AWS CloudTrail: S3 Browser creates Inline IAM policy with default bucket placeholder

Detects S3 Browser–initiated IAM PutUserPolicy requests that include a templated S3 bucket placeholder in the inline policy.

FreeUnreviewedSigmahighv1
title: "AWS CloudTrail: S3 Browser creates Inline IAM policy with default bucket placeholder"
id: 850a45a6-2c78-4d4d-9c91-faf0cbd389e0
status: test
description: This rule flags AWS IAM PutUserPolicy events where the request originates from an S3 Browser user agent and the inline policy contains a default S3 bucket placeholder string "<YOUR-BUCKET-NAME>". Attackers and misconfigurations can use template-based policy creation to quickly grant access, sometimes unintentionally leaving placeholder values in the policy document. It relies on CloudTrail IAM event data, including eventSource/eventName, userAgent, and requestParameters text patterns in the policy content.
references:
  - https://permiso.io/blog/s/unmasking-guivil-new-cloud-threat-actor
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/aws/cloudtrail/aws_iam_s3browser_templated_s3_bucket_policy_creation.yml
author: daniel.bohannon@permiso.io (@danielhbohannon), Huntrule Team
date: 2023-05-17
tags:
  - attack.execution
  - attack.stealth
  - attack.t1059.009
  - attack.persistence
  - attack.initial-access
  - attack.privilege-escalation
  - attack.t1078.004
logsource:
  product: aws
  service: cloudtrail
detection:
  selection:
    eventSource: iam.amazonaws.com
    eventName: PutUserPolicy
    userAgent|contains: S3 Browser
    requestParameters|contains|all:
      - '"arn:aws:s3:::<YOUR-BUCKET-NAME>/*"'
      - '"s3:GetObject"'
      - '"Allow"'
  condition: selection
falsepositives:
  - Valid usage of S3 browser with accidental creation of default Inline IAM policy without changing default S3 bucket name placeholder value
level: high
license: DRL-1.1
related:
  - id: db014773-7375-4f4e-b83b-133337c0ffee
    type: derived

What it detects

This rule flags AWS IAM PutUserPolicy events where the request originates from an S3 Browser user agent and the inline policy contains a default S3 bucket placeholder string "<YOUR-BUCKET-NAME>". Attackers and misconfigurations can use template-based policy creation to quickly grant access, sometimes unintentionally leaving placeholder values in the policy document. It relies on CloudTrail IAM event data, including eventSource/eventName, userAgent, and requestParameters text patterns in the policy content.

Known false positives

  • Valid usage of S3 browser with accidental creation of default Inline IAM policy without changing default S3 bucket name placeholder value

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.