AWS CloudTrail: Potential S3 Bucket Enumeration via ListBuckets by Non-AssumedRole

Identifies S3 ListBuckets calls in CloudTrail that are not from assumed-role identities, which may indicate bucket discovery activity.

FreeReviewedSigma · Low · v5
Product
aws
Service
cloudtrail
Author
Christopher Peacock @securepeacock, SCYTHE @scythe_io (SigmaHQ), DRL 1.1
Published
2023-01-06
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule flags CloudTrail events where an AWS principal calls S3 ListBuckets, indicating possible attempts to enumerate buckets. Attackers may use this information to identify accessible bucket names and further target specific storage resources. It relies on CloudTrail telemetry for eventSource s3.amazonaws.com and eventName ListBuckets, and excludes activity originating from AssumedRole identities.

Related detections3 linkedT1580 — drag to rearrange
Suspicious SES Account Sending Enablement and Identity Verification via CloudTrail
Suspicious AWS SAML Provider Enumeration for Federation Recon (via cloudtrail)
Suspicious Boto3 Kali Linux User Agent in AWS CloudTrail Reconnaissance (via cloudtrail)
AWS CloudTrail: Potential S3 Bucket Enumeration via ListBuckets by Non-AssumedRole
Pivot detection · T1580 · 3 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.