AWS CloudTrail: S3 Browser creates Inline IAM policy with default bucket placeholder
Detects S3 Browser–initiated IAM PutUserPolicy requests that include a templated S3 bucket placeholder in the inline policy.
FreeUnreviewedSigmahighv1
aws-cloudtrail-s3-browser-creates-inline-iam-policy-with-default-bucket-placehol-db014773
title: "AWS CloudTrail: S3 Browser creates Inline IAM policy with default bucket placeholder"
id: 850a45a6-2c78-4d4d-9c91-faf0cbd389e0
status: test
description: This rule flags AWS IAM PutUserPolicy events where the request originates from an S3 Browser user agent and the inline policy contains a default S3 bucket placeholder string "<YOUR-BUCKET-NAME>". Attackers and misconfigurations can use template-based policy creation to quickly grant access, sometimes unintentionally leaving placeholder values in the policy document. It relies on CloudTrail IAM event data, including eventSource/eventName, userAgent, and requestParameters text patterns in the policy content.
references:
- https://permiso.io/blog/s/unmasking-guivil-new-cloud-threat-actor
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/aws/cloudtrail/aws_iam_s3browser_templated_s3_bucket_policy_creation.yml
author: daniel.bohannon@permiso.io (@danielhbohannon), Huntrule Team
date: 2023-05-17
tags:
- attack.execution
- attack.stealth
- attack.t1059.009
- attack.persistence
- attack.initial-access
- attack.privilege-escalation
- attack.t1078.004
logsource:
product: aws
service: cloudtrail
detection:
selection:
eventSource: iam.amazonaws.com
eventName: PutUserPolicy
userAgent|contains: S3 Browser
requestParameters|contains|all:
- '"arn:aws:s3:::<YOUR-BUCKET-NAME>/*"'
- '"s3:GetObject"'
- '"Allow"'
condition: selection
falsepositives:
- Valid usage of S3 browser with accidental creation of default Inline IAM policy without changing default S3 bucket name placeholder value
level: high
license: DRL-1.1
related:
- id: db014773-7375-4f4e-b83b-133337c0ffee
type: derived
What it detects
This rule flags AWS IAM PutUserPolicy events where the request originates from an S3 Browser user agent and the inline policy contains a default S3 bucket placeholder string "<YOUR-BUCKET-NAME>". Attackers and misconfigurations can use template-based policy creation to quickly grant access, sometimes unintentionally leaving placeholder values in the policy document. It relies on CloudTrail IAM event data, including eventSource/eventName, userAgent, and requestParameters text patterns in the policy content.
Known false positives
- Valid usage of S3 browser with accidental creation of default Inline IAM policy without changing default S3 bucket name placeholder value
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.