S3
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for S3 rules that match the service but not a specific eventName. | N | Y |
| Copy | Copies an existing S3 object to a new location within S3; logged as a CloudTrail data event. | Y | Y |
| Delete | Removes the public access block configuration for an AWS account; CloudTrail eventName for the DeletePublicAccessBlock API at the account level. | N | Y |
| Delete | Permanently deletes an empty S3 bucket owned by the authenticated sender. | Y | N |
| Delete | Deletes the CORS configuration from a specified S3 bucket. | Y | Y |
| Delete | Removes the server-side encryption configuration from a specified S3 bucket. | Y | Y |
| Delete | Deletes the lifecycle configuration of a specified S3 bucket. | Y | Y |
| Delete | Deletes the resource-based bucket policy from a specified S3 bucket. | Y | Y |
| Delete | Removes the public access block configuration for an S3 bucket; CloudTrail eventName for the DeletePublicAccessBlock API at the bucket level. | Y | Y |
| Delete | Deletes the replication configuration from a specified S3 bucket. | Y | Y |
| Delete | Removes an object from a specified S3 bucket. | Y | Y |
| Get | Returns the access control list (ACL) of an S3 bucket. | Y | Y |
| Get | Retrieves the CORS configuration for a specified S3 bucket. | Y | N |
| Get | Retrieves an inventory configuration for a specified S3 bucket. | Y | N |
| Get | Retrieves a metrics configuration for a specified S3 bucket. | Y | N |
| Get | Retrieves the resource-based bucket policy for a specified S3 bucket. | Y | Y |
| Get | Returns the policy status for a specific S3 bucket, indicating whether the bucket is public. | Y | Y |
| Get | Retrieves the public access block configuration for a specified S3 bucket. | Y | Y |
| Get | Retrieves the tag set associated with a specified S3 bucket. | Y | N |
| Get | Returns the versioning state of an S3 bucket. | Y | Y |
| Get | Retrieves an object from a specified S3 bucket. | Y | Y |
| List | Lists the objects in a specified S3 bucket. | N | Y |
| List | Lists all S3 buckets owned by the authenticated requester. | Y | Y |
| List | Lists some or all objects in a specified S3 bucket. | Y | Y |
| Put | Creates or modifies the public access block configuration for an AWS account. | N | Y |
| Put | Sets the permissions on an existing S3 bucket using access control lists (ACLs). | Y | Y |
| Put | Creates or replaces the lifecycle configuration on an S3 bucket (can be abused to expire/delete objects). | Y | Y |
| Put | Sets the logging parameters for a specified S3 bucket. | Y | Y |
| Put | Applies a resource-based bucket policy to an S3 bucket. | Y | Y |
| Put | Creates or modifies the public access block configuration for an S3 bucket. | Y | Y |
| Put | Creates or replaces the replication configuration for an S3 bucket; CloudTrail eventName for the PutReplicationConfiguration API. | Y | Y |
| Put | Sets the versioning state for a specified S3 bucket. | Y | Y |
| Put | Sets the configuration of the website for a specified S3 bucket. | Y | Y |
| Put | Sets the default server-side encryption configuration for a specified S3 bucket. | N | Y |
| Put | Creates or replaces the lifecycle configuration for a specified S3 bucket. | N | Y |
| Put | Adds an object to a specified S3 bucket. | Y | Y |
| Put | Creates or replaces the replication configuration for a specified S3 bucket. | N | Y |
| Replicate | Replicates an object to a destination bucket as part of a replication configuration. | N | Y |
| Restore | Restores a temporarily deleted or archived object in a specified S3 bucket. | Y | Y |
| Abort | This operation aborts a multipart upload. | Y | N |
| Complete | Completes a multipart upload by assembling previously uploaded parts. | Y | N |
| Create | This action creates an Amazon S3 bucket. | Y | N |
| Create | Creates an S3 Metadata V2 metadata configuration for a general purpose bucket. | N | N |
| Create | We recommend that you create your S3 Metadata configurations by using the V2 CreateBucketMetadataConfiguration API operation. | N | N |
| Create | End of support notice: As of October 1, 2025, Amazon S3 has discontinued support for Email Grantee Access Control Lists (ACLs). | Y | N |
| Create | Creates a session that establishes temporary security credentials to support fast authentication and authorization for the Zonal endpoint API operations on directory buckets. | N | N |
| Delete | This operation is not supported for directory buckets. | Y | N |
| Delete | This operation is not supported for directory buckets. | Y | N |
| Delete | Deletes an S3 Inventory configuration (identified by the inventory ID) from the bucket. | Y | N |
| Delete | Deletes an S3 Metadata configuration from a general purpose bucket. | Y | N |
| Delete | We recommend that you delete your S3 Metadata configurations by using the V2 DeleteBucketMetadataTableConfiguration API operation. | Y | N |
| Delete | Deletes a metrics configuration for the Amazon CloudWatch request metrics (specified by the metrics configuration ID) from the bucket. | Y | N |
| Delete | This operation is not supported for directory buckets. | Y | N |
| Delete | This operation is not supported for directory buckets. | Y | N |
| Delete | This operation is not supported for directory buckets. | Y | N |
| Delete | Deletes a specific annotation from an Amazon S3 object. | Y | N |
| Delete | This operation enables you to delete multiple objects from a bucket using a single HTTP request. | Y | Y |
| Delete | This operation is not supported for directory buckets. | Y | N |
| Delete | This operation is not supported for directory buckets. | N | N |
| Get | Returns the attribute-based access control (ABAC) property of the general purpose bucket. | Y | N |
| Get | This operation is not supported for directory buckets. | Y | N |
| Get | This operation is not supported for directory buckets. | Y | N |
| Get | Returns the default encryption configuration for an Amazon S3 bucket. | Y | N |
| Get | This operation is not supported for directory buckets. | Y | N |
| Get | For an updated version of this API, see GetBucketLifecycleConfiguration. | Y | N |
| Get | Using the GetBucketLocation operation is no longer a best practice. | Y | N |
| Get | This operation is not supported for directory buckets. | Y | N |
| Get | Retrieves the S3 Metadata configuration for a general purpose bucket. | Y | N |
| Get | We recommend that you retrieve your S3 Metadata configurations by using the V2 GetBucketMetadataTableConfiguration API operation. | Y | N |
| Get | This operation is not supported for directory buckets. | Y | N |
| Get | This operation is not supported for directory buckets. | Y | N |
| Get | This operation is not supported for directory buckets. | Y | N |
| Get | This operation is not supported for directory buckets. | Y | N |
| Get | This operation is not supported for directory buckets. | Y | N |
| Get | This operation is not supported for directory buckets. | Y | Y |
| Get | Retrieves an annotation from an Amazon S3 object. | N | N |
| Get | Retrieves all of the metadata from an object without returning the object itself. | N | N |
| Get | This operation is not supported for directory buckets. | N | N |
| Get | This operation is not supported for directory buckets. | Y | N |
| Get | This operation is not supported for directory buckets. | N | N |
| Get | This operation is not supported for directory buckets. | N | N |
| Get | This operation is not supported for directory buckets. | N | N |
| Head | You can use this operation to determine if a bucket exists and if you have permission to access it. | N | N |
| Head | The HEAD operation retrieves metadata from an object without returning the object itself. | N | N |
| List | Returns a list of all Amazon S3 directory buckets owned by the authenticated sender of the request. | N | N |
| List | This operation lists in-progress multipart uploads in a bucket. | Y | N |
| List | Lists the annotations attached to an Amazon S3 object. | N | N |
| List | Returns some or all (up to 1,000) of the objects in a bucket with each request. | N | N |
| List | This operation is not supported for directory buckets. | N | N |
| List | Lists the parts that have been uploaded for a specific multipart upload. | N | N |
| Put | Sets the attribute-based access control (ABAC) property of the general purpose bucket. | Y | N |
| Put | This operation is not supported for directory buckets. | N | N |
| Put | This operation is not supported for directory buckets. | Y | N |
| Put | This operation is not supported for directory buckets. | Y | Y |
| Put | This operation configures default encryption and Amazon S3 Bucket Keys for an existing bucket. | Y | N |
| Put | This operation is not supported for directory buckets. | Y | N |
| Put | This implementation of the PUT action adds an S3 Inventory configuration (identified by the inventory ID) to the bucket. | Y | N |
| Put | Creates a new lifecycle configuration for the bucket or replaces an existing lifecycle configuration. | N | N |
| Put | Sets a metrics configuration (specified by the metrics configuration ID) for the bucket. | Y | N |
| Put | This operation is not supported for directory buckets. | Y | N |
| Put | This operation is not supported for directory buckets. | N | N |
| Put | This operation is not supported for directory buckets. | Y | N |
| Put | This operation is not supported for directory buckets. | Y | N |
| Put | This operation is not supported for directory buckets. | Y | N |
| Put | End of support notice: As of October 1, 2025, Amazon S3 has discontinued support for Email Grantee Access Control Lists (ACLs). | Y | Y |
| Put | Attaches an annotation to an Amazon S3 object. | Y | N |
| Put | This operation is not supported for directory buckets. | N | N |
| Put | This operation is not supported for directory buckets. | N | N |
| Put | This operation is not supported for directory buckets. | N | N |
| Put | This operation is not supported for directory buckets. | Y | N |
| Put | This operation is not supported for directory buckets. | N | N |
| Rename | Renames an existing object in a directory bucket that uses the S3 Express One Zone storage class. | N | N |
| Select | This operation is not supported for directory buckets. | N | N |
| Update | Updates the annotation table configuration for an Amazon S3 bucket's metadata configuration. | Y | N |
| Update | Enables or disables a live inventory table for an S3 Metadata configuration on a general purpose bucket. | Y | N |
| Update | Enables or disables journal table record expiration for an S3 Metadata configuration on a general purpose bucket. | Y | N |
| Update | This operation is not supported for directory buckets or Amazon S3 on Outposts buckets. | N | N |
| Upload | Uploads a part in a multipart upload. | Y | N |
| Upload | Uploads a part by copying data from an existing object as data source. | Y | N |
| Write | This operation is not supported for directory buckets. | N | N |
| Get | Retrieves the public access block configuration for an AWS account; CloudTrail eventName for the GetPublicAccessBlock API at the account level. | Y | N |
| Get | GetMultiRegionAccessPoint recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetMultiRegionAccessPointPolicy recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetMultiRegionAccessPointPolicyStatus recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetStorageLensConfiguration recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Get | GetStorageLensConfigurationTagging recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListAccessGrants recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListAccessGrantsInstances recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListAccessGrantsLocations recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListAccessPoints recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListMultiRegionAccessPoints recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListStorageLensConfigurations recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| List | ListStorageLensGroups recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Put | Associates an access policy with the specified Amazon S3 access point, replacing any existing policy. | N | Y |
| Associate | Associate your S3 Access Grants instance with an Amazon Web Services IAM Identity Center instance. | N | N |
| Create | Creates an access grant that gives a grantee access to your S3 data. | N | N |
| Create | Creates an S3 Access Grants instance, which serves as a logical grouping for access grants. | N | N |
| Create | The S3 data location that you would like to register in your S3 Access Grants instance. | N | N |
| Create | Creates an access point and associates it to a specified bucket. | N | N |
| Create | This operation is not supported by directory buckets. | N | N |
| Create | This operation creates an S3 Batch Operations job. | N | N |
| Create | This operation is not supported by directory buckets. | N | N |
| Create | Creates a new S3 Storage Lens group and associates it with the specified Amazon Web Services account ID. | N | N |
| Delete | Deletes the access grant from the S3 Access Grants instance. | N | N |
| Delete | Deletes your S3 Access Grants instance. | N | N |
| Delete | Deletes the resource policy of the S3 Access Grants instance. | N | N |
| Delete | Deregisters a location from your S3 Access Grants instance. | N | N |
| Delete | Deletes the specified access point. | N | N |
| Delete | This operation is not supported by directory buckets. | N | N |
| Delete | Deletes the access point policy for the specified access point. | N | N |
| Delete | This operation is not supported by directory buckets. | N | N |
| Delete | Deletes an existing access point scope for a directory bucket. | N | N |
| Delete | This action deletes an Amazon S3 on Outposts bucket's lifecycle configuration. | N | N |
| Delete | Removes the entire tag set from the specified S3 Batch Operations job. | N | N |
| Delete | This operation is not supported by directory buckets. | N | N |
| Delete | This operation is not supported by directory buckets. | N | N |
| Delete | This operation is not supported by directory buckets. | N | N |
| Delete | Deletes an existing S3 Storage Lens group. | N | N |
| Describe | Retrieves the configuration parameters and status for a Batch Operations job. | N | N |
| Describe | This operation is not supported by directory buckets. | N | N |
| Dissociate | Dissociates the Amazon Web Services IAM Identity Center instance from the S3 Access Grants instance. | N | N |
| Get | Get the details of an access grant from your S3 Access Grants instance. | N | N |
| Get | Retrieves the S3 Access Grants instance for a Region in your account. | N | N |
| Get | Retrieve the S3 Access Grants instance that contains a particular prefix. | N | N |
| Get | Returns the resource policy of the S3 Access Grants instance. | N | N |
| Get | Retrieves the details of a particular location registered in your S3 Access Grants instance. | N | N |
| Get | Returns configuration information about the specified access point. | N | N |
| Get | This operation is not supported by directory buckets. | N | N |
| Get | This operation is not supported by directory buckets. | N | N |
| Get | Returns the access point policy associated with the specified access point. | N | N |
| Get | This operation is not supported by directory buckets. | N | N |
| Get | This operation is not supported by directory buckets. | N | N |
| Get | This operation is not supported by directory buckets. | N | N |
| Get | Returns the access point scope for a directory bucket. | N | N |
| Get | Gets an Amazon S3 on Outposts bucket. | N | N |
| Get | Returns a temporary access credential from S3 Access Grants to the grantee or client application. | N | N |
| Get | Returns the tags on an S3 Batch Operations job. | N | N |
| Get | This operation is not supported by directory buckets. | N | N |
| Get | Retrieves the Storage Lens group configuration details. | N | N |
| List | Returns a list of the access points that are owned by the Amazon Web Services account and that are associated with the specified directory bucket. | N | N |
| List | This operation is not supported by directory buckets. | N | N |
| List | Use this API to list the access grants that grant the caller access to Amazon S3 data through S3 Access Grants. | N | N |
| List | Lists current S3 Batch Operations jobs as well as the jobs that have ended within the last 90 days for the Amazon Web Services account making the request. | N | N |
| List | This operation is not supported by directory buckets. | N | N |
| List | This operation allows you to list all of the tags for a specified resource. | N | N |
| Put | Updates the resource policy of the S3 Access Grants instance. | N | N |
| Put | This operation is not supported by directory buckets. | N | N |
| Put | This operation is not supported by directory buckets. | N | N |
| Put | Creates or replaces the access point scope for a directory bucket. | N | N |
| Put | Sets the supplied tag-set on an S3 Batch Operations job. | N | N |
| Put | This operation is not supported by directory buckets. | N | N |
| Put | This operation is not supported by directory buckets. | N | N |
| Put | This operation is not supported by directory buckets. | N | N |
| Submit | This operation is not supported by directory buckets. | N | N |
| Tag | Creates a new user-defined tag or updates an existing tag. | N | N |
| Untag | This operation removes the specified user-defined tags from an S3 resource. | N | N |
| Update | Updates the IAM role of a registered location in your S3 Access Grants instance. | N | N |
| Update | Updates an existing S3 Batch Operations job's priority. | N | N |
| Update | Updates the status for the specified job. | N | N |
| Update | Updates the existing Storage Lens group. | N | N |
any: S3 (catch-all)
#Description
Catch-all entry for S3 rules that match the service but not a specific eventName.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1530, T1580, T1619, T1657
CopyObject
#Description
Copies an existing S3 object to a new location within S3; logged as a CloudTrail data event.
