Tool

github.com/ramimac/aws-customer-security-incidents

https://github.com/ramimac/aws-customer-security-incidents
Published on
github.com

ATT&CK techniques those detections carry

  • T1059Command and Scripting Interpreter
  • T1059.006Python
  • T1069Permission Groups Discovery
  • T1069.003Cloud Groups
  • T1530Data from Cloud Storage
  • T1537Transfer Data to Cloud Account
  • T1567Exfiltration Over Web Service
  • T1567.002Exfiltration to Cloud Storage
  • +1 more
Open the original

2 published detections cite this

Citing it, not covering it: each of these was written with this as evidence, and carries the source it came from and the licence it was published under.

Detections citing this reference
DetectionSeverity
Potential Third-Party Cloud Storage Client ExecutionMedium
Cloud Offensive Framework ExecutionMedium

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice