elastic
medium
kql
AWS S3 Credential File Retrieved from Bucket
Detects successful S3 GetObject calls targeting high-value credential and secret files commonly
stored in S3 buckets: AWS credentials files (".aws/credentials", ".aws/config"), SSH private keys
("id_rsa", "id_ed25519", "id_ecdsa", "id_dsa"), environment files (".env"), PEM and PuTTY key files,
and other private key patterns. These file types are high-yield targets for credential harvesting
from S3. The rule excludes AWSService identity type to suppress S3 replication, Glacier restore,
and other