Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Data Components DC0025 — Cloud Storage Access
DC0025

Cloud Storage Access

13 analytic(s) · 11 detection strategy(ies)

Description

Cloud storage access refers to the retrieval or interaction with data stored in cloud infrastructure. This data component includes activities such as reading, downloading, or accessing files and objects within cloud storage systems. Common examples include API calls like GetObject in AWS S3, which retrieves objects from cloud buckets. Examples: - AWS S3 Access: An adversary uses the `GetObject` API to retrieve sensitive data from an AWS S3 bucket. - Azure Blob Storage Access: A user accesses a blob in Azure Storage using `Get Blob` or `Get Blob Properties`. - Google Cloud Storage Access: An adversary uses `storage.objects.get` to download objects from - OpenStack Swift Storage Access: A user retrieves an object from OpenStack Swift using the `GET` method.

Referenced in Analytics

13
AN0043 Analytic 0043 DET0014

Detects virtual disk expansion or file copy operations to cloud buckets or mounted volumes from isolated instances.

AWS:CloudTrail gcp:audit
AN0198 Analytic 0198 DET0071

Detects remote write activity across cloud VMs or object storage buckets within the same region/account that correlate with data aggregation across hosts.

AWS:CloudTrail AWS:VPCFlowLogs esxi:hostd
AN0370 Analytic 0370 DET0131

Detects access to cloud APIs or CLI tools to move or sync files from sensitive buckets to external endpoints using protocols like HTTPS or S3 APIs.

AWS:CloudTrail AWS:VPCFlowLogs
AN0666 Analytic 0666 DET0238

Adversary uses compromised instance credentials or web application access to deface content hosted in S3 buckets, Azure Blob Storage, or GCP Buckets.

CloudTrail:PutObject AWS:CloudTrail
AN0679 Analytic 0679 DET0242

Database enumeration and export activity (e.g., `SELECT * FROM`, `SHOW DATABASES`) issued via ephemeral VMs, admin APIs, or cloud shell from non-monitoring accounts. Defender correlates audit logs (CloudTrail, GCP Admin, AzureDiagnostics), storage write ops, and cross-region transfers by identities not tied to DB operations.

AWS:CloudTrail AWS:CloudTrail AWS:VPCFlowLogs
AN1160 Analytic 1160 DET0413

Programmatic or excessive access to file shares, SharePoint, or database repositories by users not typically interacting with them. This includes abnormal access by privileged accounts, enumeration of large numbers of files, or downloads of sensitive content in bursts.

WinEventLog:Security m365:unified
AN1328 Analytic 1328 DET0484

Spike in object access from new IAM user or role followed by data exfiltration to external IPs

AWS:CloudTrail AWS:CloudTrail AWS:VPCFlowLogs
AN1329 Analytic 1329 DET0484

OAuth token granted to external app followed by download of high-volume files in OneDrive/Google Drive

m365:unified
AN1330 Analytic 1330 DET0484

Internal user account accesses shared links outside org followed by mass file download

m365:sharepoint azure:signinlogs
AN1426 Analytic 1426 DET0515

Use of OAuth tokens by third-party apps to access user mail, calendar, or SharePoint resources where the token was granted recently or via spearphishing.

m365:unified
AN1473 Analytic 1473 DET0533

Detects anomalous CI/CD workflow execution originating from forked repositories, with pull request (PR) metadata or commit messages containing suspicious patterns (e.g., encoded payloads), coupled with the use of insecure pipeline triggers like `pull_request_target` or excessive API usage of CI/CD secrets. Correlation with unusual artifact generation or secret exfiltration via encoded or external network destination URLs confirms suspicious behavior.

saas:github saas:github saas:github saas:RepoEvents saas:PRMetadata
AN1594 Analytic 1594 DET0578

Detection of suspicious enumeration of cloud storage objects via API calls such as AWS S3 ListObjectsV2, Azure List Blobs, or GCP ListObjects. Correlate access with account role, user context, and prior authentication activity to identify anomalous usage patterns (e.g., unusual account, unexpected regions, or large-scale enumeration in short time windows).

AWS:CloudTrail AWS:CloudTrail
AN1625 Analytic 1625 DET0590

Adversary modifies content in cloud-hosted websites (e.g., AWS S3-backed, Azure Blob-hosted sites) by gaining access to management consoles or APIs and uploading altered HTML/JS files.

AWS:CloudTrail AWS:CloudTrail AWS:CloudTrail

Details

MITRE ID
DC0025
STIX ID
x-mitre-data-component--58ef998c-f3bf-4985-b487-b1005f5c05d1
Analytics
13
Detection Strategies
11
Leaving Threaticon

This link opens an external site that isn't part of the platform.