elastic
medium
kql
Suspicious AWS S3 Connection via Script Interpreter
Detects when a script interpreter (osascript, Node.js, Python) with minimal arguments makes an outbound
connection to AWS S3 or CloudFront domains. Threat actors have used S3 buckets for both command and control
and data exfiltration. Script interpreters connecting to cloud storage should be investigated for potential
malicious activity.