detect-s3-cross-account-copy
Installation
SKILL.md
detect-s3-cross-account-copy
Streaming detector for AWS S3 object copies into a different AWS account. This is the first honest shipped AWS exfiltration-to-cloud-account slice under the ATT&CK roadmap, and it stays intentionally narrow.
Use when
- You stream CloudTrail through
ingest-cloudtrail-ocsfand want near-real-time findings on suspicious cross-account S3 copies - You want a deterministic, read-only AWS exfiltration detector aligned to ATT&CK
T1537 - You need a narrow follow-on slice after the shipped AWS discovery and IAM-user persistence detectors
Do NOT use
- As a generic S3 object-write detector for same-account operations
- To infer every exfiltration path; this slice only covers successful cross-account
CopyObject - To claim all cross-account storage movement is covered; multipart, replication, and non-S3 destinations remain separate follow-on work