FORENSIA

ATT&CK · T1619

Cloud Storage Object Discovery

Tactics: discovery

About

Adversaries may enumerate objects in cloud storage infrastructure. Adversaries may use this information during automated discovery to shape follow-on behaviors, including requesting all or specific objects from cloud storage. Similar to File and Directory Discovery on a local host, after identifying available storage services (i.e. Cloud Infrastructure Discovery) adversaries may access the contents/objects stored in cloud infrastructure. Cloud service providers offer APIs allowing users to enumerate objects stored within cloud storage. Examples include ListObjectsV2 in AWS and List Blobs in Azure .

Platforms: IaaSMITRE ATT&CK ↗

Used by actors

0 known groups

No mapped actors.

Software

3 malware/tools implement this

PeiratesPacuTruffleHog

Corpus indicators tagged with this technique

0 indicators in the corpus carry T1619.

No corpus indicators are tagged with this technique yet.