Technique.View on attack.mitre.org
Adversaries may enumerate objects in cloud storage infrastructure. Adversaries may use this information during automated discovery to shape follow-on behaviors, including requesting all or specific objects from cloud storage. Similar to File and Directory Discovery on a local host, after identifying available storage services (i.e. Cloud Infrastructure Discovery) adversaries may access the contents/objects stored in cloud infrastructure.
Cloud service providers offer APIs allowing users to enumerate objects stored within cloud storage. Examples include ListObjectsV2 in AWS and List Blobs in Azure .
Rules on DetectionCode tagged with T1619.
| Rule | Level | Log source |
|---|---|---|
| Potential Bucket Enumeration on AWS | low | aws / NULL |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupShinyHunters | ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to access S3 objects. |
| Used by | Procedure example |
|---|---|
| ToolPacu | Pacu can enumerate AWS storage services, such as S3 buckets and Elastic Block Store volumes. |
| ToolPeirates | Peirates can list AWS S3 buckets. |
| ToolTruffleHog | TruffleHog can enumerate cloud storage environments including Amazon Web Service (AWS) S3 buckets and Google Cloud Storage buckets. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.