Panther medium experimental python
S3 Bucket Encryption Deleted
Detects when S3 bucket encryption configuration is deleted, which could expose data to unauthorized access or indicate ransomware preparation activity.
Detection Logic
from panther_aws_helpers import aws_cloudtrail_success, aws_rule_context
def rule(event):
return (
aws_cloudtrail_success(event)
and event.get("eventSource") == "s3.amazonaws.com"
and event.get("eventName") == "DeleteBucketEncryption"
)
def title(event):
return (
f"[AWS.CloudTrail] User [{event.udm('actor_user')}] "
f"deleted bucket encryption for bucket "
f"[{event.deep_get('requestParameters', 'bucketName')}] bucket"
)
def alert_context(event):
return aws_rule_context(event) Field Validations
Loading…
Comments (0)
Loading comments...