AWS CloudTrail S3 Bucket/Replication Configuration Tampering via Management API Calls

Flags CloudTrail S3 management API actions that modify bucket protections or move/restore objects.

FreeReviewedSigma · Low · v5
Product
aws
Service
cloudtrail
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-07-24
Updated
2026-07-31

ATT&CK techniques

Exfiltration
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Impact

What it detects

This rule flags AWS CloudTrail events where an identity performs S3 data management actions that modify bucket configuration or object replication state. Attackers may use these S3 controls to weaken security settings, alter data handling, or change replication behavior to support unauthorized access or persistence. The detection relies on CloudTrail telemetry with eventSource set to s3.amazonaws.com and eventName matching the listed S3 management and replication operations.

Related detections9 linkedT1537 — drag to rearrange
Suspicious Cross-Project Compute Snapshot Creation via GCP Audit
Suspicious Compute Disk IAM Policy Modification Granting Owner Role via GCP Audit
Suspicious EBS Snapshot Shared With External Account via CloudTrail
Suspicious GCP Bucket Deletion for Namespace Hijacking (via gcp)
GitHub Audit Log: Repository or Organization Transfer Detected
GitHub Audit Logs: Private/Internal Forking Policy Enabled or Cleared
Microsoft 365 SecurityComplianceCenter: Exfiltration Activity to Unsanctioned Apps
AWS CloudTrail: EC2 Snapshot Attribute Permission Modified for Cross-Account Access
AWS CloudTrail EC2 CreateInstanceExportTask Failure
AWS CloudTrail S3 Bucket/Replication Configuration Tampering via Management API Calls
Pivot detection · T1537 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.