Skip to content

PutBucketPublicAccessBlock

AWS

PutBucketPublicAccessBlock

service: AWS - S3
tactics:
techniques:

Event

Sets BlockPublicAcls, IgnorePublicAcls, BlockPublicPolicy, and RestrictPublicBuckets. These controls respectively reject public ACL writes, disregard public ACL grants, reject public policies, and restrict access under public policies. Effective settings include stricter applicable account and access-point controls. Setting bucket flags false neither grants access nor overrides those controls.

Security Context

Weakening controls can prepare unauthorized collection (contextual T1530), but migration or policy management can be legitimate. A fixed external-account grant is not necessarily a public policy, so this change is not a prerequisite for every cross-account grant.

Log Source

CloudTrail management event with eventSource: s3.amazonaws.com and eventName: PutBucketPublicAccessBlock. The REST API is named PutPublicAccessBlock; this page uses the bucket-level CloudTrail event name. Check errors and resulting resource state; a null response does not by itself indicate failure.

Key Fields

FieldInvestigation value
requestParameters.bucketNameBucket scope; inspect account and access-point settings too.
requestParameters.PublicAccessBlockConfigurationWhich controls changed and their prior values.
eventTime, awsRegion, recipientAccountId, eventIDTimeline, service Region, account, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Compare all four old/new values and verify resulting effective restrictions.
  3. Inspect actual ACL/policy grants and Object Ownership; determine whether exposure changed at all.
  4. Correlate PutBucketAcl, PutBucketPolicy, and subsequent access without assuming every external grant was previously blocked.

Sample Event

Synthetic scenario. Draco sets all four bucket flags false. This does not establish public exposure, removed account-level protections, or successful access.

Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T21:42:08Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T23:15:33Z",
"eventSource": "s3.amazonaws.com",
"eventName": "PutBucketPublicAccessBlock",
"awsRegion": "us-west-2",
"sourceIPAddress": "203.0.113.66",
"userAgent": "[aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6]",
"requestParameters": {
"bucketName": "fantasticlogs-niffler-archive",
"Host": "fantasticlogs-niffler-archive.s3.us-west-2.amazonaws.com",
"publicAccessBlock": [
""
],
"PublicAccessBlockConfiguration": {
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/",
"BlockPublicAcls": false,
"IgnorePublicAcls": false,
"BlockPublicPolicy": false,
"RestrictPublicBuckets": false
}
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000101100110",
"eventID": "90000000-0000-4000-8000-000101100111",
"readOnly": false,
"resources": [
{
"accountId": "555123456789",
"type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::fantasticlogs-niffler-archive"
}
],
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "fantasticlogs-niffler-archive.s3.us-west-2.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Collection

Techniques:
  • T1530 — Data from Cloud Storage — Adversaries may access data from cloud storage.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.