PutBucketPolicy
PutBucketPolicy
Event
Replaces the complete policy, so inspect removed statements as well as additions. Cross-account delegation to an account principal does not automatically authorize every identity in that account; caller-side authorization, explicit denies, object ownership, Block Public Access, and KMS controls can matter. A specified external account is not equivalent to anonymous public access.
Security Context
Unauthorized external grants can prepare transfer to another account (contextual T1537). Normal integrations use the same API. A policy change alone does not prove object reads or bypass every IAM control.
Log Source
CloudTrail management event with eventSource: s3.amazonaws.com and eventName: PutBucketPolicy. Check errors and resulting resource state; a null response does not by itself indicate failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.bucketName, bucketPolicy | Target and complete submitted policy; encoding/field names vary. |
resources | Owner account context for the target bucket. |
eventTime, awsRegion, recipientAccountId, eventID | Timeline, service Region, account, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Compare old/new principals, actions, resources, conditions, and denies.
- Verify external-account ownership, caller-side authorization, and encryption/ownership constraints. Do not equate a root account ARN with all principals being automatically allowed.
- Correlate GetObject and CopyObject from the newly authorized identities before claiming data transfer.
Sample Event
Synthetic scenario. Draco submits a policy naming an external account. The sample does not show that account’s IAM policies or any successful object access.
Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T21:42:08Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T23:39:21Z", "eventSource": "s3.amazonaws.com", "eventName": "PutBucketPolicy", "awsRegion": "us-west-2", "sourceIPAddress": "203.0.113.66", "userAgent": "[aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6]", "requestParameters": { "bucketName": "fantasticlogs-niffler-archive", "Host": "fantasticlogs-niffler-archive.s3.us-west-2.amazonaws.com", "policy": [ "" ], "bucketPolicy": { "Version": "2012-10-17", "Statement": [ { "Sid": "AllowExternalReadAccess", "Effect": "Allow", "Principal": { "AWS": "arn:aws:iam::555666661337:root" }, "Action": [ "s3:GetObject", "s3:ListBucket" ], "Resource": [ "arn:aws:s3:::fantasticlogs-niffler-archive", "arn:aws:s3:::fantasticlogs-niffler-archive/*" ] } ] } }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000101100100", "eventID": "90000000-0000-4000-8000-000101100101", "readOnly": false, "resources": [ { "accountId": "555123456789", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::fantasticlogs-niffler-archive" } ], "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "fantasticlogs-niffler-archive.s3.us-west-2.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Exfiltration
- T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.