AWS S3 Bucket Versioning Disable

Rule Info

Name
AWS S3 Bucket Versioning Disable
Author
Sean Johnstone | Unit 42
Description
Detects when S3 bucket versioning is disabled. Threat actors use this technique during AWS ransomware incidents prior to deleting S3 objects.
Date
2023-10-28 00:00:00
Modified
None
Id
a136ac98-b2bc-4189-a14d-f0d0388e57a7
Tags
attack.impact attack.t1490 DEMO
Type
Community Rule

Rule History

Author
Title
Date
Commit
github-actions[bot]
Merge PR #4991 from @nasbench - Promote older rules status from `experimental` to `test`
2024-09-02
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
Sean Johnstone
Merge PR #4523 from @sj-sec - Add New AWS Rule `S3 Bucket Versioning Disable`
2023-10-28