Umbra Wiki technique technique/T1619
Back to wiki

T1619 — Cloud Storage Object Discovery

provenance: imported · ATT&CK: T1619

T1619: Cloud Storage Object Discovery

MITRE ATT&CK® Enterprise technique

Tactics Discovery
Platforms IaaS
Permissions required
Version 1.0

Description

Adversaries may enumerate objects in cloud storage infrastructure. Adversaries may use this information during automated discovery to shape follow-on behaviors, including requesting all or specific objects from cloud storage. Similar to File and Directory Discovery on a local host, after identifying available storage services (i.e. Cloud Infrastructure Discovery) adversaries may access the contents/objects stored in cloud infrastructure.

Cloud service providers offer APIs allowing users to enumerate objects stored within cloud storage. Examples include ListObjectsV2 in AWS (Citation: ListObjectsV2) and List Blobs in Azure(Citation: List Blobs) .

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1619
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/