LoFP LoFP / aws administrator legitimately disabling bucket versioning

Techniques

Sample rules

AWS S3 Bucket Versioning Disable

Description

Detects when S3 bucket versioning is disabled. Threat actors use this technique during AWS ransomware incidents prior to deleting S3 objects.

Detection logic

condition: selection
selection:
  eventName: PutBucketVersioning
  eventSource: s3.amazonaws.com
  requestParameters|contains: Suspended