detect-s3-cross-account-copy

Installation
SKILL.md

detect-s3-cross-account-copy

Streaming detector for AWS S3 object copies into a different AWS account. This is the first honest shipped AWS exfiltration-to-cloud-account slice under the ATT&CK roadmap, and it stays intentionally narrow.

Use when

  • You stream CloudTrail through ingest-cloudtrail-ocsf and want near-real-time findings on suspicious cross-account S3 copies
  • You want a deterministic, read-only AWS exfiltration detector aligned to ATT&CK T1537
  • You need a narrow follow-on slice after the shipped AWS discovery and IAM-user persistence detectors

Do NOT use

  • As a generic S3 object-write detector for same-account operations
  • To infer every exfiltration path; this slice only covers successful cross-account CopyObject
  • To claim all cross-account storage movement is covered; multipart, replication, and non-S3 destinations remain separate follow-on work

Rule

Installs
1
GitHub Stars
3
First Seen
Jun 21, 2026
detect-s3-cross-account-copy — msaad00/cloud-ai-security-skills