Skip to content

Latest commit

 

History

History
34 lines (27 loc) · 1.17 KB

MATCH-S00764.md

File metadata and controls

34 lines (27 loc) · 1.17 KB

Rules: AWS CloudTrail - S3 Bucket Public Access Block Disabled

Description

Detects when GetPublicAccessBlock returns NoSuchPublicAccessBlockConfiguration, indicating the public access block has all values are set to false or the feature is disabled.

Additional Details

Detail Value
Type Templated Match
Category Collection
Apply Risk to Entities srcDevice_ip, device_ip, user_username
Signal Name AWS CloudTrail - An S3 Bucket Public Access Block is Disabled
Summary Expression An S3 Bucket Public Access Block is Disabled. {{action}} command run by User: {{user_username}} with IP: {{srcDevice_ip}} User: {{user_username}}
Score/Severity Static: 2
Enabled by Default True
Prototype False
Tags _mitreAttackTactic:TA0009, _mitreAttackTechnique:T1530

Vendors and Products

Fields Used

Origin Field
Normalized Schema action
Normalized Schema device_ip
Direct from Record fields['errorCode']
Normalized Schema metadata_product
Normalized Schema metadata_vendor
Normalized Schema srcDevice_ip
Normalized Schema user_username