Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0041 — Detection of Lifecycle Policy Modifications for Triggered Deletion in IaaS Cloud Storage
DET0041

Detection of Lifecycle Policy Modifications for Triggered Deletion in IaaS Cloud Storage

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN0117 Analytic 0117
IaaS

Adversary with write access to storage modifies lifecycle policies (e.g., via PutBucketLifecycle) to schedule rapid object deletion across one or more storage buckets. This is often used to trigger impact (destruction), remove logs (defense evasion), or force extortion (ransomware).

AWS:CloudTrail PutBucketLifecycle, PutLifecycleConfiguration, SetBucketLifecycle, storage.buckets.update
[LifecycleExpirationDays] Policy values setting Expiration in fewer than N days (e.g., 0–1) are highly suspicious.
[TargetBucket] Filter by bucket types (e.g., log storage, production DB snapshots) to prioritize detection.
[Principal] Correlate rare or anomalous IAM principals making destructive lifecycle changes.
[TimeWindow] Link lifecycle policy change with API activity suggesting staged deletion or extortion attempt.

Detected Techniques

1

Details

MITRE ID
DET0041
STIX ID
x-mitre-detection-strategy--cfdf2a13-7059-4532-9d1c-f9129b0e3f7b
Analytics
1
Techniques Detected
1
By Tactic
Impact
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.