Techniques
Sample rules
AWS S3 Data Management Tampering
- source: sigma
- technicques:- t1537
 
Description
Detects when a user tampers with S3 data management in Amazon Web Services.
Detection logic
condition: selection
selection:
  eventName:
  - PutBucketLogging
  - PutBucketWebsite
  - PutEncryptionConfiguration
  - PutLifecycleConfiguration
  - PutReplicationConfiguration
  - ReplicateObject
  - RestoreObject
  eventSource: s3.amazonaws.com
