Skip to content

PutBucketPolicy

AWS

PutBucketPolicy

service: AWS - S3
techniques:

Event

Replaces the complete policy, so inspect removed statements as well as additions. Cross-account delegation to an account principal does not automatically authorize every identity in that account; caller-side authorization, explicit denies, object ownership, Block Public Access, and KMS controls can matter. A specified external account is not equivalent to anonymous public access.

Security Context

Unauthorized external grants can prepare transfer to another account (contextual T1537). Normal integrations use the same API. A policy change alone does not prove object reads or bypass every IAM control.

Log Source

CloudTrail management event with eventSource: s3.amazonaws.com and eventName: PutBucketPolicy. Check errors and resulting resource state; a null response does not by itself indicate failure.

Key Fields

FieldInvestigation value
requestParameters.bucketName, bucketPolicyTarget and complete submitted policy; encoding/field names vary.
resourcesOwner account context for the target bucket.
eventTime, awsRegion, recipientAccountId, eventIDTimeline, service Region, account, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Compare old/new principals, actions, resources, conditions, and denies.
  3. Verify external-account ownership, caller-side authorization, and encryption/ownership constraints. Do not equate a root account ARN with all principals being automatically allowed.
  4. Correlate GetObject and CopyObject from the newly authorized identities before claiming data transfer.

Sample Event

Synthetic scenario. Draco submits a policy naming an external account. The sample does not show that account’s IAM policies or any successful object access.

Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T21:42:08Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T23:39:21Z",
"eventSource": "s3.amazonaws.com",
"eventName": "PutBucketPolicy",
"awsRegion": "us-west-2",
"sourceIPAddress": "203.0.113.66",
"userAgent": "[aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6]",
"requestParameters": {
"bucketName": "fantasticlogs-niffler-archive",
"Host": "fantasticlogs-niffler-archive.s3.us-west-2.amazonaws.com",
"policy": [
""
],
"bucketPolicy": {
"Version": "2012-10-17",
"Statement": [
{
"Sid": "AllowExternalReadAccess",
"Effect": "Allow",
"Principal": {
"AWS": "arn:aws:iam::555666661337:root"
},
"Action": [
"s3:GetObject",
"s3:ListBucket"
],
"Resource": [
"arn:aws:s3:::fantasticlogs-niffler-archive",
"arn:aws:s3:::fantasticlogs-niffler-archive/*"
]
}
]
}
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000101100100",
"eventID": "90000000-0000-4000-8000-000101100101",
"readOnly": false,
"resources": [
{
"accountId": "555123456789",
"type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::fantasticlogs-niffler-archive"
}
],
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "fantasticlogs-niffler-archive.s3.us-west-2.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Exfiltration

Techniques:
  • T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.