CopyObject
CopyObject
Event
Copies an existing object, requiring source read and destination write authorization plus applicable KMS permissions. A single CopyObject supports up to 5 GB; larger copies use multipart copy. Destination encryption follows the requested settings or destination defaults; missing encryption headers do not prove an unencrypted copy. Even an HTTP 200 response can contain a copy error.
Security Context
Unauthorized copying may collect data (T1530) or transfer it to another cloud account (T1537). Routine migration and organization use the same API. Bucket names, Region changes, or omitted encryption fields do not establish evasion or ownership.
Log Source
CloudTrail data event with eventSource: s3.amazonaws.com and eventName: CopyObject. Object data events require configured collection, such as an appropriately selected trail or event data store. They are not included in Event history or default management-event collection. Check errors and resulting resource state; a null response does not by itself indicate failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.bucketName, key | Destination bucket and key. |
requestParameters.x-amz-copy-source | Source bucket/key and optional version; preserve encoding before decoding. |
resources | Source/destination resource and account context where present. |
eventTime, awsRegion, recipientAccountId, eventID | Timeline, service Region, account, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Verify source and destination ownership, object sensitivity, versions, and authorization.
- Confirm the copy outcome using complete API/task evidence and the resulting destination object; inspect destination encryption rather than assuming it was removed.
- Correlate GetObject or subsequent copies and approved migration activity. Establish actual external access before claiming exfiltration.
Sample Event
Synthetic scenario. Draco requests a copy into a bucket shown with a different account ID. The record does not prove the source contains PII, that the copy completed, or that destination encryption was removed.
Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:38:54Z", "eventSource": "s3.amazonaws.com", "eventName": "CopyObject", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "[aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6]", "requestParameters": { "bucketName": "draco-exfil-bucket-666", "Host": "draco-exfil-bucket-666.s3.us-west-2.amazonaws.com", "x-amz-copy-source": "fantasticlogs-niffler-archive/customers/2026-q1/customer-pii-export.parquet", "key": "stolen/customer-pii-export.parquet" }, "responseElements": null, "additionalEventData": { "SignatureVersion": "SigV4", "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "bytesTransferredIn": 0.0, "AuthenticationMethod": "AuthHeader", "x-amz-id-2": "fqzX1iZV6ImDtkFxbGvziOE6fUwryRa+PhnLckfVAkLNHdbCAHNq4l/yckUd1a2HNJPL6NAS01U=", "bytesTransferredOut": 4827193.0 }, "requestID": "90000000-0000-4000-8000-000000001001", "eventID": "90000000-0000-4000-8000-000000001010", "readOnly": false, "resources": [ { "type": "AWS::S3::Object", "ARN": "arn:aws:s3:::draco-exfil-bucket-666/stolen/customer-pii-export.parquet" }, { "accountId": "555666661337", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::draco-exfil-bucket-666" }, { "accountId": "555123456789", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::fantasticlogs-niffler-archive" }, { "type": "AWS::S3::Object", "ARN": "arn:aws:s3:::fantasticlogs-niffler-archive/customers/2026-q1/customer-pii-export.parquet" } ], "eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "555123456789", "eventCategory": "Data", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "draco-exfil-bucket-666.s3.us-west-2.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Collection Exfiltration
- T1530 — Data from Cloud Storage — Adversaries may access data from cloud storage.
- T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.