CloudTrail data event: not logged by a standard management-events trail. Requires explicit data-event configuration (an advanced event selector) on the trail or CloudTrail Lake; absence of this event does not prove the action did not occur. S3 data event. Requires S3 data-event logging. Generates events in both source and destination bucket trails (if different). Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SSEApplied": "SSE_KMS",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0.0,
"bytesTransferredOut": 234.0,
"x-amz-id-2": "fqzX1iZV6ImDtkFxbGvziOE6fUwryRa+PhnLckfVAkLNHdbCAHNq4l/yckUd1a2HNJPL6NAS01U="
},
"awsRegion": "us-west-2",
"eventCategory": "Data",
"eventID": "b20d43de-175d-4443-acd7-f5f3e587ae00",
"eventName": "CopyObject",
"eventSource": "s3.amazonaws.com",
"eventTime": "2021-01-11T12:40:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": false,
"readOnly": false,
"recipientAccountId": "111111111111",
"requestID": "6A7359F7A9414B02",
"requestParameters": {
"Host": "patricktestbucketencrypt.s3.us-west-2.amazonaws.com",
"bucketName": "patricktestbucketencrypt",
"key": "kms_aws_events_encrypted.json",
"x-amz-copy-source": "patricktestbucketencrypt/kms_aws_events.json",
"x-amz-server-side-encryption": "aws:kms",
"x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1"
},
"resources": [
{
"ARN": "arn:aws:s3:::patricktestbucketencrypt/kms_aws_events_encrypted.json",
"type": "AWS::S3::Object"
},
{
"ARN": "arn:aws:s3:::patricktestbucketencrypt",
"accountId": "111111111111",
"type": "AWS::S3::Bucket"
},
{
"ARN": "arn:aws:s3:::patricktestbucketencrypt",
"accountId": "111111111111",
"type": "AWS::S3::Bucket"
},
{
"ARN": "arn:aws:s3:::patricktestbucketencrypt/kms_aws_events.json",
"type": "AWS::S3::Object"
}
],
"responseElements": {
"x-amz-server-side-encryption": "aws:kms",
"x-amz-server-side-encryption-aws-kms-key-id": "arn:aws:kms:us-west-2:111111111111:key/f2a82583-a7d3-4c92-8787-fe2baab1cee1"
},
"sourceIPAddress": "95.90.199.65",
"userAgent": "[aws-cli/2.0.45 Python/3.7.4 Darwin/20.2.0 exe/x86_64 command/s3.cp]",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLJ2OYSF6E",
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:user/patrick_cli",
"principalId": "AIDAYTOGP2RLNALZHZ6KX",
"type": "IAMUser",
"userName": "patrick_cli"
}
}
Common Indicators #
Field Kind Value Rules Vendors aws.cloudtrail.flattened.request_parameters.x-amz-server-side-encryption-customer-algorithm (elastic rule field)eq aes2562 rules elastic aws::sourceIPAddress (panther rule field)is_not_null 1 rule panther Detection Rules #
Elastic #
T1486↳ also matches PutObject T1486T1078, T1078.004, T1486↳ also matches PutObject Splunk #
CopyObject event where server-side encryption with AWS KMS is specified. This activity…T1486Panther #
References #
DeleteAccountPublicAccessBlock
#Description
Removes the public access block configuration for an AWS account; CloudTrail eventName for the DeletePublicAccessBlock API at the account level.
CloudTrail management event, logged by default. Account-level S3 control API (s3control). Logged as a management event in the account's trail. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
YARA-L #
T1562↳ also matches DeleteBucketPublicAccessBlock, PutAccountPublicAccessBlock, PutBucketPublicAccessBlock Panther #
T1562
DeleteBucket
#Description
Permanently deletes an empty S3 bucket owned by the authenticated sender.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"eventVersion": "1.11",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE"
},
"eventTime": "2026-07-28T20:59:40Z",
"eventSource": "s3.amazonaws.com",
"eventName": "DeleteBucket",
"awsRegion": "us-west-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "[aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#s3api.delete-bucket]",
"requestParameters": {
"bucketName": "dw-harn-s3-eb786637",
"Host": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
},
"responseElements": null,
"additionalEventData": {
"SignatureVersion": "SigV4",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"bytesTransferredIn": 0,
"AuthenticationMethod": "AuthHeader",
"x-amz-id-2": "b+Lki7+mXZyvNK4ZjzI8HVCdrhPgCqiIQs5ySbvmYLN9ui/UdDIPpFCGFnOLB4zwKL7Q9wazW6g=",
"bytesTransferredOut": 0
},
"requestID": "RDXBV8FZ46VC57G5",
"eventID": "4a64a3bd-7ffc-4749-8684-d88e73d19d44",
"readOnly": false,
"resources": [
{
"accountId": "123456789012",
"type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::dw-harn-s3-eb786637"
}
],
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
}
}
DeleteBucketCors
#Description
Deletes the CORS configuration from a specified S3 bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 0,
"x-amz-id-2": "RpNRqhkqgcK8sWz03N9lMveWojNWV5z5c1YwrpKFrVXNLEnksdy75pooJhGUKvkovApAlsArm2s="
},
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f5a248b7-f196-4ef8-a7e5-0668dd7166fa",
"eventName": "DeleteBucketCors",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:08:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7Y2YA0ACYV5B12EM",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"bucketName": "dwfix-s3-123456789012-uw1",
"cors": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1070, T1490, T1562, T1562.001, T1562.008↳ also matches DeleteBucketEncryption, DeleteBucketLifecycle, DeleteBucketPolicy, DeleteBucketReplication Panther #
T1567↳ also matches DeleteBucketLifecycle, DeleteBucketPolicy, DeleteBucketReplication, PutBucketAcl, PutBucketLifecycle, PutBucketPolicy, PutBucketReplication, PutBucketCors
DeleteBucketEncryption
#Description
Removes the server-side encryption configuration from a specified S3 bucket.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 0,
"x-amz-id-2": "hG2WYrbWlc/oCO+lcpulcsoZieRNMCONOypwMv9vQkS1pfqi03zvDY3IIEtDlwxlGzseOPAzq0s="
},
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "c0a8bd07-7b4e-4f81-aa34-67096a1f2325",
"eventName": "DeleteBucketEncryption",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:08:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "CPH8E7CNKPWCGWFB",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"bucketName": "dwfix-s3-123456789012-uw1",
"encryption": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Elastic #
T1070, T1490, T1562, T1562.001, T1562.008↳ also matches DeleteBucketCors, DeleteBucketLifecycle, DeleteBucketPolicy, DeleteBucketReplication Panther #
T1485, T1562
DeleteBucketLifecycle
#Description
Deletes the lifecycle configuration of a specified S3 bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 0,
"x-amz-id-2": "ABu8KDu4dp2IbUOExQuYJCHxqjkkiuCoUOOIPMtnzSVZKjHOo6yF4T70mEsiFuWNKf7fkJLCPt4="
},
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "8ec435c9-76d1-47d1-8eae-8a8864e3dff5",
"eventName": "DeleteBucketLifecycle",
"eventSource": "s3.amazonaws.com",
"eventTime": "2023-07-10T12:07:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "0VTYVM320ZVNB8CM",
"requestParameters": {
"Host": "stratus-red-team-ctlr-bucket-zqfsvooxqj.s3.us-east-1.amazonaws.com",
"bucketName": "stratus-red-team-ctlr-bucket-zqfsvooxqj",
"lifecycle": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::stratus-red-team-ctlr-bucket-zqfsvooxqj",
"accountId": "123837392027",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "stratus-red-team-ctlr-bucket-zqfsvooxqj.s3.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "[stratus-red-team_1807d824-ddbc-4a01-9249-8175115f1397]",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1070, T1490, T1562, T1562.001, T1562.008↳ also matches DeleteBucketCors, DeleteBucketEncryption, DeleteBucketPolicy, DeleteBucketReplication Panther #
T1567↳ also matches DeleteBucketCors, DeleteBucketPolicy, DeleteBucketReplication, PutBucketAcl, PutBucketLifecycle, PutBucketPolicy, PutBucketReplication, PutBucketCors
References #
DeleteBucketPolicy
#Description
Deletes the resource-based bucket policy from a specified S3 bucket.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 0,
"x-amz-id-2": "ri2kYFQG4IDcZT+VgIXi/VJMZ4k7oSrx/E6+Tq4qICuZWzqo2/kFoqii+/nvMkPpYZBkPiNnPxQ="
},
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "b921a62d-9241-42a2-bb3c-6821e55c20cd",
"eventName": "DeleteBucketPolicy",
"eventSource": "s3.amazonaws.com",
"eventTime": "2023-07-10T12:28:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "Z8ACGF9H5JD4TYH9",
"requestParameters": {
"Host": "stratus-red-team-bdbp-lhfzvgcamn.s3.us-east-1.amazonaws.com",
"bucketName": "stratus-red-team-bdbp-lhfzvgcamn",
"policy": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::stratus-red-team-bdbp-lhfzvgcamn",
"accountId": "123837392027",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "stratus-red-team-bdbp-lhfzvgcamn.s3.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "[stratus-red-team_b1d7e3ac-1a0f-40b2-b062-a4297558e42f]",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Elastic #
T1070, T1490, T1562, T1562.001, T1562.008↳ also matches DeleteBucketCors, DeleteBucketEncryption, DeleteBucketLifecycle, DeleteBucketReplication Panther #
T1567↳ also matches DeleteBucketCors, DeleteBucketLifecycle, DeleteBucketReplication, PutBucketAcl, PutBucketLifecycle, PutBucketPolicy, PutBucketReplication, PutBucketCors References #
DeleteBucketPublicAccessBlock
#Description
Removes the public access block configuration for an S3 bucket; CloudTrail eventName for the DeletePublicAccessBlock API at the bucket level.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 298,
"x-amz-id-2": "piKxUz94ssEurGMC2tymwHbVLrAHmpLFxxm2/toOSt+gdXQe/cLfHZFBsbTf/nRzVky15hQMSAw="
},
"awsRegion": "us-west-1",
"errorCode": "NoSuchBucket",
"errorMessage": "The specified bucket does not exist",
"eventCategory": "Management",
"eventID": "fc922f9c-210d-48ba-9e45-a9023c47cde2",
"eventName": "DeleteBucketPublicAccessBlock",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:26:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "S0YQXV8Q9GG3D4KZ",
"requestParameters": {
"Host": "dw-probe.s3.us-west-1.amazonaws.com",
"bucketName": "dw-probe",
"publicAccessBlock": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
YARA-L #
T1562↳ also matches DeleteAccountPublicAccessBlock, PutAccountPublicAccessBlock, PutBucketPublicAccessBlock Panther #
T1190, T1562
DeleteBucketReplication
#Description
Deletes the replication configuration from a specified S3 bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 298,
"x-amz-id-2": "Fb2rUZ+McIyCdhrL+WBN33uUnVtw8HzLWAWvA2+pISTvMhLyANwchng28q5uyEFM8Sp0oCqyFNQ="
},
"awsRegion": "us-west-1",
"errorCode": "NoSuchBucket",
"errorMessage": "The specified bucket does not exist",
"eventCategory": "Management",
"eventID": "a6c004af-5365-4289-96df-6da14e8b515d",
"eventName": "DeleteBucketReplication",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:26:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "S0YXZNQP9HHA09FH",
"requestParameters": {
"Host": "dw-probe.s3.us-west-1.amazonaws.com",
"bucketName": "dw-probe",
"replication": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1070, T1490, T1562, T1562.001, T1562.008↳ also matches DeleteBucketCors, DeleteBucketEncryption, DeleteBucketLifecycle, DeleteBucketPolicy Panther #
T1485, T1562T1567↳ also matches DeleteBucketCors, DeleteBucketLifecycle, DeleteBucketPolicy, PutBucketAcl, PutBucketLifecycle, PutBucketPolicy, PutBucketReplication, PutBucketCors
DeleteObject
#Description
Removes an object from a specified S3 bucket.
CloudTrail data event: not logged by a standard management-events trail. Requires explicit data-event configuration (an advanced event selector) on the trail or CloudTrail Lake; absence of this event does not prove the action did not occur. S3 data event. Requires S3 data-event logging on the trail (advanced event selector on AWS::S3::Object). Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 0,
"x-amz-id-2": "ZFD39juNHPmj2SyQuQ1dAnhb1zdZ6FoQsJXsqdb/0gqdTh63T9vOMJJm8k6aEvWt2b/bvkMHncar7NPxuwHWuG6OtC9TGWuz"
},
"awsRegion": "us-west-1",
"eventCategory": "Data",
"eventID": "72b60490-9d47-470e-ba87-5c18025cf501",
"eventName": "DeleteObject",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:07:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": false,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7Y2X813VDT5T736Y",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"bucketName": "dwfix-s3-123456789012-uw1",
"key": "dw2.txt"
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
},
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1/dw2.txt",
"type": "AWS::S3::Object"
}
],
"responseElements": {
"x-amz-delete-marker": "true",
"x-amz-version-id": "tPT4tHw.vYXuNP6nw_.CmLbT6kLJd.i2"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Elastic #
T1485, T1530, T1565, T1565.001, T1619↳ also matches GetObject, ListBucket, ListObjects, PutObject Panther #
GetBucketAcl
#Description
Returns the access control list (ACL) of an S3 bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 552,
"x-amz-id-2": "DHHJ5nPs/IFMD8ZnPDTj7jK2Y5p9Lbi4Llx+0k5M+ryQha+ilD7Id4HYRCj5pTQlOEQEa8kqTnAclxWPpL/E8g=="
},
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "d9a07e9d-28ac-45d9-b8ef-43433808f2f0",
"eventName": "GetBucketAcl",
"eventSource": "s3.amazonaws.com",
"eventTime": "2023-07-10T11:42:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "NDWM1TJTAVTRM8FN",
"requestParameters": {
"Host": "baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w.s3.us-east-1.amazonaws.com",
"acl": "",
"bucketName": "baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w"
},
"resources": [
{
"ARN": "arn:aws:s3:::baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w",
"accountId": "123837392027",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "10.248.16.43",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w.s3.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "[S3Console/0.4, aws-internal/3 aws-sdk-java/1.12.488 Linux/5.4.247-169.350.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.372-b08 java/1.8.0_372 vendor/Oracle_Corporation cfg/retry-mode/standard]",
"userIdentity": {
"accessKeyId": "AKIATFQZ7NSC8Q4X21BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/benjamin",
"principalId": "AIDATFQR7NSC5U6Q3TMDR",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T11:42:31Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "benjamin"
},
"vpcEndpointId": "vpce-f40dc59d"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aws::sessionCredentialFromConsole (elastic rule field) | is_null | | 1 rule | elastic |
aws::userIdentity.type (elastic rule field) | ne | awsservice | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1526, T1530, T1580, T1619↳ also matches GetBucketPolicy, GetBucketPolicyStatus, GetBucketPublicAccessBlock, GetBucketVersioning
References #
GetBucketCors
#Description
Retrieves the CORS configuration for a specified S3 bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 354,
"x-amz-id-2": "4RS9BMomnioURtCQrrrpCVvsqlbvRwVkrtj4kkN93TyW1xzrSFC1sm2AVhg4d0K1dnbr/XFYCszULdYRHCV8Yw=="
},
"awsRegion": "us-east-1",
"errorCode": "NoSuchCORSConfiguration",
"errorMessage": "The CORS configuration does not exist",
"eventCategory": "Management",
"eventID": "61b38ec9-0b96-44c4-a90b-d5a79439503e",
"eventName": "GetBucketCors",
"eventSource": "s3.amazonaws.com",
"eventTime": "2023-07-10T12:00:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "DXX0S9N6W7MF8MP2",
"requestParameters": {
"Host": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
"bucketName": "stratus-red-team-ctes-bucket-qyxyekjbtk",
"cors": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::stratus-red-team-ctes-bucket-qyxyekjbtk",
"accountId": "123837392027",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "[APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_1d949e3e-4092-4c96-a6ef-96a967510a46 HashiCorp-terraform-exec/0.17.3]",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
GetBucketInventoryConfiguration
#Description
Retrieves an inventory configuration for a specified S3 bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 189,
"x-amz-id-2": "v7IN8HkbTsFB6SUBbWpN1+GTkZgkEQhzGKJPaYy96IDDw0Mm7onMdht6Fe+P3O/lZenVUHEcO5s="
},
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "383842a4-cd7a-40f9-bd3a-6e414b7ae089",
"eventName": "GetBucketInventoryConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2021-07-07T17:59:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "AC28AN05GCG4Q2EK",
"requestParameters": {
"Host": "s3.us-east-2.amazonaws.com",
"bucketName": "cado-response-cados3bucketalt-1v7p4ao8z6xku",
"inventory": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::cado-response-cados3bucketalt-1v7p4ao8z6xku",
"accountId": "797507667711",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "213.205.197.162",
"userAgent": "[S3Console/0.4, aws-internal/3 aws-sdk-java/1.11.1002 Linux/5.4.116-64.217.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.282-b08 java/1.8.0_282 vendor/Oracle_Corporation cfg/retry-mode/legacy]",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI372QWMLG4E",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
},
"vpcEndpointId": "vpce-eca44785"
}
References #
GetBucketMetricsConfiguration
#Description
Retrieves a metrics configuration for a specified S3 bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"x-amz-id-2": "DRnthuB7AtIk5kz+AOQcA8Jl9kIaFL50WiHJ5mht47H48Nygl/zTsIEEy/jqZUNZYELix2nSoRU="
},
"awsRegion": "us-east-1",
"errorCode": "NoSuchBucket",
"errorMessage": "The specified bucket does not exist",
"eventID": "00a9c555-72c5-477d-8850-feca9b5e8b1f",
"eventName": "GetBucketMetricsConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2020-09-21T04:28:05Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "5E17183CBB69805",
"requestParameters": {
"Host": "s3.amazonaws.com",
"bucketName": "dummy_data",
"id": "dummy_data",
"metrics": ""
},
"responseElements": null,
"sourceIPAddress": "9.240.250.1",
"userAgent": "[Boto3/1.14.51 Python/3.8.5 Linux/4.19.76-linuxkit Botocore/1.17.51]",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetBucketPolicy
#Description
Retrieves the resource-based bucket policy for a specified S3 bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 373,
"x-amz-id-2": "f2vaS6JPTLdKw37mgdFv5DyoXG70Bhv2oYdQdYMz5rhp297ibIqaToYq/m65r+tgjYs7KnXmTAk="
},
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "c20d93d2-87e1-483d-9c6c-9cdfc35671d4",
"eventName": "GetBucketPolicy",
"eventSource": "s3.amazonaws.com",
"eventTime": "2023-07-10T11:42:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "GXK985FFMWTE90RA",
"requestParameters": {
"Host": "baker221b-bucketsevidenceeeedc25d-1q9cl0tuy4gbm.s3.us-east-1.amazonaws.com",
"bucketName": "baker221b-bucketsevidenceeeedc25d-1q9cl0tuy4gbm",
"policy": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::baker221b-bucketsevidenceeeedc25d-1q9cl0tuy4gbm",
"accountId": "123837392027",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "10.248.16.43",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "baker221b-bucketsevidenceeeedc25d-1q9cl0tuy4gbm.s3.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "[Boto3/1.26.165 Python/3.10.6 Linux/5.19.0-46-generic Botocore/1.29.165]",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSCUXC3DDDP",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/benjamin",
"principalId": "AIDATFQR7NSC5U6Q3TMDR",
"type": "IAMUser",
"userName": "benjamin"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aws::sessionCredentialFromConsole (elastic rule field) | is_null | | 1 rule | elastic |
aws::userIdentity.type (elastic rule field) | ne | awsservice | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1526, T1530, T1580, T1619↳ also matches GetBucketAcl, GetBucketPolicyStatus, GetBucketPublicAccessBlock, GetBucketVersioning
References #
GetBucketPolicyStatus
#Description
Returns the policy status for a specific S3 bucket, indicating whether the bucket is public.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 142,
"x-amz-id-2": "nLku2A0cBs+pH6IZJ3sXVsk7KOqQVqCKmaJIjQ68P/itPODLWmR7QT0+/tKDb3YGKv90+394cTWPli6TY065Kg=="
},
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "aeeaa143-69ff-47d3-9d62-8356f01e9a8c",
"eventName": "GetBucketPolicyStatus",
"eventSource": "s3.amazonaws.com",
"eventTime": "2023-07-10T11:42:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "NDWKK8R5MVJJW7RE",
"requestParameters": {
"Host": "baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w.s3.us-east-1.amazonaws.com",
"bucketName": "baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w",
"policyStatus": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w",
"accountId": "123837392027",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "10.248.16.43",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w.s3.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "[S3Console/0.4, aws-internal/3 aws-sdk-java/1.12.488 Linux/5.4.247-169.350.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.372-b08 java/1.8.0_372 vendor/Oracle_Corporation cfg/retry-mode/standard]",
"userIdentity": {
"accessKeyId": "AKIATFQZ7NSC8Q4X21BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/benjamin",
"principalId": "AIDATFQR7NSC5U6Q3TMDR",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T11:42:31Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "benjamin"
},
"vpcEndpointId": "vpce-f40dc59d"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aws::sessionCredentialFromConsole (elastic rule field) | is_null | | 1 rule | elastic |
aws::userIdentity.type (elastic rule field) | ne | awsservice | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1526, T1530, T1580, T1619↳ also matches GetBucketAcl, GetBucketPolicy, GetBucketPublicAccessBlock, GetBucketVersioning
References #
GetBucketPublicAccessBlock
#Description
Retrieves the public access block configuration for a specified S3 bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 326,
"x-amz-id-2": "6YyGGLKZXYf3vfASwZOXeSfV+THvl/YamrZ0rtLHzpt4vyqnkTLB3n1KJb2VdOujH+dvCFs2gbAH0hMUI3+0tw=="
},
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "3c856bc0-1a07-4c18-89d9-4d9205856714",
"eventName": "GetBucketPublicAccessBlock",
"eventSource": "s3.amazonaws.com",
"eventTime": "2023-07-10T11:42:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "NDWZRY56ZA5P31TT",
"requestParameters": {
"Host": "baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w.s3.us-east-1.amazonaws.com",
"bucketName": "baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w",
"publicAccessBlock": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w",
"accountId": "123837392027",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "10.248.16.43",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "baker221b-bucketssecuritylogsbef08b3e-13nrzhi7fcs7w.s3.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "[S3Console/0.4, aws-internal/3 aws-sdk-java/1.12.488 Linux/5.4.247-169.350.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.372-b08 java/1.8.0_372 vendor/Oracle_Corporation cfg/retry-mode/standard]",
"userIdentity": {
"accessKeyId": "AKIATFQZ7NSC8Q4X21BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/benjamin",
"principalId": "AIDATFQR7NSC5U6Q3TMDR",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T11:42:31Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "benjamin"
},
"vpcEndpointId": "vpce-f40dc59d"
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aws::sessionCredentialFromConsole (elastic rule field) | is_null | | 1 rule | elastic |
aws::userIdentity.type (elastic rule field) | ne | awsservice | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1526, T1530, T1580, T1619↳ also matches GetBucketAcl, GetBucketPolicy, GetBucketPolicyStatus, GetBucketVersioning
References #
GetBucketTagging
#Description
Retrieves the tag set associated with a specified S3 bucket.
