AWS IAM S3Browser Templated S3 Bucket Policy Creation

 Original Source: [Sigma source]
Title: AWS IAM S3Browser Templated S3 Bucket Policy Creation
Status: test
Description:Detects S3 browser utility creating Inline IAM policy containing default S3 bucket name placeholder value of "<YOUR-BUCKET-NAME>".
References:
  -https://permiso.io/blog/s/unmasking-guivil-new-cloud-threat-actor
Author: daniel.bohannon@permiso.io (@danielhbohannon)
Date: 2023-05-17
modified:None
Tags:
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1059.009'
  • -'attack.persistence'
  • -'attack.initial-access'
  • -'attack.privilege-escalation'
  • -'attack.t1078.004'
Logsource:
  • product: aws
  • service: cloudtrail
Detection:
  selection:
    eventSource: 'iam.amazonaws.com'
    eventName: 'PutUserPolicy'
    userAgent|contains: 'S3 Browser'
    requestParameters|contains|all:
      -'"arn:aws:s3:::<YOUR-BUCKET-NAME>/*"'
      -'"s3:GetObject"'
      -'"Allow"'

  condition:selection
Falsepositives:
  -Valid usage of S3 browser with accidental creation of default Inline IAM policy without changing default S3 bucket name placeholder value
Level: high