| name | detecting-s3-data-exfiltration-attempts |
| description | Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers. . Use when working with detecting s3 data exfiltration attempts. |
| domain | cybersecurity |
| tags | ["cloud-security","aws","s3","data-exfiltration","guardduty","macie","threat-detection"] |
| subdomain | cloud-security |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.IR-01","ID.AM-08","GV.SC-06","DE.CM-01"] |
Detecting S3 Data Exfiltration Attempts
Overview
Cybersecurity skill for detecting s3 data exfiltration attempts. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"detecting s3 data exfiltration attempts"
-
"Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail"
-
When GuardDuty detects anomalous S3 access patterns such as bulk downloads from unusual IPs
-
When investigating suspected data breach involving S3-stored sensitive data
-
When building detection rules for S3 data loss prevention monitoring
-
When responding to Macie alerts about sensitive data being accessed or moved
-
When compliance requires monitoring and logging of all access to classified data stores
Do not use for preventing data exfiltration (use S3 bucket policies, VPC endpoints, and SCPs), for data classification (use Amazon Macie discovery jobs), or for network-level exfiltration detection (use VPC Flow Logs with network analysis tools).
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- CloudTrail configured with S3 data event logging (
GetObject, PutObject, CopyObject)
- GuardDuty enabled with S3 Protection feature activated
- Amazon Macie enabled for sensitive data discovery in target buckets
- CloudWatch Logs or Athena for querying CloudTrail logs at scale
- VPC endpoint policies configured for S3 access monitoring
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs() -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}