Example CloudTrail Event #
{
"eventVersion": "1.11",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE"
},
"eventTime": "2026-07-28T20:59:30Z",
"eventSource": "s3.amazonaws.com",
"eventName": "GetBucketTagging",
"awsRegion": "us-west-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "[aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#s3api.get-bucket-tagging]",
"requestParameters": {
"tagging": "",
"bucketName": "dw-harn-s3-eb786637",
"Host": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
},
"responseElements": null,
"additionalEventData": {
"SignatureVersion": "SigV4",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"bytesTransferredIn": 0,
"AuthenticationMethod": "AuthHeader",
"x-amz-id-2": "furHhP/N0aS78cZ1mzEGNyn7oF8eCfdX7Q/Oo0Mp6FQVrKeQNzhK+Q6AKPlWOBPIPpGhKO8597o=",
"bytesTransferredOut": 181
},
"requestID": "08G14C4WBM93E9FG",
"eventID": "0b479541-f1f3-422d-a90f-feff14ed1fdc",
"readOnly": true,
"resources": [
{
"accountId": "123456789012",
"type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::dw-harn-s3-eb786637"
}
],
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
}
}
GetBucketVersioning
#Description
Returns the versioning state of an S3 bucket.
Example CloudTrail Event #
{
"eventVersion": "1.11",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE"
},
"eventTime": "2026-07-28T20:59:33Z",
"eventSource": "s3.amazonaws.com",
"eventName": "GetBucketVersioning",
"awsRegion": "us-west-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "[aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#s3api.get-bucket-versioning]",
"requestParameters": {
"bucketName": "dw-harn-s3-eb786637",
"Host": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com",
"versioning": ""
},
"responseElements": null,
"additionalEventData": {
"SignatureVersion": "SigV4",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"bytesTransferredIn": 0,
"AuthenticationMethod": "AuthHeader",
"x-amz-id-2": "N5rUdQvFFRmgPL2uGlRwVbug5ETcPRAfNRBPJbtaE33DHdPl8nI1SQjy/1oSbMozMXsGUtKtBJYMtG8/IeUHGM2Wh482UaG8",
"bytesTransferredOut": 162
},
"requestID": "Q1V7FCJ1Q2GYKVS3",
"eventID": "b0784fa3-900a-4d4b-b3ec-9b5f1409ca57",
"readOnly": true,
"resources": [
{
"accountId": "123456789012",
"type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::dw-harn-s3-eb786637"
}
],
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aws::sessionCredentialFromConsole (elastic rule field) | is_null | | 1 rule | elastic |
aws::userIdentity.type (elastic rule field) | ne | awsservice | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1526, T1530, T1580, T1619↳ also matches GetBucketAcl, GetBucketPolicy, GetBucketPolicyStatus, GetBucketPublicAccessBlock
GetObject
#Description
Retrieves an object from a specified S3 bucket.
CloudTrail data event: not logged by a standard management-events trail. Requires explicit data-event configuration (an advanced event selector) on the trail or CloudTrail Lake; absence of this event does not prove the action did not occur. S3 data event. NOT logged by a standard management-events trail: you must enable S3 data-event logging (an advanced event selector on AWS::S3::Object) on the trail or CloudTrail Lake. Absence of GetObject events does NOT mean no object was read, only that data-event logging was not configured. High volume in active buckets. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 1056,
"x-amz-id-2": "fMMbTGYfQkr9O2R7On0/sZu0Qyz98L+f8VIkEW4VUma85VwniXUkng/yorbrfhF8a7pr5aDlwJA="
},
"awsRegion": "us-west-2",
"eventCategory": "Data",
"eventID": "806e0fbd-756b-412a-933b-01839be21e95",
"eventName": "GetObject",
"eventSource": "s3.amazonaws.com",
"eventTime": "2023-04-11T01:18:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": false,
"readOnly": true,
"recipientAccountId": "111111111111",
"requestID": "GVS0GF82MTWWV0GM",
"requestParameters": {
"Host": "security-content.s3.us-west-2.amazonaws.com",
"bucketName": "security-content",
"key": "stories/use_of_cleartext_protocols.yml",
"x-amz-request-payer": "requester"
},
"resources": [
{
"ARN": "arn:aws:s3:::security-content/stories/use_of_cleartext_protocols.yml",
"type": "AWS::S3::Object"
},
{
"ARN": "arn:aws:s3:::security-content",
"accountId": "111111111111",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "12.26.0.38",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "security-content.s3.us-west-2.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "[aws-cli/2.11.2 Python/3.11.2 Darwin/22.3.0 exe/x86_64 prompt/off command/s3.cp]",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLF5EAXXXX",
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:user/console",
"principalId": "AIDAYTOGP2RLCNEAQXWZV",
"type": "IAMUser",
"userName": "console"
}
}
Common Indicators #
Field Kind Value Rules Vendors aws::errorCode (kusto rule field)is_not_null 1 rule kusto aws::errorCodeis_null 3 rules kusto, panther aws::errorMessage (kusto rule field)is_not_null 1 rule kusto aws::errorMessage (kusto rule field)is_null 2 rules kusto aws::sourceIPAddress (panther rule field)is_not_null 1 rule panther Detection Rules #
Elastic #
T1530, T1552, T1552.001T1485, T1530, T1565, T1565.001, T1619↳ also matches DeleteObject, ListBucket, ListObjects, PutObject Splunk #
anomalydetection command to detect unusual patterns in the…T1119Kusto #
T1110T1530T1486↳ also matches PutObject Panther #
T1537References #
ListBucket
#Description
Lists the objects in a specified S3 bucket.
CloudTrail data event: not logged by a standard management-events trail. Requires explicit data-event configuration (an advanced event selector) on the trail or CloudTrail Lake; absence of this event does not prove the action did not occur. ListBucket never appears as a CloudTrail eventName: it is the IAM permission name (s3:ListBucket) that governs object listing, and no S3 API operation carries that name. CloudTrail records bucket-object listing as the ListObjects data event. Detection rules that match eventName = ListBucket never fire; query ListObjects instead. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Elastic #
T1485, T1530, T1565, T1565.001, T1619↳ also matches DeleteObject, GetObject, ListObjects, PutObject
ListBuckets
#Description
Lists all S3 buckets owned by the authenticated requester.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"eventVersion": "1.11",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE"
},
"eventTime": "2026-07-28T20:59:34Z",
"eventSource": "s3.amazonaws.com",
"eventName": "ListBuckets",
"awsRegion": "us-west-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "[aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/n,Z,E,C,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#s3api.list-buckets]",
"requestParameters": {
"Host": "s3.us-west-1.amazonaws.com"
},
"responseElements": null,
"additionalEventData": {
"SignatureVersion": "SigV4",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"bytesTransferredIn": 0,
"AuthenticationMethod": "AuthHeader",
"x-amz-id-2": "NHQnVgVsQ01jR9WIB+5lsrLHd3cjCT2vR7YkwfRHNG5v9QeW2thlsxvpWslvdPKKqnrLtmrCtknbCELtiCHkpetfa1GNOdAs",
"bytesTransferredOut": 619
},
"requestID": "300976TX1HKG5JCA",
"eventID": "0b21e0da-b8ed-4104-89f8-3827bc34482d",
"readOnly": true,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "s3.us-west-1.amazonaws.com"
}
}
Detection Rules #
Sigma #
T1580, T1619Elastic #
List*/Describe* patterns are intentionally omitted to reduce noise. Hosting ASNs are heavily dual-use; validate source.as.number in your data and extend event.action only when your baseline allows it.T1526, T1580
ListObjects
#Description
Lists some or all objects in a specified S3 bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0.0,
"bytesTransferredOut": 1350.0,
"x-amz-id-2": "CDF4o3iABidxM7tObbdzljr2WXXJg4/T0D7FHMypp0GRb9/FGbpmEC0dT3/VSk/bJVzL2+8d2yc="
},
"awsRegion": "us-west-2",
"eventCategory": "Data",
"eventID": "0eb2f60e-de2a-4226-a209-7019880b96b4",
"eventName": "ListObjects",
"eventSource": "s3.amazonaws.com",
"eventTime": "2021-04-13T17:15:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": false,
"readOnly": true,
"recipientAccountId": "760111141337",
"requestID": "V2Q7GX963V7X07W8",
"requestParameters": {
"Host": "s3.us-west-2.amazonaws.com",
"bucketName": "blackcert-results",
"encoding-type": "url",
"prefix": ""
},
"resources": [
{
"ARNPrefix": "arn:aws:s3:::blackcert-results/",
"type": "AWS::S3::Object"
},
{
"ARN": "arn:aws:s3:::blackcert-results",
"accountId": "760111141337",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "167.172.217.29",
"userAgent": "[aws-cli/1.14.44 Python/3.6.9 Linux/4.15.0-101-generic botocore/1.8.48]",
"userIdentity": {
"accessKeyId": "AKIAJ4HBMCEJQUGRUSWQ",
"accountId": "760111141337",
"arn": "arn:aws:iam::760111141337:user/jose_cli",
"principalId": "AIDAJ6Q5I24S6JKLAVZDS",
"type": "IAMUser",
"userName": "jose_cli"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1485, T1530, T1565, T1565.001, T1619↳ also matches DeleteObject, GetObject, ListBucket, PutObject
References #
PutAccountPublicAccessBlock
#Description
Creates or modifies the public access block configuration for an AWS account.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1562↳ also matches DeleteAccountPublicAccessBlock, DeleteBucketPublicAccessBlock, PutBucketPublicAccessBlock
PutBucketAcl
#Description
Sets the permissions on an existing S3 bucket using access control lists (ACLs).
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 640,
"bytesTransferredOut": 0,
"x-amz-id-2": "S8PMIlhbmqkangd8wjarKQ9cYX3NQPHTsIWtaBOmx6fY4x67RKIPZtcMDmM6Ft+LAcDBzUVnPTg="
},
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "041673a9-6c38-4b94-859c-006cf6848cb7",
"eventName": "PutBucketAcl",
"eventSource": "s3.amazonaws.com",
"eventTime": "2021-07-07T17:58:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "797507667711",
"requestID": "CFZ8WDJ15W52Q77E",
"requestParameters": {
"AccessControlPolicy": {
"AccessControlList": {
"Grant": [
{
"Grantee": {
"ID": "a6b38300126c5508f0638332394b6c926b20a00ff7165e645f4e9dc6accfceee",
"xmlns:xsi": "http://www.w3.org/2001/XMLSchema-instance",
"xsi:type": "CanonicalUser"
},
"Permission": "FULL_CONTROL"
},
{
"Grantee": {
"URI": "http://acs.amazonaws.com/groups/s3/LogDelivery",
"xmlns:xsi": "http://www.w3.org/2001/XMLSchema-instance",
"xsi:type": "Group"
},
"Permission": "FULL_CONTROL"
}
]
},
"Owner": {
"ID": "a6b38300126c5508f0638332394b6c926b20a00ff7165e645f4e9dc6accfceee"
},
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"Host": "s3.us-east-2.amazonaws.com",
"acl": "",
"bucketName": "cado-response-cados3bucketalt-1v7p4ao8z6xku"
},
"resources": [
{
"ARN": "arn:aws:s3:::cado-response-cados3bucketalt-1v7p4ao8z6xku",
"accountId": "797507667711",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "213.205.197.162",
"userAgent": "[S3Console/0.4, aws-internal/3 aws-sdk-java/1.11.1002 Linux/5.4.122-66.218.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.282-b08 java/1.8.0_282 vendor/Oracle_Corporation cfg/retry-mode/legacy]",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI37VSLCHQMS",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
},
"vpcEndpointId": "vpce-eca44785"
}
Detection Rules #
Elastic #
T1530Splunk #
PutBucketAcl actions where the access control list (ACL) grants permissions to all users or…T1530T1530Kusto #
T1537YARA-L #
T1562Panther #
T1567↳ also matches DeleteBucketCors, DeleteBucketLifecycle, DeleteBucketPolicy, DeleteBucketReplication, PutBucketLifecycle, PutBucketPolicy, PutBucketReplication, PutBucketCors References #
PutBucketLifecycle
#Description
Creates or replaces the lifecycle configuration on an S3 bucket (can be abused to expire/delete objects).
