Skip to content

CopyObject

AWS

CopyObject

service: AWS - S3
techniques:

Event

Copies an existing object, requiring source read and destination write authorization plus applicable KMS permissions. A single CopyObject supports up to 5 GB; larger copies use multipart copy. Destination encryption follows the requested settings or destination defaults; missing encryption headers do not prove an unencrypted copy. Even an HTTP 200 response can contain a copy error.

Security Context

Unauthorized copying may collect data (T1530) or transfer it to another cloud account (T1537). Routine migration and organization use the same API. Bucket names, Region changes, or omitted encryption fields do not establish evasion or ownership.

Log Source

CloudTrail data event with eventSource: s3.amazonaws.com and eventName: CopyObject. Object data events require configured collection, such as an appropriately selected trail or event data store. They are not included in Event history or default management-event collection. Check errors and resulting resource state; a null response does not by itself indicate failure.

Key Fields

FieldInvestigation value
requestParameters.bucketName, keyDestination bucket and key.
requestParameters.x-amz-copy-sourceSource bucket/key and optional version; preserve encoding before decoding.
resourcesSource/destination resource and account context where present.
eventTime, awsRegion, recipientAccountId, eventIDTimeline, service Region, account, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Verify source and destination ownership, object sensitivity, versions, and authorization.
  3. Confirm the copy outcome using complete API/task evidence and the resulting destination object; inspect destination encryption rather than assuming it was removed.
  4. Correlate GetObject or subsequent copies and approved migration activity. Establish actual external access before claiming exfiltration.

Sample Event

Synthetic scenario. Draco requests a copy into a bucket shown with a different account ID. The record does not prove the source contains PII, that the copy completed, or that destination encryption was removed.

Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:38:54Z",
"eventSource": "s3.amazonaws.com",
"eventName": "CopyObject",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "[aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6]",
"requestParameters": {
"bucketName": "draco-exfil-bucket-666",
"Host": "draco-exfil-bucket-666.s3.us-west-2.amazonaws.com",
"x-amz-copy-source": "fantasticlogs-niffler-archive/customers/2026-q1/customer-pii-export.parquet",
"key": "stolen/customer-pii-export.parquet"
},
"responseElements": null,
"additionalEventData": {
"SignatureVersion": "SigV4",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"bytesTransferredIn": 0.0,
"AuthenticationMethod": "AuthHeader",
"x-amz-id-2": "fqzX1iZV6ImDtkFxbGvziOE6fUwryRa+PhnLckfVAkLNHdbCAHNq4l/yckUd1a2HNJPL6NAS01U=",
"bytesTransferredOut": 4827193.0
},
"requestID": "90000000-0000-4000-8000-000000001001",
"eventID": "90000000-0000-4000-8000-000000001010",
"readOnly": false,
"resources": [
{
"type": "AWS::S3::Object",
"ARN": "arn:aws:s3:::draco-exfil-bucket-666/stolen/customer-pii-export.parquet"
},
{
"accountId": "555666661337",
"type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::draco-exfil-bucket-666"
},
{
"accountId": "555123456789",
"type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::fantasticlogs-niffler-archive"
},
{
"type": "AWS::S3::Object",
"ARN": "arn:aws:s3:::fantasticlogs-niffler-archive/customers/2026-q1/customer-pii-export.parquet"
}
],
"eventType": "AwsApiCall",
"managementEvent": false,
"recipientAccountId": "555123456789",
"eventCategory": "Data",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "draco-exfil-bucket-666.s3.us-west-2.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Collection Exfiltration

Techniques:
  • T1530 — Data from Cloud Storage — Adversaries may access data from cloud storage.
  • T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.