LoFP LoFP / valid usage of s3 browser with accidental creation of default inline iam policy without changing default s3 bucket name placeholder value

Techniques

Sample rules

AWS IAM S3Browser Templated S3 Bucket Policy Creation

Description

Detects S3 browser utility creating Inline IAM policy containing default S3 bucket name placeholder value of “”.

Detection logic

condition: selection
selection:
  eventName: PutUserPolicy
  eventSource: iam.amazonaws.com
  requestParameters|contains|all:
  - '"arn:aws:s3:::<YOUR-BUCKET-NAME>/*"'
  - '"s3:GetObject"'
  - '"Allow"'
  userAgent|contains: S3 Browser