CloudTrail management event, logged by default. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 249,
"bytesTransferredOut": 0,
"x-amz-id-2": "WLiCIIDMGhCCUp11YIClXMXz0UgUy/yxG2IjL8hJBz1omJBNImuBTSA6VSh6R7ygeDM0zBAH1b4="
},
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "7823c70d-f7f9-4a04-b4c0-baa8fbe09ea3",
"eventName": "PutBucketLifecycle",
"eventSource": "s3.amazonaws.com",
"eventTime": "2023-07-10T12:00:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "3WDNJTQG33KXSTM8",
"requestParameters": {
"Host": "stratus-red-team-ctlr-bucket-zqfsvooxqj.s3.us-east-1.amazonaws.com",
"LifecycleConfiguration": {
"Rule": {
"Expiration": {
"Days": 1
},
"Filter": {
"Prefix": "*"
},
"ID": "nuke-cloudtrail-logs-after-1-day",
"Status": "Enabled"
},
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"bucketName": "stratus-red-team-ctlr-bucket-zqfsvooxqj",
"lifecycle": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::stratus-red-team-ctlr-bucket-zqfsvooxqj",
"accountId": "123837392027",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "stratus-red-team-ctlr-bucket-zqfsvooxqj.s3.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "[stratus-red-team_4990da05-9399-449e-b49f-82996a764ec9]",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Common Indicators #
Field Kind Value Rules Vendors user_type (splunk rule field)eq iamuser1 rule splunk Detection Rules #
Elastic #
T1070, T1485, T1485.001, T1562, T1562.008Splunk #
PutBucketLifecycle events in AWS CloudTrail logs where a user sets a lifecycle rule for an S3 bucket with an expiration period of fewer than three days. This detection leverages CloudTrail logs to identify…T1485, T1485.001, T1685, T1685.002PutBucketLifecycle events in AWS CloudTrail logs where a user sets a lifecycle rule for an S3 bucket with an expiration period of fewer than three days. This detection leverages CloudTrail logs to identify…T1485, T1485.001, T1685, T1685.002Panther #
T1562.008T1567↳ also matches DeleteBucketCors, DeleteBucketLifecycle, DeleteBucketPolicy, DeleteBucketReplication, PutBucketAcl, PutBucketPolicy, PutBucketReplication, PutBucketCors References #
PutBucketLogging
#Description
Sets the logging parameters for a specified S3 bucket.
CloudTrail management event, logged by default. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "abc64d9c-f357-4f4b-966b-5bc6e2271ca3",
"eventName": "PutBucketLogging",
"eventSource": "s3.amazonaws.com",
"eventTime": "2017-02-18T19:40:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "D9A3F030361A70B23",
"requestParameters": {
"BucketLoggingStatus": {
"LoggingEnabled": {
"TargetBucket": "flaws-logs",
"TargetPrefix": "logs/flaws.cloud"
},
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"bucketName": "flaws.cloud",
"logging": [
""
]
},
"responseElements": null,
"sourceIPAddress": "255.253.125.115",
"userAgent": "[S3Console/0.4]",
"userIdentity": {
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:root",
"principalId": "811596193553",
"sessionContext": {
"attributes": {
"creationDate": "2017-02-18T19:20:48Z",
"mfaAuthenticated": "true"
}
},
"type": "Root"
}
}
Common Indicators #
Field Kind Value Rules Vendors requestParameters.VersioningConfiguration.MfaDelete (panther rule field)eq Disabled1 rule panther requestParameters.VersioningConfiguration.Status (panther rule field)in Disabled1 rule panther requestParameters.VersioningConfiguration.Status (panther rule field)in Suspended1 rule panther Detection Rules #
Sigma #
T1537↳ also matches PutBucketWebsite, PutEncryptionConfiguration, PutLifecycleConfiguration, PutReplicationConfiguration, ReplicateObject, RestoreObject Elastic #
T1562, T1562.008Panther #
T1485, T1562T1485, T1562↳ also matches PutBucketVersioning References #
PutBucketPolicy
#Description
Applies a resource-based bucket policy to an S3 bucket.
CloudTrail management event, logged by default. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 494,
"bytesTransferredOut": 0,
"x-amz-id-2": "nYXxFQV/wJW6Q8m2FyK2HAI8cus359tlU7z9JFVzEsUpAMXvR6IOm2o/ukKHTitxkHKEsN4U/qU="
},
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "988f1043-3e3d-4d84-803b-1b4d00e0df90",
"eventName": "PutBucketPolicy",
"eventSource": "s3.amazonaws.com",
"eventTime": "2023-07-10T11:59:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "F0XQX2G7KS8GYAD2",
"requestParameters": {
"Host": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
"bucketName": "stratus-red-team-ctes-bucket-qyxyekjbtk",
"bucketPolicy": {
"Statement": [
{
"Action": "s3:GetBucketAcl",
"Effect": "Allow",
"Principal": {
"Service": "cloudtrail.amazonaws.com"
},
"Resource": "arn:aws:s3:::stratus-red-team-ctes-bucket-qyxyekjbtk",
"Sid": "AWSCloudTrailAclCheck"
},
{
"Action": "s3:PutObject",
"Condition": {
"StringEquals": {
"s3:x-amz-acl": "bucket-owner-full-control"
}
},
"Effect": "Allow",
"Principal": {
"Service": "cloudtrail.amazonaws.com"
},
"Resource": "arn:aws:s3:::stratus-red-team-ctes-bucket-qyxyekjbtk/*",
"Sid": "AWSCloudTrailWrite"
}
],
"Version": "2012-10-17"
},
"policy": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::stratus-red-team-ctes-bucket-qyxyekjbtk",
"accountId": "123837392027",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "[APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_1d949e3e-4092-4c96-a6ef-96a967510a46 HashiCorp-terraform-exec/0.17.3]",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Common Indicators #
Field Kind Value Rules Vendors aws::requestParameters (elastic rule field)contains effect=allow2 rules elastic aws::requestParameters (elastic rule field)contains principal=\*1 rule elastic Condition (kusto rule field)is_null 1 rule kusto Principal (kusto rule field)eq *1 rule kusto Principal_aws (kusto rule field)eq *1 rule kusto Detection Rules #
Elastic #
T1098, T1530, T1537T1530, T1537Kusto #
T1537Panther #
T1567↳ also matches DeleteBucketCors, DeleteBucketLifecycle, DeleteBucketPolicy, DeleteBucketReplication, PutBucketAcl, PutBucketLifecycle, PutBucketReplication, PutBucketCors References #
PutBucketPublicAccessBlock
#Description
Creates or modifies the public access block configuration for an S3 bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 287,
"bytesTransferredOut": 0,
"x-amz-id-2": "FS8vDS7cjbByC0qmeR9OhqvhI0VU3UY///1pQvbNLPisX3wi5txQrmQYtecmgG6rid1JADKeJKA="
},
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "a657aa02-d6ec-4b19-a028-7ed4738d494f",
"eventName": "PutBucketPublicAccessBlock",
"eventSource": "s3.amazonaws.com",
"eventTime": "2021-07-07T18:17:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "797507667711",
"requestID": "QAYF9XQRFR1XG4V6",
"requestParameters": {
"Host": "s3logssans.s3.us-east-2.amazonaws.com",
"PublicAccessBlockConfiguration": {
"BlockPublicAcls": true,
"BlockPublicPolicy": true,
"IgnorePublicAcls": true,
"RestrictPublicBuckets": true,
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"bucketName": "s3logssans",
"publicAccessBlock": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::s3logssans",
"accountId": "797507667711",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "213.205.197.211",
"userAgent": "[S3Console/0.4, aws-internal/3 aws-sdk-java/1.11.1002 Linux/5.4.122-66.218.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.282-b08 java/1.8.0_282 vendor/Oracle_Corporation cfg/retry-mode/legacy]",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI373B6VIGVS",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →YARA-L #
T1562↳ also matches DeleteAccountPublicAccessBlock, DeleteBucketPublicAccessBlock, PutAccountPublicAccessBlock
References #
PutBucketReplication
#Description
Creates or replaces the replication configuration for an S3 bucket; CloudTrail eventName for the PutReplicationConfiguration API.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 416,
"bytesTransferredOut": 0,
"x-amz-id-2": "8UoliFe/sG2/v8qB2g763/g0Fy+kfaUqtKrzLHEILnHUisC3rL1dQfJ3NSIYcA/kzpIHQ955pGo="
},
"awsRegion": "us-west-2",
"eventCategory": "Management",
"eventID": "fbe079d1-bc6b-4ee0-8893-d2b412c5550f",
"eventName": "PutBucketReplication",
"eventSource": "s3.amazonaws.com",
"eventTime": "2023-04-24T23:49:33Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "111111111111",
"requestID": "14SAVMJNEJMTZN91",
"requestParameters": {
"Host": "s3.us-west-2.amazonaws.com",
"ReplicationConfiguration": {
"Role": "arn:aws:iam::111111111111:role/attack_range_bpatel",
"Rule": {
"DeleteMarkerReplication": {
"Status": "Disabled"
},
"Destination": {
"Bucket": "arn:aws:s3:::badpublicbuckettest"
},
"Filter": "",
"ID": "replication_x_test",
"Priority": 0,
"Status": "Enabled"
},
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"bucketName": "git-wild-hunt-results",
"replication": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::git-wild-hunt-results",
"accountId": "111111111111",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "23.93.193.6",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "s3.us-west-2.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "[S3Console/0.4, aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.238-155.347.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.362-b10 java/1.8.0_362 vendor/Oracle_Corporation cfg/retry-mode/standard]",
"userIdentity": {
"accessKeyId": "ASIAYTOGP2RLJOVYQHW2",
"accountId": "111111111111",
"arn": "arn:aws:sts::111111111111:assumed-role/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f/bpatel@splunk.com",
"principalId": "AROAYTOGP2RLDF6WP4H11:bpatel@splunk.com",
"sessionContext": {
"attributes": {
"creationDate": "2023-04-24T23:45:42Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:role/aws-reserved/sso.amazonaws.com/us-west-2/AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f",
"principalId": "AROAYTOGP2RLDF6WP4H11",
"type": "Role",
"userName": "AWSReservedSSO_SPLKAdministratorAccess_d9ce1347d0a6dd3f"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
},
"vpcEndpointId": "vpce-a0d039c9"
}
Detection Rules #
Elastic #
T1537, T1567, T1567.002Splunk #
PutBucketReplication events, focusing on fields like bucketName,…T1537Panther #
T1567↳ also matches DeleteBucketCors, DeleteBucketLifecycle, DeleteBucketPolicy, DeleteBucketReplication, PutBucketAcl, PutBucketLifecycle, PutBucketPolicy, PutBucketCors References #
PutBucketVersioning
#Description
Sets the versioning state for a specified S3 bucket.
CloudTrail management event, logged by default. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"eventVersion": "1.11",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE"
},
"eventTime": "2026-07-28T20:59:31Z",
"eventSource": "s3.amazonaws.com",
"eventName": "PutBucketVersioning",
"awsRegion": "us-west-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "[aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/n,W,Z,E,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#s3api.put-bucket-versioning]",
"requestParameters": {
"bucketName": "dw-harn-s3-eb786637",
"Host": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com",
"versioning": "",
"VersioningConfiguration": {
"Status": "Enabled",
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
}
},
"responseElements": null,
"additionalEventData": {
"SignatureVersion": "SigV4",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"bytesTransferredIn": 123,
"AuthenticationMethod": "AuthHeader",
"x-amz-id-2": "gEG86qFly9JkUkrhMZUfGCciyRv82OHgdEuSwCCBz4WC9cITSFxr8O0eD43/ZAvA03zzw82OLZQ=",
"bytesTransferredOut": 0
},
"requestID": "XK540GW32E7DK3GD",
"eventID": "f29d4719-3236-4572-9fc5-191402d20bc3",
"readOnly": false,
"resources": [
{
"accountId": "123456789012",
"type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::dw-harn-s3-eb786637"
}
],
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
}
}
Common Indicators #
Field Kind Value Rules Vendors requestParameters.VersioningConfiguration.MfaDelete (panther rule field)eq Disabled2 rules panther requestParameters.VersioningConfiguration.Status (panther rule field)in Disabled2 rules panther requestParameters.VersioningConfiguration.Status (panther rule field)in Suspended2 rules panther Detection Rules #
Sigma #
T1490Elastic #
T1490Splunk #
PutBucketVersioning events with the VersioningConfiguration.Status set to Suspended. This activity is…T1490PutBucketVersioning events with the VersioningConfiguration.Status set to Suspended. This activity is…T1490Panther #
T1485, T1562T1485, T1562T1485, T1562↳ also matches PutBucketLogging
PutBucketWebsite
#Description
Sets the configuration of the website for a specified S3 bucket.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "43f300874-24b8-4780-9e2b-97667ba6aa2a",
"eventName": "PutBucketWebsite",
"eventSource": "s3.amazonaws.com",
"eventTime": "2017-02-12T20:38:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "5DC5980F7FF809774",
"requestParameters": {
"WebsiteConfiguration": {
"IndexDocument": {
"Suffix": "index.html"
},
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"bucketName": "level3-b5677c799b465420d8e7b0a6689a0bb0c4afbc9e.flaws.cloud",
"website": [
""
]
},
"responseElements": null,
"sourceIPAddress": "255.253.125.115",
"userAgent": "[S3Console/0.4]",
"userIdentity": {
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:root",
"principalId": "811596193553",
"sessionContext": {
"attributes": {
"creationDate": "2017-02-12T19:57:05Z",
"mfaAuthenticated": "false"
}
},
"type": "Root"
}
}
Detection Rules #
Sigma #
T1537↳ also matches PutBucketLogging, PutEncryptionConfiguration, PutLifecycleConfiguration, PutReplicationConfiguration, ReplicateObject, RestoreObject References #
PutEncryptionConfiguration
#Description
Sets the default server-side encryption configuration for a specified S3 bucket.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1537↳ also matches PutBucketLogging, PutBucketWebsite, PutLifecycleConfiguration, PutReplicationConfiguration, ReplicateObject, RestoreObject
PutLifecycleConfiguration
#Description
Creates or replaces the lifecycle configuration for a specified S3 bucket.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1537↳ also matches PutBucketLogging, PutBucketWebsite, PutEncryptionConfiguration, PutReplicationConfiguration, ReplicateObject, RestoreObject
PutObject
#Description
Adds an object to a specified S3 bucket.
