Panther high experimental python

AWS S3 Object Exfiltration WITH Object Deletion

Detects a ransomware attack pattern where an attacker with compromised AWS credentials exfiltrates data from an S3 bucket to an external AWS account, followed by bulk deletion of objects from the source bucket within a short timeframe. This technique was notably used by the threat actor Bling Libra to extort victims by threatening data destruction or leaks.

View Source

Detection Logic

[object Object]

Field Validations

Loading…

Comments (0)

Loading comments...