AWS CloudTrail: S3 Browser creates inline IAM policy with default bucket placeholder

Detects S3 Browser–initiated IAM PutUserPolicy requests that include a templated S3 bucket placeholder in the inline policy.

FreeReviewedSigma · High · v5
Product
aws
Service
cloudtrail
Author
daniel.bohannon@permiso.io (@danielhbohannon) (SigmaHQ), DRL 1.1
Published
2023-05-17
Updated
2026-07-31

ATT&CK techniques

Initial Access → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Cred Access

  4. Discovery

  5. Lateral Movement

  6. Collection

  7. C2

  8. Exfiltration

  9. Impact

What it detects

This rule identifies CloudTrail IAM PutUserPolicy events where the user agent contains "S3 Browser" and the request includes an inline policy referencing the default S3 bucket placeholder ARN value. Attackers can use templated or copy-pasted policies to quickly grant S3 permissions for persistence or access after gaining a foothold. The detection relies on CloudTrail IAM events, matching eventName=PutUserPolicy and specific requestParameters content indicative of the placeholder bucket and S3 GetObject allow statement.

Related detections9 linkedT1078.004 — drag to rearrange
AWS CloudTrail: S3 Browser creating IAM LoginProfiles after querying GetLoginProfile
AWS CloudTrail: S3 Browser Creates IAM User or Access Key
Suspicious Google Cloud Function Create or Update Triggering Build
Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365
Suspicious SES Account Sending Enablement and Identity Verification via CloudTrail
Possible Stolen AWS Credential Validation via STS GetCallerIdentity
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
Suspicious STS AssumeRole With Exfil Session Name via CloudTrail (via cloudtrail)
AWS CloudTrail: S3 Browser creates inline IAM policy with default bucket placeholder
Pivot detection · T1078.004 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.