CloudTrail data event: not logged by a standard management-events trail. Requires explicit data-event configuration (an advanced event selector) on the trail or CloudTrail Lake; absence of this event does not prove the action did not occur. S3 data event. Requires S3 data-event logging on the trail (advanced event selector on AWS::S3::Object). High volume in active buckets. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SSEApplied": "Default_SSE_S3",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 43,
"bytesTransferredOut": 0,
"x-amz-id-2": "15HDa9GEVKlgDYna3aD/2L11PmcDEVbA7W2EXaqkjeLSWIK49Dk++hGzFOkAPn+BFc8v86Qut8mBG1BnCl9RnzsJZVzf/CCW"
},
"awsRegion": "us-west-1",
"eventCategory": "Data",
"eventID": "684812d8-9430-4388-b6f9-54bd3dc6dab9",
"eventName": "PutObject",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:07:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": false,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7Y2Q3EQ0WGPPKXG9",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"bucketName": "dwfix-s3-123456789012-uw1",
"key": "dw.txt"
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
},
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1/dw.txt",
"type": "AWS::S3::Object"
}
],
"responseElements": {
"x-amz-expiration": "expiry-date=\"Thu, 30 Jul 2026 00:00:00 GMT\", rule-id=\"dw\"",
"x-amz-server-side-encryption": "AES256",
"x-amz-version-id": "XqF3Ks1g6Dl23X61f0Jx4ONJSggFg4Gm"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/U,Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Common Indicators #
Field Kind Value Rules Vendors event.outcome (elastic rule field)eq success5 rules elastic aws.cloudtrail.flattened.request_parameters.x-amz-server-side-encryption-customer-algorithm (elastic rule field)eq aes2562 rules elastic aws::sourceIPAddress (panther rule field)is_not_null 1 rule panther aws::userIdentity.type (elastic rule field)in iamuser1 rule elastic Detection Rules #
Elastic #
T1485, T1486, T1565, T1565.001static/js/) by an IAM user or assumed role. This can indicate suspicious modification of web content hosted on S3, such as injecting malicious scripts into a static website frontend.T1491, T1491.002, T1565, T1565.001T1485, T1530, T1565, T1565.001, T1619↳ also matches DeleteObject, GetObject, ListBucket, ListObjects Kusto #
T1651T1486↳ also matches GetObject Panther #
PutReplicationConfiguration
#Description
Creates or replaces the replication configuration for a specified S3 bucket.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1537↳ also matches PutBucketLogging, PutBucketWebsite, PutEncryptionConfiguration, PutLifecycleConfiguration, ReplicateObject, RestoreObject
ReplicateObject
#Description
Replicates an object to a destination bucket as part of a replication configuration.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1537↳ also matches PutBucketLogging, PutBucketWebsite, PutEncryptionConfiguration, PutLifecycleConfiguration, PutReplicationConfiguration, RestoreObject
RestoreObject
#Description
Restores a temporarily deleted or archived object in a specified S3 bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 161,
"bytesTransferredOut": 0,
"x-amz-id-2": "8/tY+7hf58o12doq2mROm+tiSzGbN0PG10qTDaF4fm63uvJRjVuourkwC16GsalDIlQqpMobA68="
},
"awsRegion": "us-west-1",
"eventCategory": "Data",
"eventID": "39fc7155-eb18-4383-9c50-8d151c9ab4fb",
"eventName": "RestoreObject",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T20:58:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": false,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9B51PNZWBFH74MS3",
"requestParameters": {
"Host": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
"RestoreRequest": {
"Days": 1,
"GlacierJobParameters": {
"Tier": "Standard"
},
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"bucketName": "dwfix-main-921c7279",
"key": "glacier-object.txt",
"restore": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-main-921c7279",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
},
{
"ARN": "arn:aws:s3:::dwfix-main-921c7279/glacier-object.txt",
"type": "AWS::S3::Object"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,Z,U,D cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1537↳ also matches PutBucketLogging, PutBucketWebsite, PutEncryptionConfiguration, PutLifecycleConfiguration, PutReplicationConfiguration, ReplicateObject
AbortMultipartUpload
#Description
This operation aborts a multipart upload.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 0,
"x-amz-id-2": "bqf6uKPy6MUpT45ui/nUSpvo9CIGNZGntcn0RZJ5C6+QV4ae5m1prvLoBnLFgsEvjAn1bzHn/DMDwJSPjk0lVh343lJ62MI1"
},
"awsRegion": "us-west-1",
"eventCategory": "Data",
"eventID": "cf76a5a6-7ee8-431d-80cb-f3f7156ac6c8",
"eventName": "AbortMultipartUpload",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:07:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": false,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7Y2TWFYB1RN8E448",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"bucketName": "dwfix-s3-123456789012-uw1",
"key": "mp.txt",
"uploadId": "vjrRU8b9IkTn.BdpAS76xpfkVVBa0mQqYz8sgwPnWhMa2DzTN3jWbTfqfJuTPBj2GanWuDpdI9CGRS9KGhHPMD17mhoeHmAffPo6EHWGnznmWp7y0zNt9x4Ja1HMh6Y5"
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
},
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1/mp.txt",
"type": "AWS::S3::Object"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CompleteMultipartUpload
#Description
Completes a multipart upload by assembling previously uploaded parts.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 271,
"bytesTransferredOut": 442,
"x-amz-id-2": "yCnpCd+16KzCfNSBD8uE2Non0GMOm/0oBBQkAnUL5NI3Ik0CesRRxEuWcwxUvtJz2beydLTB0vE="
},
"awsRegion": "us-west-1",
"eventCategory": "Data",
"eventID": "8dd6386d-48cc-41c3-ad8e-3e2c1fe0499c",
"eventName": "CompleteMultipartUpload",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T20:58:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": false,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "794PXSXQNVC8VYPB",
"requestParameters": {
"CompleteMultipartUpload": {
"Part": [
{
"ETag": "\"4f08eef4096726bff1125e1b1b734644\"",
"PartNumber": 1
},
{
"ETag": "\"5eb63bbbe01eeed093cb22bb8f5acdc3\"",
"PartNumber": 2
}
],
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"Host": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
"bucketName": "dwfix-main-921c7279",
"key": "mpu-object.txt",
"uploadId": "adI6a0ON5uIMbksUQjUaQDIyquNC_OPDf7eor8NZkSLr0WAKY.L8Blodil..WUaqF3ZciTtepqPeWerPn1q1CC5YZlnZExQeW.JfIRqg2yd9lO07ZmIU.f0TfMFZh3.F"
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-main-921c7279",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
},
{
"ARN": "arn:aws:s3:::dwfix-main-921c7279/mpu-object.txt",
"type": "AWS::S3::Object"
}
],
"responseElements": {
"x-amz-expiration": "expiry-date=\"Wed, 01 Jul 2026 00:00:00 GMT\", rule-id=\"dwfix-expire\"",
"x-amz-server-side-encryption": "AES256"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateBucket
#Description
This action creates an Amazon S3 bucket.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"eventVersion": "1.11",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE"
},
"eventTime": "2026-07-28T20:59:24Z",
"eventSource": "s3.amazonaws.com",
"eventName": "CreateBucket",
"awsRegion": "us-west-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "[aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#s3api.create-bucket]",
"requestParameters": {
"CreateBucketConfiguration": {
"LocationConstraint": "us-west-1",
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"bucketName": "dw-harn-s3-eb786637",
"Host": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
},
"responseElements": null,
"additionalEventData": {
"SignatureVersion": "SigV4",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"bytesTransferredIn": 153,
"AuthenticationMethod": "AuthHeader",
"x-amz-id-2": "OUmTxv7dGAXNvcHPAfgAqqxqrMbrr55zjZlQAp2Ja6+X/73Y6xFgv8DBlKZodqgKax7VaDf6/2DIAiimCS3M5aGb8eYm3zU+",
"bytesTransferredOut": 0
},
"requestID": "P3TPCVWXT4CM673R",
"eventID": "6449085a-0a89-41cd-9102-8981d350de44",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
}
}
CreateBucketMetadataConfiguration
#Description
Creates an S3 Metadata V2 metadata configuration for a general purpose bucket.
CreateBucketMetadataTableConfiguration
#Description
We recommend that you create your S3 Metadata configurations by using the V2 CreateBucketMetadataConfiguration API operation.
CreateMultipartUpload
#Description
End of support notice: As of October 1, 2025, Amazon S3 has discontinued support for Email Grantee Access Control Lists (ACLs).
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SSEApplied": "Default_SSE_S3",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 358,
"x-amz-id-2": "yhDDl31+cAMDRVhh5UKqrv3/tQDsDmYXYMvKWP6UAl8Amur9AXiChW9rjNv60k5Ef3yQCt+V8/vVIOdk7gCFKJEqZiNhoq6q"
},
"awsRegion": "us-west-1",
"eventCategory": "Data",
"eventID": "8afbdeaa-8adb-489c-aef9-9acda10c6a59",
"eventName": "CreateMultipartUpload",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:07:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": false,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7Y2NZSCVBM6AY99A",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"bucketName": "dwfix-s3-123456789012-uw1",
"key": "mp.txt",
"uploads": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
},
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1/mp.txt",
"type": "AWS::S3::Object"
}
],
"responseElements": {
"x-amz-server-side-encryption": "AES256"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateSession
#Description
Creates a session that establishes temporary security credentials to support fast authentication and authorization for the Zonal endpoint API operations on directory buckets.
DeleteBucketAnalyticsConfiguration
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 0,
"x-amz-id-2": "M+Xb8JVl4T2/TACp1wrJrtWXScelhegFp74Yd0K73j03RqtRUnZtYyge9T/tmXyzwmlazGBrTb8="
},
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "a6b20e8b-0f12-4080-a924-ef4abb34c33a",
"eventName": "DeleteBucketAnalyticsConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:08:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "CPH5GH9B5C74S5GV",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"analytics": "",
"bucketName": "dwfix-s3-123456789012-uw1",
"id": "dw"
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteBucketIntelligentTieringConfiguration
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 0,
"x-amz-id-2": "PMD0B72+Ka69VbrfgNJRo2VpzwSOQVAamS2eGq+9QcxWVHuLOUwmK5qQ25VO3q4QunvvhmQ+7+g="
},
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "47074cc9-7b90-47e9-a01f-106b9a652e85",
"eventName": "DeleteBucketIntelligentTieringConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:08:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "MDB1N7DS3WTQ7FFH",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"bucketName": "dwfix-s3-123456789012-uw1",
"id": "dw",
"intelligent-tiering": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteBucketInventoryConfiguration
#Description
Deletes an S3 Inventory configuration (identified by the inventory ID) from the bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 298,
"x-amz-id-2": "HGRJEd1EGs7zw5luD+DE/2TdGZjGfVIwt3/RMS5rO578PuCaLYWlhq6xf+RoeB5r8lxb01pAZf0="
},
"awsRegion": "us-west-1",
"errorCode": "NoSuchBucket",
"errorMessage": "The specified bucket does not exist",
"eventCategory": "Management",
"eventID": "25d257d0-2358-4136-941d-517cf6a6ffe8",
"eventName": "DeleteBucketInventoryConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:26:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "S0YNPQ9MQPJVH3VS",
"requestParameters": {
"Host": "dw-probe.s3.us-west-1.amazonaws.com",
"bucketName": "dw-probe",
"id": "dw-probe",
"inventory": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteBucketMetadataConfiguration
#Description
Deletes an S3 Metadata configuration from a general purpose bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 298,
"x-amz-id-2": "JHldfB8XmOSozqAFVxvdSBncyr9F+k/yJCzco9O9RDCga9Y2K/GktqOWT2HJpCT3QWw2XNjnqWQ="
},
"awsRegion": "us-west-1",
"errorCode": "NoSuchBucket",
"errorMessage": "The specified bucket does not exist",
"eventCategory": "Management",
"eventID": "9d305051-e643-40fa-85fc-6289ae14a714",
"eventName": "DeleteBucketMetadataConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:26:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "S0YV22SS3MCSXP0Q",
"requestParameters": {
"Host": "dw-probe.s3.us-west-1.amazonaws.com",
"bucketName": "dw-probe",
"metadataConfiguration": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteBucketMetadataTableConfiguration
#Description
We recommend that you delete your S3 Metadata configurations by using the V2 DeleteBucketMetadataTableConfiguration API operation.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 298,
"x-amz-id-2": "qJy9oBzVo/zykg9kVcLsHrwXtqwCt4w9252NnGL0GSM3IXSTH2hpDwRLbzL9oWYfG51kJFnkEN8="
},
"awsRegion": "us-west-1",
"errorCode": "NoSuchBucket",
"errorMessage": "The specified bucket does not exist",
"eventCategory": "Management",
"eventID": "b85ba33f-154b-46de-a965-525bcee63832",
"eventName": "DeleteBucketMetadataTableConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:26:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "S0YRYYV1Z91NC7RK",
"requestParameters": {
"Host": "dw-probe.s3.us-west-1.amazonaws.com",
"bucketName": "dw-probe",
"metadataTable": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteBucketMetricsConfiguration
#Description
Deletes a metrics configuration for the Amazon CloudWatch request metrics (specified by the metrics configuration ID) from the bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 0,
"x-amz-id-2": "lnYZrJuF2jDXMFfVEmBe8jA1VcdT1IORhJe6i3zY5WMSFU6qUfU7qJ0sjB7A5S5fBEa/1ATqCxw="
},
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "0df08b06-9f9a-40ff-9a2d-5dc16c5c23a9",
"eventName": "DeleteBucketMetricsConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:08:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "CPH5B068694QAPG5",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"bucketName": "dwfix-s3-123456789012-uw1",
"id": "dw",
"metrics": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteBucketOwnershipControls
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 0,
"x-amz-id-2": "lSC4p0594sHAQ/bO11MPQaIKeKS/QFnCBuKRGW5JKUGCe9N1XpX1y83xh69e0FtUFFj7svmDK5I="
},
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "6a718578-6f1d-4d2d-be83-dd5b9b4b5d5f",
"eventName": "DeleteBucketOwnershipControls",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:08:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "MDB1ZT594Y4N1RCP",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"bucketName": "dwfix-s3-123456789012-uw1",
"ownershipControls": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteBucketTagging
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 0,
"x-amz-id-2": "5s6g1Q0J1bQubRPsrtvjNxYZ+URWG79YAyf0rm+NWJ+nqupHLlXUDaugKibX+wKHsoWtuHP+8JQ="
},
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "d72670e0-bf0c-4ea1-a0e3-1332ea3be48f",
"eventName": "DeleteBucketTagging",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:08:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "CPH0YJW255Y75RFD",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"bucketName": "dwfix-s3-123456789012-uw1",
"tagging": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteBucketWebsite
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 0,
"x-amz-id-2": "XboDA8Op8eKbwefkdBt7fQTBBDYX29kG/wyJHLe/Moe748VeBTCAxbYMky+ip7BJT2vjKIfzj4c="
},
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "b91dc754-5abe-4f80-9a9a-b21e9660847f",
"eventName": "DeleteBucketWebsite",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:08:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "CPHFETRPXBQTS36W",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"bucketName": "dwfix-s3-123456789012-uw1",
"website": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteObjectAnnotation
#Description
Deletes a specific annotation from an Amazon S3 object.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 0,
"x-amz-id-2": "PGI9xpCmBfllscU6eHev1WmEe7rHqxFRbkhHnpl7/vZXzt4vc/iSESqEeuYDR/jhvFZ8dT2aAEY="
},
"awsRegion": "us-west-1",
"eventCategory": "Data",
"eventID": "9432d252-fcad-43dc-b644-47ac12e144d0",
"eventName": "DeleteObjectAnnotation",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T20:58:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": false,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "794QWWDTKGRRCFWF",
"requestParameters": {
"Host": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
"annotation": "",
"annotationName": "dwfix-annotation",
"bucketName": "dwfix-main-921c7279",
"key": "test-object.txt"
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-main-921c7279",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
},
{
"ARN": "arn:aws:s3:::dwfix-main-921c7279/test-object.txt",
"type": "AWS::S3::Object"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteObjects
#Description
This operation enables you to delete multiple objects from a bucket using a single HTTP request.
CloudTrail data event: not logged by a standard management-events trail. Requires explicit data-event configuration (an advanced event selector) on the trail or CloudTrail Lake; absence of this event does not prove the action did not occur. S3 data event. Requires S3 data-event logging on the trail. A single DeleteObjects call can delete up to 1000 keys, so each event represents bulk destruction. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 0,
"x-amz-id-2": "ULC5G/XSktS5ug9eGxT8oYJs/tXQypLbfFH295M5U5bQfZzXdw1WKqBS11xKAYcr0c+jgcguuyA+DOMKKuOITsTyszihDS5o"
},
"awsRegion": "us-west-1",
"eventCategory": "Data",
"eventID": "d440c448-f01b-4e15-b31c-32d8e650dd47",
"eventName": "DeleteObjects",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:07:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": false,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7Y2WK0V00AHY1537",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"bucketName": "dwfix-s3-123456789012-uw1",
"delete": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
},
{
"ARNPrefix": "arn:aws:s3:::dwfix-s3-123456789012-uw1/",
"type": "AWS::S3::Object"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/U,Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Common Indicators #
Field Kind Value Rules Vendors aws::sourceIPAddress (panther rule field)is_not_null 1 rule panther Detection Rules #
Panther #
DeleteObjectTagging
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 0,
"x-amz-id-2": "U15qE7yLnF+QfrrsRJf3+JY1Tkqyeq5K7IqMUddofrxpL3ySH5UBo2oe3U42fr4UOCycDA2fdjR1OKS/YyedoTfO6duX3e+E"
},
"awsRegion": "us-west-1",
"eventCategory": "Data",
"eventID": "3e3649eb-dafe-483e-954e-383869f7b4ab",
"eventName": "DeleteObjectTagging",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:07:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": false,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7Y2W5G2WBVKDZXWS",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"bucketName": "dwfix-s3-123456789012-uw1",
"key": "dw.txt",
"tagging": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
},
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1/dw.txt",
"type": "AWS::S3::Object"
}
],
"responseElements": {
"x-amz-version-id": "XqF3Ks1g6Dl23X61f0Jx4ONJSggFg4Gm"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeletePublicAccessBlock
#Description
This operation is not supported for directory buckets.
GetBucketAbac
#Description
Returns the attribute-based access control (ABAC) property of the general purpose bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 298,
"x-amz-id-2": "0csWxa2uwb9T4l14iZPX3zPaQzokEy+t+rv0E3+mbMBlS9KcWA0TVps66A+xafSH8PAPTSxGz5Q="
},
"awsRegion": "us-west-1",
"errorCode": "NoSuchBucket",
"errorMessage": "The specified bucket does not exist",
"eventCategory": "Management",
"eventID": "d5bc2f5b-ebbd-48c0-ac47-acbde29a769f",
"eventName": "GetBucketAbac",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T18:46:07Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "03F9DAESV8T2ZQV9",
"requestParameters": {
"Host": "dw-probe.s3.us-west-1.amazonaws.com",
"abac": "",
"bucketName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetBucketAccelerateConfiguration
#Description
This operation is not supported for directory buckets.
