heroui logo

Potential Third-Party Cloud Storage Client Execution

Elastic Detection Rules

View Source
Summary
Detects execution of third-party S3/object-storage clients (rclone, s5cmd, s3cmd, MinIO mc, Cyberduck, s3fs, goofys, juicefs, aws-shell) started under a scripted context on endpoints. The rule fires when a process start involves a cloud-storage client whose parent process is a script interpreter or shell command, or when the client runs from a temporary or user-writable path. After cloud credentials are obtained, adversaries may switch from AWS CLI to these clients to enumerate, mirror, and delete bucket contents rapidly. The scripted-context gating differentiates automated post-exploitation activity from interactive developer use. The rule includes a 7-day new-terms window to suppress recurring alerts for the same client on the same host. It maps to MITRE ATT&CK techniques related to exfiltration and cloud data access, and provides triage, false-positive guidance, and remediation steps.
Categories
  • Endpoint
  • Cloud
Data Sources
  • Process
  • Script
ATT&CK Techniques
  • T1537
  • T1567
  • T1567.002
  • T1530
Created: 2026-09-14