessGrant

#
Service
s3

Description

Get the details of an access grant from your S3 Access Grants instance.

GetAccessGrantsInstance

#
Service
s3

Description

Retrieves the S3 Access Grants instance for a Region in your account.

GetAccessGrantsInstanceForPrefix

#
Service
s3

Description

Retrieve the S3 Access Grants instance that contains a particular prefix.

GetAccessGrantsInstanceResourcePolicy

#
Service
s3

Description

Returns the resource policy of the S3 Access Grants instance.

GetAccessGrantsLocation

#
Service
s3

Description

Retrieves the details of a particular location registered in your S3 Access Grants instance.

GetAccessPoint

#
Service
s3

Description

Returns configuration information about the specified access point.

GetAccessPointConfigurationForObjectLambda

#
Service
s3

Description

This operation is not supported by directory buckets.

GetAccessPointForObjectLambda

#
Service
s3

Description

This operation is not supported by directory buckets.

GetAccessPointPolicy

#
Service
s3

Description

Returns the access point policy associated with the specified access point.

GetAccessPointPolicyForObjectLambda

#
Service
s3

Description

This operation is not supported by directory buckets.

GetAccessPointPolicyStatus

#
Service
s3

Description

This operation is not supported by directory buckets.

GetAccessPointPolicyStatusForObjectLambda

#
Service
s3

Description

This operation is not supported by directory buckets.

GetAccessPointScope

#
Service
s3

Description

Returns the access point scope for a directory bucket.

GetBucket

#
Service
s3

Description

Gets an Amazon S3 on Outposts bucket.

GetDataAccess

#
Service
s3

Description

Returns a temporary access credential from S3 Access Grants to the grantee or client application.

GetJobTagging

#
Service
s3

Description

Returns the tags on an S3 Batch Operations job.

GetMultiRegionAccessPointRoutes

#
Service
s3

Description

This operation is not supported by directory buckets.

GetStorageLensGroup

#
Service
s3

Description

Retrieves the Storage Lens group configuration details.

ListAccessPointsForDirectoryBuckets

#
Service
s3

Description

Returns a list of the access points that are owned by the Amazon Web Services account and that are associated with the specified directory bucket.

ListAccessPointsForObjectLambda

#
Service
s3

Description

This operation is not supported by directory buckets.

ListCallerAccessGrants

#
Service
s3

Description

Use this API to list the access grants that grant the caller access to Amazon S3 data through S3 Access Grants.

ListJobs

#
Service
s3

Description

Lists current S3 Batch Operations jobs as well as the jobs that have ended within the last 90 days for the Amazon Web Services account making the request.

ListRegionalBuckets

#
Service
s3

Description

This operation is not supported by directory buckets.

ListTagsForResource

#
Service
s3

Description

This operation allows you to list all of the tags for a specified resource.

PutAccessGrantsInstanceResourcePolicy

#
Service
s3

Description

Updates the resource policy of the S3 Access Grants instance.

PutAccessPointConfigurationForObjectLambda

#
Service
s3

Description

This operation is not supported by directory buckets.

PutAccessPointPolicyForObjectLambda

#
Service
s3

Description

This operation is not supported by directory buckets.

PutAccessPointScope

#
Service
s3

Description

Creates or replaces the access point scope for a directory bucket.

PutJobTagging

#
Service
s3

Description

Sets the supplied tag-set on an S3 Batch Operations job.

PutMultiRegionAccessPointPolicy

#
Service
s3

Description

This operation is not supported by directory buckets.

PutStorageLensConfiguration

#
Service
s3

Description

This operation is not supported by directory buckets.

PutStorageLensConfigurationTagging

#
Service
s3

Description

This operation is not supported by directory buckets.

SubmitMultiRegionAccessPointRoutes

#
Service
s3

Description

This operation is not supported by directory buckets.

TagResource

#
Service
s3

Description

Creates a new user-defined tag or updates an existing tag.

UntagResource

#
Service
s3

Description

This operation removes the specified user-defined tags from an S3 resource.

UpdateAccessGrantsLocation

#
Service
s3

Description

Updates the IAM role of a registered location in your S3 Access Grants instance.

UpdateJobPriority

#
Service
s3

Description

Updates an existing S3 Batch Operations job's priority.

UpdateJobStatus

#
Service
s3

Description

Updates the status for the specified job.

UpdateStorageLensGroup

#
Service
s3

Description

Updates the existing Storage Lens group.