CloudTrail logs this operation under the eventName GetAccelerateConfiguration; the catalog keys on the SDK operation name GetBucketAccelerateConfiguration. A detection rule may use either name.Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 298,
"x-amz-id-2": "4UM30snOSKvRkvVrzOgNTDmFjuCyZyNwXgVfE2O8P2ReyQRE7+TmaspeF9Gb8IZOaT0fIleW6yU="
},
"awsRegion": "us-west-1",
"errorCode": "NoSuchBucket",
"errorMessage": "The specified bucket does not exist",
"eventCategory": "Management",
"eventID": "340256ff-7a7f-4536-b7d7-9b65aed0a1c9",
"eventName": "GetAccelerateConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T18:46:07Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "03F10NZRJPYD8M3G",
"requestParameters": {
"Host": "dw-probe.s3.us-west-1.amazonaws.com",
"accelerate": "",
"bucketName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetBucketAnalyticsConfiguration
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"x-amz-id-2": "i09xXQ2MKcrLDhQzAfnGC/gLINoTjDo3Y3hG9TIUiAY7xRnJ6F5kileIlo3KWscZRstLfHChN5Q="
},
"awsRegion": "us-east-1",
"errorCode": "NoSuchBucket",
"errorMessage": "The specified bucket does not exist",
"eventID": "fee449117-f1bd-49c5-a24a-f9b36127b272",
"eventName": "GetBucketAnalyticsConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2020-09-21T04:28:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"readOnly": true,
"recipientAccountId": "811596193553",
"requestID": "0P5Z2XBQAWCN2PDP",
"requestParameters": {
"Host": "s3.amazonaws.com",
"analytics": "",
"bucketName": "dummy_data",
"id": "dummy_data"
},
"responseElements": null,
"sourceIPAddress": "9.240.250.1",
"userAgent": "[Boto3/1.14.51 Python/3.8.5 Linux/4.19.76-linuxkit Botocore/1.17.51]",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetBucketEncryption
#Description
Returns the default encryption configuration for an Amazon S3 bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 321,
"x-amz-id-2": "/KLysnkOpdyQBFMRu9dFVipzhAtT/tn6O5ytClX9jn/4wnOBtTTmBJ6bp4tn1iWai61r6P5l4Jk="
},
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "204a9beb-9b1c-4083-9279-51bd05eb94aa",
"eventName": "GetBucketEncryption",
"eventSource": "s3.amazonaws.com",
"eventTime": "2023-07-10T12:00:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "FAG1V07V67D44H44",
"requestParameters": {
"Host": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
"bucketName": "stratus-red-team-ctes-bucket-qyxyekjbtk",
"encryption": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::stratus-red-team-ctes-bucket-qyxyekjbtk",
"accountId": "123837392027",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "[APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_1d949e3e-4092-4c96-a6ef-96a967510a46 HashiCorp-terraform-exec/0.17.3]",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
GetBucketIntelligentTieringConfiguration
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 298,
"x-amz-id-2": "95aKcqYBtukGeWh289G48EQwszPvZHg7+IufMB3k7fzIByoaSzJN/XKjwz8cLkjI+OehS87TnV4="
},
"awsRegion": "us-west-1",
"errorCode": "NoSuchBucket",
"errorMessage": "The specified bucket does not exist",
"eventCategory": "Management",
"eventID": "3f9c2377-51b0-4d05-bc81-f6a39084d701",
"eventName": "GetBucketIntelligentTieringConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T18:46:07Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "03F058CVBQDF7QXX",
"requestParameters": {
"Host": "dw-probe.s3.us-west-1.amazonaws.com",
"bucketName": "dw-probe",
"id": "dw-probe",
"intelligent-tiering": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetBucketLifecycle
#Description
For an updated version of this API, see GetBucketLifecycleConfiguration.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 313,
"x-amz-id-2": "CTiNTOXxtLbBJFQ9ITNWSQPJrkE19NKVi1pT2uzI1Sodn7DL9UnobYxm6kbkbT4+uKxhu3a6MoM="
},
"awsRegion": "us-east-1",
"errorCode": "NoSuchLifecycleConfiguration",
"errorMessage": "The lifecycle configuration does not exist",
"eventCategory": "Management",
"eventID": "0aba48a0-49f4-4bbd-ab3f-6c75c8efb1ce",
"eventName": "GetBucketLifecycle",
"eventSource": "s3.amazonaws.com",
"eventTime": "2023-07-10T12:00:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "6T7WWC4P2D4GPWQN",
"requestParameters": {
"Host": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
"bucketName": "stratus-red-team-ctes-bucket-qyxyekjbtk",
"lifecycle": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::stratus-red-team-ctes-bucket-qyxyekjbtk",
"accountId": "123837392027",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "[APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_1d949e3e-4092-4c96-a6ef-96a967510a46 HashiCorp-terraform-exec/0.17.3]",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
GetBucketLocation
#Description
Using the GetBucketLocation operation is no longer a best practice.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 108,
"x-amz-id-2": "W6I1woNC4SkUGvYtfXAoAV7nYN5J3T9dpikLLl8JTNP/XA0acaLFd5mYN6etSxvZ6AIiuqevRP0="
},
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "1f07ad67-b44f-4f8f-87b4-3bcf4d2fdb46",
"eventName": "GetBucketLocation",
"eventSource": "s3.amazonaws.com",
"eventTime": "2023-07-10T11:43:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "XWA4G86RD2987F7J",
"requestParameters": {
"Host": "s3.us-east-1.amazonaws.com",
"bucketName": "invictus-aws-2022-10-27-8aukl",
"location": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::invictus-aws-2022-10-27-8aukl",
"accountId": "123837392027",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "10.248.16.43",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "s3.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "[Boto3/1.26.165 Python/3.10.6 Linux/5.19.0-46-generic Botocore/1.29.165]",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSCUXC3DDDP",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/benjamin",
"principalId": "AIDATFQR7NSC5U6Q3TMDR",
"type": "IAMUser",
"userName": "benjamin"
}
}
References #
GetBucketLogging
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 289,
"x-amz-id-2": "nCX0RuWZsl0hDNCONzAYqBJhruBw6bSHijA3R/7kWXrThHLww4fET3Gpafft53c3ujXoMsWlh+I="
},
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "b89b5aad-a778-47ab-a9bf-9cb0842f81b5",
"eventName": "GetBucketLogging",
"eventSource": "s3.amazonaws.com",
"eventTime": "2023-07-10T11:43:07Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "PQRSYJBACCRHAVPA",
"requestParameters": {
"Host": "invictus-aws-2022-10-27-8aukl.s3.us-east-1.amazonaws.com",
"bucketName": "invictus-aws-2022-10-27-8aukl",
"logging": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::invictus-aws-2022-10-27-8aukl",
"accountId": "123837392027",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "10.248.16.43",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "invictus-aws-2022-10-27-8aukl.s3.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "[Boto3/1.26.165 Python/3.10.6 Linux/5.19.0-46-generic Botocore/1.29.165]",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSCUXC3DDDP",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/benjamin",
"principalId": "AIDATFQR7NSC5U6Q3TMDR",
"type": "IAMUser",
"userName": "benjamin"
}
}
References #
GetBucketMetadataConfiguration
#Description
Retrieves the S3 Metadata configuration for a general purpose bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 298,
"x-amz-id-2": "3p6/B7yUfaq6WDPL9vZaSfF0df8r+REKHKaO273VEW3KWBlRQHpcM4KUJVfJNvsFsBfKJW3Aqz0="
},
"awsRegion": "us-west-1",
"errorCode": "NoSuchBucket",
"errorMessage": "The specified bucket does not exist",
"eventCategory": "Management",
"eventID": "8827138b-cfbc-4b47-91aa-35ba04703615",
"eventName": "GetBucketMetadataConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T18:46:07Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "03F6SAY1N5XGY73Q",
"requestParameters": {
"Host": "dw-probe.s3.us-west-1.amazonaws.com",
"bucketName": "dw-probe",
"metadataConfiguration": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetBucketMetadataTableConfiguration
#Description
We recommend that you retrieve your S3 Metadata configurations by using the V2 GetBucketMetadataTableConfiguration API operation.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 298,
"x-amz-id-2": "XW/QPuksGkGcASQ4AvADHimZwWHWDBFhXt9B+S7u9f0P8AI/wVN8sH5C0kno5zf5goXx7j+w4xQ="
},
"awsRegion": "us-west-1",
"errorCode": "NoSuchBucket",
"errorMessage": "The specified bucket does not exist",
"eventCategory": "Management",
"eventID": "15b0694b-ba4b-4a9b-a74b-4e9dba66e949",
"eventName": "GetBucketMetadataTableConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T18:46:07Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "03F8B8W9RRR4NKG6",
"requestParameters": {
"Host": "dw-probe.s3.us-west-1.amazonaws.com",
"bucketName": "dw-probe",
"metadataTable": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetBucketNotification
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "13a08591-5451-4920-8e54-f63c3e89efb3",
"eventName": "GetBucketNotification",
"eventSource": "s3.amazonaws.com",
"eventTime": "2017-02-12T20:38:21Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "DA7A691249E0886",
"requestParameters": {
"bucketName": "level3-b5677c799b465420d8e7b0a6689a0bb0c4afbc9e.flaws.cloud",
"notification": [
""
]
},
"responseElements": null,
"sourceIPAddress": "AWS Internal",
"userAgent": "[aws-internal/3]",
"userIdentity": {
"accessKeyId": "ASIALDOGXGOQA5IF2TC7",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:root",
"principalId": "811596193553",
"sessionContext": {
"attributes": {
"creationDate": "2017-02-12T19:57:05Z",
"mfaAuthenticated": "false"
}
},
"type": "Root"
}
}
References #
GetBucketOwnershipControls
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 321,
"x-amz-id-2": "QqR5FlH9No3Y5lAD3cCh6DcgYNEFz4RXHThsszajJ2To9oNBMhnZ4B+CId8uVZWVm1JQAloj+mA="
},
"awsRegion": "us-east-2",
"errorCode": "OwnershipControlsNotFoundError",
"errorMessage": "The bucket ownership controls were not found",
"eventCategory": "Management",
"eventID": "6604c21d-19f6-4b76-ae93-b07b5d89d31e",
"eventName": "GetBucketOwnershipControls",
"eventSource": "s3.amazonaws.com",
"eventTime": "2021-07-07T17:24:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "ZBKPDA19T3VTTYSB",
"requestParameters": {
"Host": "s3.us-east-2.amazonaws.com",
"bucketName": "cado-response-cados3bucketalt-1v7p4ao8z6xku",
"ownershipControls": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::cado-response-cados3bucketalt-1v7p4ao8z6xku",
"accountId": "797507667711",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "167.98.108.182",
"userAgent": "[S3Console/0.4, aws-internal/3 aws-sdk-java/1.11.1002 Linux/5.4.122-66.218.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.282-b08 java/1.8.0_282 vendor/Oracle_Corporation cfg/retry-mode/legacy]",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI37UYLMS4UD",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/sean",
"principalId": "AIDA3TLZJI375TCG5FSRI",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:56:28Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "sean"
},
"vpcEndpointId": "vpce-eca44785"
}
References #
GetBucketReplication
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 362,
"x-amz-id-2": "Z/W18FkXcg2VxLJ8rmaXFJaPCA22bkMXHNhc0hsWCoj4rFTzMx+Ce434/AW6gnB7+rWB7ISgZmk="
},
"awsRegion": "us-east-1",
"errorCode": "ReplicationConfigurationNotFoundError",
"errorMessage": "The replication configuration was not found",
"eventCategory": "Management",
"eventID": "933e890c-59c2-4b02-94f9-d897105774d7",
"eventName": "GetBucketReplication",
"eventSource": "s3.amazonaws.com",
"eventTime": "2023-07-10T12:00:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "FAG47VW6DAV6HNSS",
"requestParameters": {
"Host": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
"bucketName": "stratus-red-team-ctes-bucket-qyxyekjbtk",
"replication": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::stratus-red-team-ctes-bucket-qyxyekjbtk",
"accountId": "123837392027",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "[APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_1d949e3e-4092-4c96-a6ef-96a967510a46 HashiCorp-terraform-exec/0.17.3]",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
GetBucketRequestPayment
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 172,
"x-amz-id-2": "McA1LBXhV/96SQf7L/oNPu62KbafpSo3thi3aOG64fOm8XKguL3bFgiMninRP/mULpWTF4+U/So="
},
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "a8f9c9ca-2699-4671-95b3-c65680fe169f",
"eventName": "GetBucketRequestPayment",
"eventSource": "s3.amazonaws.com",
"eventTime": "2023-07-10T12:00:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "6T7PEWH8YDPMZYNJ",
"requestParameters": {
"Host": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
"bucketName": "stratus-red-team-ctes-bucket-qyxyekjbtk",
"requestPayment": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::stratus-red-team-ctes-bucket-qyxyekjbtk",
"accountId": "123837392027",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "[APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_1d949e3e-4092-4c96-a6ef-96a967510a46 HashiCorp-terraform-exec/0.17.3]",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
GetBucketWebsite
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 366,
"x-amz-id-2": "TpdrYTET2hjtrOYFH2msTUMMJGTyBLbUjPHnR7tILNDTnm9gpXY/e1Bud6AeXDl0YNa/BemTD6U="
},
"awsRegion": "us-east-1",
"errorCode": "NoSuchWebsiteConfiguration",
"errorMessage": "The specified bucket does not have a website configuration",
"eventCategory": "Management",
"eventID": "ac58e122-51a4-420a-a5c5-0db11a29829f",
"eventName": "GetBucketWebsite",
"eventSource": "s3.amazonaws.com",
"eventTime": "2023-07-10T12:00:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "DXXBR7T8B17BENKA",
"requestParameters": {
"Host": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
"bucketName": "stratus-red-team-ctes-bucket-qyxyekjbtk",
"website": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::stratus-red-team-ctes-bucket-qyxyekjbtk",
"accountId": "123837392027",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "stratus-red-team-ctes-bucket-qyxyekjbtk.s3.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "[APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_1d949e3e-4092-4c96-a6ef-96a967510a46 HashiCorp-terraform-exec/0.17.3]",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
GetObjectAcl
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"eventVersion": "1.11",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE"
},
"eventTime": "2026-07-28T21:18:50Z",
"eventSource": "s3.amazonaws.com",
"eventName": "GetObjectAcl",
"awsRegion": "us-west-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "[aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#s3api.get-object-acl]",
"requestParameters": {
"bucketName": "dw-harn-s3-e59db69d",
"Host": "dw-harn-s3-e59db69d.s3.us-west-1.amazonaws.com",
"acl": "",
"key": "dw-harn-e59db69d"
},
"responseElements": null,
"additionalEventData": {
"SignatureVersion": "SigV4",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"bytesTransferredIn": 0,
"AuthenticationMethod": "AuthHeader",
"x-amz-id-2": "ef9W/ZwMg+T2iKNth1mx4P8ytM1XXQlJX6FvvbZPjnoxJI49vzcgO0p6imoKvBKTNo5hiI383ZgDaDyedpAecg6eyslY1fHs",
"bytesTransferredOut": 480
},
"requestID": "WPXBWJA1AFWJ1FJR",
"eventID": "f16b17ed-f962-4bcc-8de2-6b4a2f7767af",
"readOnly": true,
"resources": [
{
"accountId": "123456789012",
"type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::dw-harn-s3-e59db69d"
},
{
"type": "AWS::S3::Object",
"ARN": "arn:aws:s3:::dw-harn-s3-e59db69d/dw-harn-e59db69d"
}
],
"eventType": "AwsApiCall",
"managementEvent": false,
"recipientAccountId": "123456789012",
"eventCategory": "Data",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-harn-s3-e59db69d.s3.us-west-1.amazonaws.com"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
GetObjectAnnotation
#Description
Retrieves an annotation from an Amazon S3 object.
GetObjectAttributes
#Description
Retrieves all of the metadata from an object without returning the object itself.
GetObjectLegalHold
#Description
This operation is not supported for directory buckets.
GetObjectLockConfiguration
#Description
This operation is not supported for directory buckets.
CloudTrail logs this operation under the eventName GetBucketObjectLockConfiguration; the catalog keys on the SDK operation name GetObjectLockConfiguration. A detection rule may use either name.Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 298,
"x-amz-id-2": "Nh6IyrFQGZEodtqaawSuwt9CoiQL2nzqXpwVg2POMcqu1sN3Xu2EX/a+jxiNnEwPBtzktJcDaeA="
},
"awsRegion": "us-west-1",
"errorCode": "NoSuchBucket",
"errorMessage": "The specified bucket does not exist",
"eventCategory": "Management",
"eventID": "7d606875-d767-4cfd-a1cf-72a0c9158394",
"eventName": "GetBucketObjectLockConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T18:46:07Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "03F0MG45QN31TZTW",
"requestParameters": {
"Host": "dw-probe.s3.us-west-1.amazonaws.com",
"bucketName": "dw-probe",
"object-lock": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetObjectRetention
#Description
This operation is not supported for directory buckets.
GetObjectTagging
#Description
This operation is not supported for directory buckets.
GetObjectTorrent
#Description
This operation is not supported for directory buckets.
HeadBucket
#Description
You can use this operation to determine if a bucket exists and if you have permission to access it.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "7d7132d9-dbf7-4c3b-bf59-d804bd23b40c",
"eventSource": "s3.amazonaws.com",
"eventName": "HeadBucket",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": false,
"requestID": "0F4Q66B4Q5TMQXF6",
"userAgent": "trustedadvisor.amazonaws.com",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::EXAMPLE"
},
{
"type": "AWS::S3::Object",
"ARNPrefix": "arn:aws:s3:::EXAMPLE"
}
]
}
HeadObject
#Description
The HEAD operation retrieves metadata from an object without returning the object itself.
ListDirectoryBuckets
#Description
Returns a list of all Amazon S3 directory buckets owned by the authenticated sender of the request.
ListMultipartUploads
#Description
This operation lists in-progress multipart uploads in a bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-SHA",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 417,
"x-amz-id-2": "Xbutbtlu9df9s7R2NmZG5GQtASbe2v5MI09KBmXcC5tQ+GvnIYwPXy7iUdVaYxv/wOT/gRWs9pw="
},
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "1ae13b3c-966b-4747-b35c-6909fea1d451",
"eventName": "ListMultipartUploads",
"eventSource": "s3.amazonaws.com",
"eventTime": "2021-07-07T18:14:18Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "V5JH5QBF7SZ75RM7",
"requestParameters": {
"Host": "cado-response-cados3bucketalt-1v7p4ao8z6xku.s3.dualstack.us-east-2.amazonaws.com",
"bucketName": "cado-response-cados3bucketalt-1v7p4ao8z6xku",
"delimiter": "/",
"prefix": "",
"uploads": "",
"x-amz-request-payer": "requester"
},
"resources": [
{
"ARN": "arn:aws:s3:::cado-response-cados3bucketalt-1v7p4ao8z6xku",
"accountId": "797507667711",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "167.98.108.182",
"userAgent": "[Cyberduck/7.9.1.34974 (Windows 10/10.0) (amd64)]",
"userIdentity": {
"accessKeyId": "AKIA3TLZJI372BTFKEHQ",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/sean",
"principalId": "AIDA3TLZJI375TCG5FSRI",
"type": "IAMUser",
"userName": "sean"
}
}
References #
ListObjectAnnotations
#Description
Lists the annotations attached to an Amazon S3 object.
