GetObject
GetObject
Event
Reads an object subject to S3 authorization, applicable KMS permissions, and storage-class retrieval requirements. A range request may retrieve only part of an object. CloudTrail records request metadata rather than object contents.
Security Context
Unauthorized reads can collect cloud data (T1530). The call alone does not identify a destination cloud account, so T1537 is not assigned here. Routine downloads and workload reads are common. An AWS Region field identifies service context, not the caller’s physical location.
Log Source
CloudTrail data event with eventSource: s3.amazonaws.com and eventName: GetObject. Object data events require configured collection, such as an appropriately selected trail or event data store. They are not included in Event history or default management-event collection. Check errors and resulting resource state; a null response does not by itself indicate failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.bucketName, key, versionId | Object and optional version. |
userIdentity, sourceIPAddress | Caller/session evidence; do not invent a preceding federation exchange. |
additionalEventData | Transfer metrics if present; the sample alone does not establish bytes received. |
eventTime, awsRegion, recipientAccountId, eventID | Timeline, service Region, account, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Confirm outcome, selected version/range, and whether archived data was available.
- Compare caller and access volume to expected workloads and classify actual object contents using approved metadata.
- Correlate client activity and CopyObject where relevant; distinguish read access from proven downstream transfer.
Sample Event
Synthetic scenario. Draco requests an archive object. The sample does not establish caller geography, a preceding GetFederationToken exchange, or a complete file download.
Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "FederatedUser", "principalId": "555123456789:draco-fed", "arn": "arn:aws:sts::555123456789:federated-user/draco-fed", "accountId": "555123456789", "accessKeyId": "ASIADRAC0FED0SESS00666", "sessionContext": { "sessionIssuer": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "userName": "draco" }, "attributes": { "creationDate": "2026-04-15T21:21:38Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:28:54Z", "eventSource": "s3.amazonaws.com", "eventName": "GetObject", "awsRegion": "us-west-2", "sourceIPAddress": "203.0.113.66", "userAgent": "[aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6]", "requestParameters": { "bucketName": "fantasticlogs-niffler-archive", "Host": "fantasticlogs-niffler-archive.s3.us-west-2.amazonaws.com", "key": "pii/2026-04/customer-pii-export.parquet" }, "responseElements": null, "additionalEventData": { "SignatureVersion": "SigV4", "CipherSuite": "TLS_AES_128_GCM_SHA256", "bytesTransferredIn": 0, "AuthenticationMethod": "AuthHeader", "x-amz-id-2": "EXAMPLEEXAMPLEEXAMPLEEXAMPLE/EXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLEEXAMPLE", "bytesTransferredOut": 1834521088 }, "requestID": "90000000-0000-4000-8000-000100111110", "eventID": "90000000-0000-4000-8000-000100111111", "readOnly": true, "resources": [ { "type": "AWS::S3::Object", "ARN": "arn:aws:s3:::fantasticlogs-niffler-archive/pii/2026-04/customer-pii-export.parquet" }, { "accountId": "555123456789", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::fantasticlogs-niffler-archive" } ], "eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "555123456789", "eventCategory": "Data", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "fantasticlogs-niffler-archive.s3.us-west-2.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Collection
- T1530 — Data from Cloud Storage — Adversaries may access data from cloud storage.