PutBucketReplication
PutBucketReplication
Event
Replaces replication rules and the replication role. Source and destination require versioning and appropriate role/bucket permissions. Live replication generally covers eligible new writes after configuration; existing objects require a separate batch-replication path. Filters, supported object states, ownership, and KMS configuration constrain replication, and enabling a rule does not guarantee completion.
Security Context
Unauthorized cross-account replication can support T1537. Backup and regional resilience are legitimate uses. Do not claim every object is mirrored or that the source has no observable replication activity.
Log Source
CloudTrail management event with eventSource: s3.amazonaws.com and eventName: PutBucketReplication. Check errors and resulting resource state; a null response does not by itself indicate failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.ReplicationConfiguration.Role | Replication role and trust/permission dependencies. |
requestParameters.ReplicationConfiguration.Rule | Filters, destination account/bucket, encryption selection, ownership, and delete-marker behavior. |
eventTime, awsRegion, recipientAccountId, eventID | Timeline, service Region, account, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Compare full previous/new configuration and confirm destination ownership, versioning, and replication-role authorization.
- Assess matching object scope, KMS opt-in/permissions, and existing-object handling. The sample’s disabled DeleteMarkerReplication does not copy delete markers.
- Check replication status/metrics and destination objects; correlate CopyObject only where evidence links the workflows.
Sample Event
Synthetic scenario. Draco enables an all-prefix rule to an external-account bucket. Prerequisites and actual replicated objects are absent, so continuous successful copying is not established.
Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T21:42:08Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T23:48:07Z", "eventSource": "s3.amazonaws.com", "eventName": "PutBucketReplication", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "[aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6]", "requestParameters": { "bucketName": "fantasticlogs-occamy-ingest", "Host": "fantasticlogs-occamy-ingest.s3.amazonaws.com", "replication": [ "" ], "ReplicationConfiguration": { "xmlns": "http://s3.amazonaws.com/doc/2006-03-01/", "Role": "arn:aws:iam::555123456789:role/draco-replication-role", "Rule": [ { "ID": "exfil-to-666", "Status": "Enabled", "Priority": 1, "Filter": { "Prefix": "" }, "DeleteMarkerReplication": { "Status": "Disabled" }, "Destination": { "Bucket": "arn:aws:s3:::draco-exfil-bucket-666", "Account": "555666661337", "AccessControlTranslation": { "Owner": "Destination" } } } ] } }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000101101000", "eventID": "90000000-0000-4000-8000-000101101001", "readOnly": false, "resources": [ { "accountId": "555123456789", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::fantasticlogs-occamy-ingest" } ], "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "fantasticlogs-occamy-ingest.s3.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Exfiltration
- T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.