ListObjectsV2
#Description
Returns some or all (up to 1,000) of the objects in a bucket with each request.
ListObjectVersions
#Description
This operation is not supported for directory buckets.
ListParts
#Description
Lists the parts that have been uploaded for a specific multipart upload.
PutBucketAbac
#Description
Sets the attribute-based access control (ABAC) property of the general purpose bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 97,
"bytesTransferredOut": 0,
"x-amz-id-2": "dgKfePm8EB/ngIQAddiHrJEqIyMCpYIHJtInBBt0aUIA/xBGBslUrl/HNsgqpU7WkGJTZ/1xA+k="
},
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "e1d0d6fa-8315-4867-b01e-8d6d4edfd9a1",
"eventName": "PutBucketAbac",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T20:58:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "794PVFCEKXF18JJ1",
"requestParameters": {
"AbacStatus": {
"Status": "Enabled",
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"Host": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
"abac": "",
"bucketName": "dwfix-main-921c7279"
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-main-921c7279",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,Z,U,D cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutBucketAccelerateConfiguration
#Description
This operation is not supported for directory buckets.
PutBucketAnalyticsConfiguration
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 132,
"bytesTransferredOut": 0,
"x-amz-id-2": "NmhKDLBFbN46zMoQPpbwaB14DgjkpoMu3+8r/TNPJzb0hIZ7qqtIQQy0c9sMAoxgm3jo8VD0nRWbXSrDWJPPej3Mj52bMxi8"
},
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "dc78e3ca-5c95-4025-abf7-697f0dc9312a",
"eventName": "PutBucketAnalyticsConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:07:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7Y2ZGZECGKQ5P8F8",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"analytics": "",
"bucketName": "dwfix-s3-123456789012-uw1",
"id": "dw"
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutBucketCors
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4"
},
"awsRegion": "us-west-2",
"errorCode": "AccessDenied",
"errorMessage": "Access Denied",
"eventID": "3b80225a-902b-481f-990e-346cd6344335",
"eventName": "PutBucketCors",
"eventSource": "s3.amazonaws.com",
"eventTime": "2019-05-07T15:06:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "80F0EAB4B0DE97F4",
"requestParameters": {
"CORSConfiguration": {
"CORSRule": {
"AllowedMethod": "GET",
"AllowedOrigin": "*"
},
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"bucketName": "flaws.cloud",
"cors": [
""
],
"host": [
"s3.us-west-2.amazonaws.com"
]
},
"responseElements": null,
"sourceIPAddress": "107.164.125.91",
"userAgent": "[Boto3/1.4.7 Python/2.7.15rc1 Linux/4.15.0-1035-aws Botocore/1.7.48]",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1567↳ also matches DeleteBucketCors, DeleteBucketLifecycle, DeleteBucketPolicy, DeleteBucketReplication, PutBucketAcl, PutBucketLifecycle, PutBucketPolicy, PutBucketReplication
References #
PutBucketEncryption
#Description
This operation configures default encryption and Amazon S3 Bucket Keys for an existing bucket.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 240,
"bytesTransferredOut": 0,
"x-amz-id-2": "PqdKdvrPL3dHT4syTYbCiVI5FFSHZH3RDFRIevWpOlGYKiU3HN9I4pHkaYSZtJ7D2g8QpFlzWim1ykF+4rfXlV/HvseiMLbU"
},
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "42d9418e-426e-4fee-91af-e8fcde481686",
"eventName": "PutBucketEncryption",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:07:56Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "G4Z47EF5KQ5YQCX3",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"ServerSideEncryptionConfiguration": {
"Rule": {
"ApplyServerSideEncryptionByDefault": {
"SSEAlgorithm": "AES256"
}
},
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"bucketName": "dwfix-s3-123456789012-uw1",
"encryption": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/U,Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutBucketIntelligentTieringConfiguration
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 223,
"bytesTransferredOut": 0,
"x-amz-id-2": "P4yTAwaW+/Cf6qWvTR5RZqLgFAZqqPaW881zT7gz8WJpkqsZJWup9WuHIEWQCX41aZ9dGTQPKmFhJ1SBFo5QnSP2kjaToeTw"
},
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "6b3e010e-9889-448e-91e6-bfcc90f33bee",
"eventName": "PutBucketIntelligentTieringConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:07:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7Y2YE395GNB2KGD1",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"IntelligentTieringConfiguration": {
"Id": "dw",
"Status": "Enabled",
"Tiering": {
"AccessTier": "ARCHIVE_ACCESS",
"Days": 90
},
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"bucketName": "dwfix-s3-123456789012-uw1",
"id": "dw",
"intelligent-tiering": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutBucketInventoryConfiguration
#Description
This implementation of the PUT action adds an S3 Inventory configuration (identified by the inventory ID) to the bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 454,
"bytesTransferredOut": 0,
"x-amz-id-2": "iL8qcEQ6LrPUeL8ufkVshXTQ5GquoF6lyVaHFw0PtPQDdB9rJK3HBoumSgipk39Ug/AmzUcQSzE="
},
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "c4ba6fe8-cabd-475a-a6e6-37f6eae00fc6",
"eventName": "PutBucketInventoryConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T20:58:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9B5FZDYXKN62HEDG",
"requestParameters": {
"Host": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
"InventoryConfiguration": {
"Destination": {
"S3BucketDestination": {
"AccountId": 123456789012,
"Bucket": "arn:aws:s3:::dwfix-main-921c7279",
"Format": "CSV",
"Prefix": "inventory/"
}
},
"Id": "dwfix-inventory",
"IncludedObjectVersions": "Current",
"IsEnabled": true,
"Schedule": {
"Frequency": "Daily"
},
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"bucketName": "dwfix-main-921c7279",
"id": "dwfix-inventory",
"inventory": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-main-921c7279",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutBucketLifecycleConfiguration
#Description
Creates a new lifecycle configuration for the bucket or replaces an existing lifecycle configuration.
PutBucketMetricsConfiguration
#Description
Sets a metrics configuration (specified by the metrics configuration ID) for the bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 104,
"bytesTransferredOut": 0,
"x-amz-id-2": "wh8K294tnDPj1Xe6S/eZaMwUUNW3Yc8/8bD23v3+JdUH6g3jE4PndUWvIZDWRX1rw2Q+2lziJVYrU/vGfXFqHs9SFYGXBHaH"
},
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "ff7b5a73-1aaf-48c0-9fd5-53420a73ee0c",
"eventName": "PutBucketMetricsConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:07:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7Y2VWTA7AKZET7CA",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"bucketName": "dwfix-s3-123456789012-uw1",
"id": "dw",
"metrics": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,b,Z,n cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutBucketNotification
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4"
},
"awsRegion": "us-west-2",
"errorCode": "AccessDenied",
"errorMessage": "Access Denied",
"eventID": "97f9c0f7-c285-4653-b6bb-313e676c21ef",
"eventName": "PutBucketNotification",
"eventSource": "s3.amazonaws.com",
"eventTime": "2019-05-07T15:07:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "E1347D268AA5D801",
"requestParameters": {
"NotificationConfiguration": {
"TopicConfiguration": {
"Event": "s3:ReducedRedundancyLostObject",
"Topic": "arn:aws:sns:us-west-2:005412338514:sns-topic-one"
},
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"bucketName": "flaws.cloud",
"host": [
"s3.us-west-2.amazonaws.com"
],
"notification": [
""
]
},
"responseElements": null,
"sourceIPAddress": "107.164.125.91",
"userAgent": "[Boto3/1.4.7 Python/2.7.15rc1 Linux/4.15.0-1035-aws Botocore/1.7.48]",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
PutBucketNotificationConfiguration
#Description
This operation is not supported for directory buckets.
PutBucketOwnershipControls
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 155,
"bytesTransferredOut": 0,
"x-amz-id-2": "EDHRFFl4Cd+WIdTaHx80bWNIrig52W0tsCI2YYK1ebZjWhdH1NYmbDdMtjYJ6ipKBTCTnsKt12qipghIi3LFlxrHZoPQa3Yf"
},
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "0fe7b60a-8843-457e-804e-2c78b32c0597",
"eventName": "PutBucketOwnershipControls",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:07:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "W6T1TQ9Z7GKHR4Z7",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"OwnershipControls": {
"Rule": {
"ObjectOwnership": "BucketOwnerPreferred"
},
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"bucketName": "dwfix-s3-123456789012-uw1",
"ownershipControls": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/U,Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutBucketRequestPayment
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 133,
"bytesTransferredOut": 0,
"x-amz-id-2": "DI0fzy+xnJciTtQizE5pRiUeHIhFkUwDk9xXabnlHGjqFa3rolVE3RiFmWiDAwg07Zi+T+rmb3djrh6LOjOzZjwjhf1hlMDB"
},
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f0eea530-158e-48be-8164-6800e7b4a2cc",
"eventName": "PutBucketRequestPayment",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:07:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "W6TFCRGJKFF6PG8D",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"RequestPaymentConfiguration": {
"Payer": "BucketOwner",
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"bucketName": "dwfix-s3-123456789012-uw1",
"requestPayment": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/U,Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutBucketTagging
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"eventVersion": "1.11",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE"
},
"eventTime": "2026-07-28T20:59:29Z",
"eventSource": "s3.amazonaws.com",
"eventName": "PutBucketTagging",
"awsRegion": "us-west-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "[aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/n,W,Z,E,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#s3api.put-bucket-tagging]",
"requestParameters": {
"Tagging": {
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/",
"TagSet": {
"Tag": {
"Value": "aws_harness",
"Key": "dw-harness"
}
}
},
"tagging": "",
"bucketName": "dw-harn-s3-eb786637",
"Host": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
},
"responseElements": null,
"additionalEventData": {
"SignatureVersion": "SigV4",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"bytesTransferredIn": 142,
"AuthenticationMethod": "AuthHeader",
"x-amz-id-2": "fmIErzGMti7rperNyTlBoli7aZfaWF43fclVRHTGqvtZih47cpMq08bL47YaFMpZ75EUkOzTmj9Z2IZmwvehw0b/CfJpJYXI",
"bytesTransferredOut": 0
},
"requestID": "0QPXGGBB5FPG1337",
"eventID": "2095f7a8-2908-4cf7-a156-d2971508ff35",
"readOnly": false,
"resources": [
{
"accountId": "123456789012",
"type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::dw-harn-s3-eb786637"
}
],
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-harn-s3-eb786637.s3.us-west-1.amazonaws.com"
}
}
PutObjectAcl
#Description
End of support notice: As of October 1, 2025, Amazon S3 has discontinued support for Email Grantee Access Control Lists (ACLs).
CloudTrail data event: not logged by a standard management-events trail. Requires explicit data-event configuration (an advanced event selector) on the trail or CloudTrail Lake; absence of this event does not prove the action did not occur. S3 data event. Requires S3 data-event logging on the trail. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"aclRequired": "Yes",
"bytesTransferredIn": 0,
"bytesTransferredOut": 0,
"x-amz-id-2": "WdQ2bx6z/QbIBlYUc8eugUivzwtd8wxE17nIjLta7J2PrihHWlRy/4F6vyeRUsBM4aiZCWwqfzBu1o7PU5btEis7TN1UvsdJ"
},
"awsRegion": "us-west-1",
"eventCategory": "Data",
"eventID": "9b8364bc-b232-483b-b6c9-c76313c0b20d",
"eventName": "PutObjectAcl",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:07:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": false,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7Y2QA4BVSJQ6ZE64",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"acl": "",
"bucketName": "dwfix-s3-123456789012-uw1",
"key": "dw.txt",
"x-amz-acl": "private"
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
},
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1/dw.txt",
"type": "AWS::S3::Object"
}
],
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/U,Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Kusto #
T1537Panther #
PutObjectAnnotation
#Description
Attaches an annotation to an Amazon S3 object.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 61,
"bytesTransferredOut": 179,
"x-amz-id-2": "7uLxIbYWknSnU9IpNdvoyzcX1obO9fYR/lPF7DUs+5QHvb1L0L3bG6brtiVsqHnOYENNesggk5s="
},
"awsRegion": "us-west-1",
"eventCategory": "Data",
"eventID": "b730a2b2-cdc7-4672-804f-b9007905e193",
"eventName": "PutObjectAnnotation",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T20:58:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": false,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "794N704X7Z5BT4WS",
"requestParameters": {
"Host": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
"annotation": "",
"annotationName": "dwfix-annotation",
"bucketName": "dwfix-main-921c7279",
"key": "test-object.txt"
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-main-921c7279",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
},
{
"ARN": "arn:aws:s3:::dwfix-main-921c7279/test-object.txt",
"type": "AWS::S3::Object"
}
],
"responseElements": {
"x-amz-server-side-encryption": "AES256"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/n,b,Z,U,D cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutObjectLegalHold
#Description
This operation is not supported for directory buckets.
PutObjectLockConfiguration
#Description
This operation is not supported for directory buckets.
PutObjectRetention
#Description
This operation is not supported for directory buckets.
PutObjectTagging
#Description
This operation is not supported for directory buckets.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 126,
"bytesTransferredOut": 0,
"x-amz-id-2": "II6G4NY0RPbtQDQprMxlx4CG8iGcYB4TO3TuIJznMgbkmHMqRRIwiVb9bpn8eYJd4WuOvcDGR4vreCElxkGDw2PZLZhxxvO8"
},
"awsRegion": "us-west-1",
"eventCategory": "Data",
"eventID": "d5703205-cd0f-4afe-b04f-33c5a5f8348d",
"eventName": "PutObjectTagging",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:07:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": false,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7Y2YPHQ36N6X484H",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"bucketName": "dwfix-s3-123456789012-uw1",
"key": "dw.txt",
"tagging": ""
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
},
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1/dw.txt",
"type": "AWS::S3::Object"
}
],
"responseElements": {
"x-amz-version-id": "XqF3Ks1g6Dl23X61f0Jx4ONJSggFg4Gm"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/U,Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
PutPublicAccessBlock
#Description
This operation is not supported for directory buckets.
RenameObject
#Description
Renames an existing object in a directory bucket that uses the S3 Express One Zone storage class.
SelectObjectContent
#Description
This operation is not supported for directory buckets.
UpdateBucketMetadataAnnotationTableConfiguration
#Description
Updates the annotation table configuration for an Amazon S3 bucket's metadata configuration.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 157,
"bytesTransferredOut": 298,
"x-amz-id-2": "AR8hoJ2grjBSlgpEL9z8Z241L24jVd9XaApl7bsEy75BSEiE50AQ7eUTvsqDBCY76arnf0jeHPo="
},
"awsRegion": "us-west-1",
"errorCode": "NoSuchBucket",
"errorMessage": "The specified bucket does not exist",
"eventCategory": "Management",
"eventID": "26bd1f25-9018-47bc-a9c3-ba5efd59c209",
"eventName": "UpdateBucketMetadataAnnotationTableConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:26:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "S0YQQP98VQ9BB483",
"requestParameters": {
"AnnotationTableConfiguration": {
"ConfigurationState": "ENABLED",
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"Host": "dw-probe.s3.us-west-1.amazonaws.com",
"bucketName": "dw-probe",
"metadataAnnotationTable": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,U,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateBucketMetadataInventoryTableConfiguration
#Description
Enables or disables a live inventory table for an S3 Metadata configuration on a general purpose bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 155,
"bytesTransferredOut": 318,
"x-amz-id-2": "TJQe+WtXM+HQ7HfWd7YLAtb3Z/utiD8c/M2Ywz5fvKbIOIIn6AGKS5oOAOtCJILyr5a0Mp0gZUT/IvPTOlKvWoJuuZ5r3mp7"
},
"awsRegion": "us-west-1",
"errorCode": "NoSuchBucket",
"errorMessage": "The specified bucket does not exist",
"eventCategory": "Management",
"eventID": "83b9f1ec-9157-4bd2-80fc-ced4104dff0d",
"eventName": "UpdateBucketMetadataInventoryTableConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:26:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "S0YR36KPW9CCH223",
"requestParameters": {
"Host": "dw-probe.s3.us-west-1.amazonaws.com",
"InventoryTableConfiguration": {
"ConfigurationState": "ENABLED",
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"bucketName": "dw-probe",
"metadataInventoryTable": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,U,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateBucketMetadataJournalTableConfiguration
#Description
Enables or disables journal table record expiration for an S3 Metadata configuration on a general purpose bucket.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 172,
"bytesTransferredOut": 298,
"x-amz-id-2": "UD2KgCUdbRw4VGqLaCP3qvN7Vu+VtjXiFpNuoHHLmwtlHhWrKBdTK7Qp0DdP33O2myiejNDwyy4="
},
"awsRegion": "us-west-1",
"errorCode": "NoSuchBucket",
"errorMessage": "The specified bucket does not exist",
"eventCategory": "Management",
"eventID": "7c722329-ef76-425c-93bb-b09c16a1b9dc",
"eventName": "UpdateBucketMetadataJournalTableConfiguration",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:26:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "S0YWRJ9RPRHVXGEV",
"requestParameters": {
"Host": "dw-probe.s3.us-west-1.amazonaws.com",
"JournalTableConfiguration": {
"RecordExpiration": {
"Expiration": "ENABLED"
},
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/"
},
"bucketName": "dw-probe",
"metadataJournalTable": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dw-probe.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,U,D,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateObjectEncryption
#Description
This operation is not supported for directory buckets or Amazon S3 on Outposts buckets.
