Cloud Storage Object Discovery

T1619

Technique.View on attack.mitre.org

About this technique

Adversaries may enumerate objects in cloud storage infrastructure. Adversaries may use this information during automated discovery to shape follow-on behaviors, including requesting all or specific objects from cloud storage. Similar to File and Directory Discovery on a local host, after identifying available storage services (i.e. Cloud Infrastructure Discovery) adversaries may access the contents/objects stored in cloud infrastructure.

Cloud service providers offer APIs allowing users to enumerate objects stored within cloud storage. Examples include ListObjectsV2 in AWS and List Blobs in Azure .

Detection rules1

Rules on DetectionCode tagged with T1619.

Sigma1

RuleLevelLog source
Potential Bucket Enumeration on AWSlowaws / NULL

Splunk0

No Splunk rules are mapped to this technique yet.

Groups1

Software3

Campaigns0

None recorded.

Procedure examples4

Groups1

Used byProcedure example
GroupShinyHunters

ShinyHunters has used Amazon Simple Storage Service (S3) Browser and WinSCP to access S3 objects.

Software3

Used byProcedure example
ToolPacu

Pacu can enumerate AWS storage services, such as S3 buckets and Elastic Block Store volumes.

ToolPeirates

Peirates can list AWS S3 buckets.

ToolTruffleHog

TruffleHog can enumerate cloud storage environments including Amazon Web Service (AWS) S3 buckets and Google Cloud Storage buckets.

References2

  1. List Blobs Open source
    Microsoft - List Blobs. (n.d.). Retrieved October 4, 2021.
  2. ListObjectsV2 Open source
    Amazon - ListObjectsV2. Retrieved October 4, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.