heroui logo

AWS S3 Delete Object Detection

Panther Rules

View Source
Summary
The AWS S3 Delete Object Detection rule is designed to monitor and detect mass deletion of objects within Amazon S3 buckets. It acts as a security watch against potential unauthorized access or malicious activities that could lead to significant data loss. This rule evaluates CloudTrail logs for instances in which the DeleteObject action is executed, specifically looking for thresholds that indicate multiple objects have been deleted (greater than the defined threshold of 50 deletions). If triggered, it signals potentially harmful activity that warrants investigation to confirm whether the deletions were authorized. Users are advised to take immediate action to identify the executing user and verify the legitimacy of the deletions while tracking for any other suspicious behaviors in the account.
Categories
  • Cloud
  • AWS
  • Infrastructure
Data Sources
  • Cloud Storage
  • Logon Session
Created: 2025-03-19