You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Rules: AWS CloudTrail - S3 Bucket Public Access Block Disabled
Description
Detects when GetPublicAccessBlock returns NoSuchPublicAccessBlockConfiguration, indicating the public access block has all values are set to false or the feature is disabled.
Additional Details
Detail
Value
Type
Templated Match
Category
Collection
Apply Risk to Entities
srcDevice_ip, device_ip, user_username
Signal Name
AWS CloudTrail - An S3 Bucket Public Access Block is Disabled
Summary Expression
An S3 Bucket Public Access Block is Disabled. {{action}} command run by User: {{user_username}} with IP: {{srcDevice_ip}} User: {{user_username}}