AWS S3 Public Access Block Removed
Dash が新機能を発表!インシデントマネジメント、Continuous Profiler など多数の機能が追加されました! Dash イベントで発表された新機能!
<  Back to rules search

AWS S3 Public Access Block Removed

cloudtrail

Classification:

compliance

Set up the cloudtrail integration.

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。

Overview

Goal

Detect when the S3 Public Access Block configuration has been removed

Strategy

This rule lets you monitor this CloudTrail API call to detect if an attacker is deleting the S3 Public Access Block configuration:

Triage & Response

  1. Determine who the user was who made this API call.
  2. Contact the user and inform them of best practices of enabling Public Access Block on S3 buckets.
  3. Re-enable Public Access Block on the S3 bucket.

More details on S3 Public Block Public Access can be found here.