UploadPart
#Description
Uploads a part in a multipart upload.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 47,
"bytesTransferredOut": 0,
"x-amz-id-2": "LdXCdhcGAHHLCNi21E/pqSQOh6ODsM0ygdHgLrRXvEZvjCgCjb6S5pVWvfo4lAA4tQ1RiAXeGZjLV1hvz31U1yOZu0E2a88z"
},
"awsRegion": "us-west-1",
"eventCategory": "Data",
"eventID": "1a9c4e28-1d20-47fe-94f6-5fab2c9b3713",
"eventName": "UploadPart",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T19:07:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": false,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7Y2ZPGHMXKWHGVA9",
"requestParameters": {
"Host": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"bucketName": "dwfix-s3-123456789012-uw1",
"key": "mp.txt",
"partNumber": "1",
"uploadId": "vjrRU8b9IkTn.BdpAS76xpfkVVBa0mQqYz8sgwPnWhMa2DzTN3jWbTfqfJuTPBj2GanWuDpdI9CGRS9KGhHPMD17mhoeHmAffPo6EHWGnznmWp7y0zNt9x4Ja1HMh6Y5"
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
},
{
"ARN": "arn:aws:s3:::dwfix-s3-123456789012-uw1/mp.txt",
"type": "AWS::S3::Object"
}
],
"responseElements": {
"x-amz-server-side-encryption": "AES256"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-s3-123456789012-uw1.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/U,Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UploadPartCopy
#Description
Uploads a part by copying data from an existing object as data source.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "TLS_AES_128_GCM_SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 220,
"x-amz-id-2": "542/NnTtkq7OLim3CV+u/UrtiSfcMVGcD5fqdacxAZ7UpNPNQlZOsI3bkAloFoVOySWCRdA/1qU="
},
"awsRegion": "us-west-1",
"eventCategory": "Data",
"eventID": "96d051f6-0918-4747-b060-a40c836e5be4",
"eventName": "UploadPartCopy",
"eventSource": "s3.amazonaws.com",
"eventTime": "2026-06-29T20:58:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": false,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "794VJ8B04MVN34T4",
"requestParameters": {
"Host": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
"bucketName": "dwfix-main-921c7279",
"key": "mpu-object.txt",
"partNumber": "2",
"uploadId": "adI6a0ON5uIMbksUQjUaQDIyquNC_OPDf7eor8NZkSLr0WAKY.L8Blodil..WUaqF3ZciTtepqPeWerPn1q1CC5YZlnZExQeW.JfIRqg2yd9lO07ZmIU.f0TfMFZh3.F",
"x-amz-copy-source": "dwfix-main-921c7279/test-object.txt"
},
"resources": [
{
"ARN": "arn:aws:s3:::dwfix-main-921c7279",
"accountId": "123456789012",
"type": "AWS::S3::Bucket"
},
{
"ARN": "arn:aws:s3:::dwfix-main-921c7279/mpu-object.txt",
"type": "AWS::S3::Object"
},
{
"ARN": "arn:aws:s3:::dwfix-main-921c7279/test-object.txt",
"type": "AWS::S3::Object"
}
],
"responseElements": {
"x-amz-server-side-encryption": "AES256"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "dwfix-main-921c7279.s3.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "[Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,n,b cfg/retry-mode#legacy Botocore/1.43.36]",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
WriteGetObjectResponse
#Description
This operation is not supported for directory buckets.
GetAccountPublicAccessBlock
#Description
Retrieves the public access block configuration for an AWS account; CloudTrail eventName for the GetPublicAccessBlock API at the account level.
Example CloudTrail Event #
{
"additionalEventData": {
"AuthenticationMethod": "AuthHeader",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"SignatureVersion": "SigV4",
"bytesTransferredIn": 0,
"bytesTransferredOut": 274,
"x-amz-id-2": "rfW4obUXUJPAoQs2hnZDo3sb9F/kP1rMAGCXUBLTCRb2sjNdwDUnl4hFRRAs2ABSt4yrghlZkSk="
},
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "Access Denied",
"eventCategory": "Management",
"eventID": "15349b87-ec43-44b8-bf51-2381e6dd8552",
"eventName": "GetAccountPublicAccessBlock",
"eventSource": "s3.amazonaws.com",
"eventTime": "2021-04-13T11:36:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "731544447609",
"requestID": "X1DWMM0KGEZEND7W",
"requestParameters": {
"Host": "731544447609.s3-control.us-east-1.amazonaws.com"
},
"responseElements": null,
"sourceIPAddress": "34.12.134.20",
"userAgent": "[aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback]",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
"accountId": "731544447609",
"arn": "arn:aws:iam::731544447609:user/cloudsploit",
"principalId": "AIDAYTOGP2RLMDEPWZWMJ",
"type": "IAMUser",
"userName": "cloudsploit"
}
}
References #
GetMultiRegionAccessPoint
#Description
GetMultiRegionAccessPoint recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "fc41dbf5-d94c-4ace-b648-d3f38750d700",
"eventSource": "s3.amazonaws.com",
"eventName": "GetMultiRegionAccessPoint",
"awsRegion": "us-west-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "8B58F99GM56QS3NK",
"userAgent": "access-analyzer.amazonaws.com"
}
GetMultiRegionAccessPointPolicy
#Description
GetMultiRegionAccessPointPolicy recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "f78e99c1-6098-441d-9d48-5defa6012afc",
"eventSource": "s3.amazonaws.com",
"eventName": "GetMultiRegionAccessPointPolicy",
"awsRegion": "us-west-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "62ZNHDDW37AVGTRC",
"userAgent": "[aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/s3control#1.69.0 m/E,i]",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "123456789012.s3-control.us-west-2.amazonaws.com"
}
}
GetMultiRegionAccessPointPolicyStatus
#Description
GetMultiRegionAccessPointPolicyStatus recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "ec2cb003-5b29-4943-ad1f-072d3c3cbfad",
"eventSource": "s3.amazonaws.com",
"eventName": "GetMultiRegionAccessPointPolicyStatus",
"awsRegion": "us-west-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "7R79J4DHBFXT4YW6",
"userAgent": "access-analyzer.amazonaws.com"
}
GetStorageLensConfiguration
#Description
GetStorageLensConfiguration recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "c510cadf-dc12-4383-b50c-9b5a7b47288a",
"eventSource": "s3.amazonaws.com",
"eventName": "GetStorageLensConfiguration",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "RDZM8XKCG2TX8W5F",
"userAgent": "[aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/s3control#1.69.0 m/E]",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "123456789012.s3-control.us-east-1.amazonaws.com"
}
}
GetStorageLensConfigurationTagging
#Description
GetStorageLensConfigurationTagging recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "d2decef5-890d-4fef-bd82-2c88df3370a9",
"eventSource": "s3.amazonaws.com",
"eventName": "GetStorageLensConfigurationTagging",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "RDZRGP91PD4B0J26",
"userAgent": "[aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/s3control#1.69.0 m/E]",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "123456789012.s3-control.us-east-1.amazonaws.com"
}
}
ListAccessGrants
#Description
ListAccessGrants recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "bdc10e4a-3744-4b8f-881c-d57553a6e3e7",
"eventSource": "s3.amazonaws.com",
"eventName": "ListAccessGrants",
"awsRegion": "eu-west-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "0E26GC92ECKMDHN4",
"userAgent": "config.amazonaws.com",
"errorCode": "AccessGrantsInstanceNotExistsError"
}
ListAccessGrantsInstances
#Description
ListAccessGrantsInstances recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "93796275-2155-4e1f-86cd-8e9318a4bdce",
"eventSource": "s3.amazonaws.com",
"eventName": "ListAccessGrantsInstances",
"awsRegion": "us-west-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "4KY08KNBX1G0DP8R",
"userAgent": "config.amazonaws.com"
}
ListAccessGrantsLocations
#Description
ListAccessGrantsLocations recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "296a2947-9112-4a06-8e2c-06a42f02389b",
"eventSource": "s3.amazonaws.com",
"eventName": "ListAccessGrantsLocations",
"awsRegion": "ap-southeast-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "W08NCHB8NH903M1X",
"userAgent": "config.amazonaws.com",
"errorCode": "AccessGrantsInstanceNotExistsError"
}
ListAccessPoints
#Description
ListAccessPoints recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "722996e2-9bf1-4560-8014-69ec04a47466",
"eventSource": "s3.amazonaws.com",
"eventName": "ListAccessPoints",
"awsRegion": "eu-central-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "TJEAMJEEQTH6SP8C",
"userAgent": "cloudformation.amazonaws.com"
}
ListMultiRegionAccessPoints
#Description
ListMultiRegionAccessPoints recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "43802c1d-c034-4e04-8fc0-e1844d075df3",
"eventSource": "s3.amazonaws.com",
"eventName": "ListMultiRegionAccessPoints",
"awsRegion": "us-west-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "KTBPRNHZMGEWEFAN",
"userAgent": "access-analyzer.amazonaws.com"
}
ListStorageLensConfigurations
#Description
ListStorageLensConfigurations recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "d0a36151-e582-433f-ac2c-261acfe5d2b3",
"eventSource": "s3.amazonaws.com",
"eventName": "ListStorageLensConfigurations",
"awsRegion": "ca-central-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "RDZZFD9VTGE3NPK1",
"userAgent": "[aws-sdk-go-v2/1.43.0 ua/2.1 os/linux lang/go#1.26.5 md/GOOS#linux md/GOARCH#arm64 api/s3control#1.69.0 m/C,E]",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "123456789012.s3-control.ca-central-1.amazonaws.com"
}
}
ListStorageLensGroups
#Description
ListStorageLensGroups recorded by CloudTrail for Amazon S3. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "f0952ac1-ec11-422a-8b30-67892856bb22",
"eventSource": "s3.amazonaws.com",
"eventName": "ListStorageLensGroups",
"awsRegion": "us-west-2",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "FKNKT3R4TEYYHQFS",
"userAgent": "config.amazonaws.com"
}
PutAccessPointPolicy
#Description
Associates an access policy with the specified Amazon S3 access point, replacing any existing policy.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Condition (kusto rule field) | is_null | | 1 rule | kusto |
Effect (kusto rule field) | eq | allow | 1 rule | kusto |
Principal (kusto rule field) | eq | * | 1 rule | kusto |
Principal_aws (kusto rule field) | eq | * | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1537
AssociateAccessGrantsIdentityCenter
#Description
Associate your S3 Access Grants instance with an Amazon Web Services IAM Identity Center instance.
CreateAccessGrant
#Description
Creates an access grant that gives a grantee access to your S3 data.
CreateAccessGrantsInstance
#Description
Creates an S3 Access Grants instance, which serves as a logical grouping for access grants.
CreateAccessGrantsLocation
#Description
The S3 data location that you would like to register in your S3 Access Grants instance.
CreateAccessPoint
#Description
Creates an access point and associates it to a specified bucket.
CreateAccessPointForObjectLambda
#Description
This operation is not supported by directory buckets.
CreateJob
#Description
This operation creates an S3 Batch Operations job.
CreateMultiRegionAccessPoint
#Description
This operation is not supported by directory buckets.
CreateStorageLensGroup
#Description
Creates a new S3 Storage Lens group and associates it with the specified Amazon Web Services account ID.
DeleteAccessGrant
#Description
Deletes the access grant from the S3 Access Grants instance.
DeleteAccessGrantsInstance
#Description
Deletes your S3 Access Grants instance.
DeleteAccessGrantsInstanceResourcePolicy
#Description
Deletes the resource policy of the S3 Access Grants instance.
DeleteAccessGrantsLocation
#Description
Deregisters a location from your S3 Access Grants instance.
DeleteAccessPoint
#Description
Deletes the specified access point.
DeleteAccessPointForObjectLambda
#Description
This operation is not supported by directory buckets.
DeleteAccessPointPolicy
#Description
Deletes the access point policy for the specified access point.
DeleteAccessPointPolicyForObjectLambda
#Description
This operation is not supported by directory buckets.
DeleteAccessPointScope
#Description
Deletes an existing access point scope for a directory bucket.
DeleteBucketLifecycleConfiguration
#Description
This action deletes an Amazon S3 on Outposts bucket's lifecycle configuration.
DeleteJobTagging
#Description
Removes the entire tag set from the specified S3 Batch Operations job.
DeleteMultiRegionAccessPoint
#Description
This operation is not supported by directory buckets.
DeleteStorageLensConfiguration
#Description
This operation is not supported by directory buckets.
DeleteStorageLensConfigurationTagging
#Description
This operation is not supported by directory buckets.
DeleteStorageLensGroup
#Description
Deletes an existing S3 Storage Lens group.
DescribeJob
#Description
Retrieves the configuration parameters and status for a Batch Operations job.
DescribeMultiRegionAccessPointOperation
#Description
This operation is not supported by directory buckets.
DissociateAccessGrantsIdentityCenter
#Description
Dissociates the Amazon Web Services IAM Identity Center instance from the S3 Access Grants instance.
GetAccessGrant
#Description
Get the details of an access grant from your S3 Access Grants instance.
GetAccessGrantsInstance
#Description
Retrieves the S3 Access Grants instance for a Region in your account.
GetAccessGrantsInstanceForPrefix
#Description
Retrieve the S3 Access Grants instance that contains a particular prefix.
GetAccessGrantsInstanceResourcePolicy
#Description
Returns the resource policy of the S3 Access Grants instance.
GetAccessGrantsLocation
#Description
Retrieves the details of a particular location registered in your S3 Access Grants instance.
GetAccessPoint
#Description
Returns configuration information about the specified access point.
GetAccessPointConfigurationForObjectLambda
#Description
This operation is not supported by directory buckets.
GetAccessPointForObjectLambda
#Description
This operation is not supported by directory buckets.
GetAccessPointPolicy
#Description
Returns the access point policy associated with the specified access point.
GetAccessPointPolicyForObjectLambda
#Description
This operation is not supported by directory buckets.
GetAccessPointPolicyStatus
#Description
This operation is not supported by directory buckets.
GetAccessPointPolicyStatusForObjectLambda
#Description
This operation is not supported by directory buckets.
GetAccessPointScope
#Description
Returns the access point scope for a directory bucket.
GetBucket
#Description
Gets an Amazon S3 on Outposts bucket.
GetDataAccess
#Description
Returns a temporary access credential from S3 Access Grants to the grantee or client application.
GetJobTagging
#Description
Returns the tags on an S3 Batch Operations job.
GetMultiRegionAccessPointRoutes
#Description
This operation is not supported by directory buckets.
GetStorageLensGroup
#Description
Retrieves the Storage Lens group configuration details.
ListAccessPointsForDirectoryBuckets
#Description
Returns a list of the access points that are owned by the Amazon Web Services account and that are associated with the specified directory bucket.
ListAccessPointsForObjectLambda
#Description
This operation is not supported by directory buckets.
ListCallerAccessGrants
#Description
Use this API to list the access grants that grant the caller access to Amazon S3 data through S3 Access Grants.
ListJobs
#Description
Lists current S3 Batch Operations jobs as well as the jobs that have ended within the last 90 days for the Amazon Web Services account making the request.
ListRegionalBuckets
#Description
This operation is not supported by directory buckets.
PutAccessGrantsInstanceResourcePolicy
#Description
Updates the resource policy of the S3 Access Grants instance.
PutAccessPointConfigurationForObjectLambda
#Description
This operation is not supported by directory buckets.
PutAccessPointPolicyForObjectLambda
#Description
This operation is not supported by directory buckets.
PutAccessPointScope
#Description
Creates or replaces the access point scope for a directory bucket.
PutJobTagging
#Description
Sets the supplied tag-set on an S3 Batch Operations job.
PutMultiRegionAccessPointPolicy
#Description
This operation is not supported by directory buckets.
PutStorageLensConfiguration
#Description
This operation is not supported by directory buckets.
PutStorageLensConfigurationTagging
#Description
This operation is not supported by directory buckets.
SubmitMultiRegionAccessPointRoutes
#Description
This operation is not supported by directory buckets.
TagResource
#Description
Creates a new user-defined tag or updates an existing tag.
UntagResource
#Description
This operation removes the specified user-defined tags from an S3 resource.
UpdateAccessGrantsLocation
#Description
Updates the IAM role of a registered location in your S3 Access Grants instance.
UpdateJobPriority
#Description
Updates an existing S3 Batch Operations job's priority.
UpdateJobStatus
#Description
Updates the status for the specified job.
UpdateStorageLensGroup
#Description
Updates the existing Storage Lens group.