Techniques
Sample rules
AWS S3 Bucket Versioning Disable
- source: sigma
- technicques:
- t1490
Description
Detects when S3 bucket versioning is disabled. Threat actors use this technique during AWS ransomware incidents prior to deleting S3 objects.
Detection logic
condition: selection
selection:
eventName: PutBucketVersioning
eventSource: s3.amazonaws.com
requestParameters|contains: Suspended