PutBucketAcl
PutBucketAcl
Event
Sets the bucket ACL. Bucket READ permission allows listing bucket objects; it does not give GetObject access to every object. Object ACLs and bucket policies are separate. Bucket owner enforced Object Ownership disables ACLs and causes ACL-setting requests to fail. Block Public Access can reject or ignore public ACL permissions.
Security Context
Unauthorized ACL changes may prepare collection (contextual T1530). Approved legacy access management also uses this API. A public-read bucket ACL is not proof that all object contents became public or were transferred to another account.
Log Source
CloudTrail management event with eventSource: s3.amazonaws.com and eventName: PutBucketAcl. Check errors and resulting resource state; a null response does not by itself indicate failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.bucketName | Target bucket and Object Ownership mode. |
requestParameters.x-amz-acl, acl | Canned or explicit grants; exact CloudTrail representation varies. |
eventTime, awsRegion, recipientAccountId, eventID | Timeline, service Region, account, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Recover the previous ACL and determine which permissions were added or removed.
- Check Object Ownership, effective Block Public Access, object ACLs, and bucket policy before assessing effective access.
- Correlate actual listing or GetObject activity. Do not treat bucket listing permission as object read permission.
Sample Event
Synthetic scenario. Draco requests public-read for the bucket. Even if accepted and effective, this does not by itself make every object readable.
Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T21:42:08Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T23:18:42Z", "eventSource": "s3.amazonaws.com", "eventName": "PutBucketAcl", "awsRegion": "us-west-2", "sourceIPAddress": "203.0.113.66", "userAgent": "[aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6]", "requestParameters": { "bucketName": "fantasticlogs-niffler-archive", "Host": "fantasticlogs-niffler-archive.s3.us-west-2.amazonaws.com", "x-amz-acl": [ "public-read" ], "acl": [ "" ] }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000101011110", "eventID": "90000000-0000-4000-8000-000101011111", "readOnly": false, "resources": [ { "accountId": "555123456789", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::fantasticlogs-niffler-archive" } ], "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "fantasticlogs-niffler-archive.s3.us-west-2.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Collection
- T1530 — Data from Cloud Storage — Adversaries may access data from cloud storage.