Title:
AWS IAM S3Browser Templated S3 Bucket Policy Creation
Status:
test
Description:Detects S3 browser utility creating Inline IAM policy containing default S3 bucket name placeholder value of "<YOUR-BUCKET-NAME>".
References:
-https://permiso.io/blog/s/unmasking-guivil-new-cloud-threat-actor
Author: daniel.bohannon@permiso.io (@danielhbohannon)
Date: 2023-05-17
modified:None
Tags:
- -'attack.execution'
- -'attack.stealth'
- -'attack.t1059.009'
- -'attack.persistence'
- -'attack.initial-access'
- -'attack.privilege-escalation'
- -'attack.t1078.004'
Logsource:
- product: aws
- service: cloudtrail
Detection:
selection:
eventSource:
'iam.amazonaws.com'
eventName:
'PutUserPolicy'
userAgent|contains:
'S3 Browser'
requestParameters|contains|all:
-'"arn:aws:s3:::<YOUR-BUCKET-NAME>/*"'
-'"s3:GetObject"'
-'"Allow"'
condition:
selection
Falsepositives:
-Valid usage of S3 browser with accidental creation of default Inline IAM policy without changing default S3 bucket name placeholder value
Level:
high