Techniques
Sample rules
AWS S3 Data Management Tampering
- source: sigma
- technicques:
- t1537
Description
Detects when a user tampers with S3 data management in Amazon Web Services.
Detection logic
condition: selection
selection:
eventName:
- PutBucketLogging
- PutBucketWebsite
- PutEncryptionConfiguration
- PutLifecycleConfiguration
- PutReplicationConfiguration
- ReplicateObject
- RestoreObject
eventSource: s3.amazonaws.com