Detecting S3 Data Exfiltration Attempts

Detecting data exfiltration attempts from AWS S3 buckets by analyzing CloudTrail S3 data events, VPC Flow Logs, GuardDuty findings, Amazon Macie alerts, and S3 access patterns to identify unauthorized bulk downloads and cross-account data transfers.

26zl Updated

File contents

26zl/cybersec-toolkit/tree/main/.claude/skills/detecting-s3-data-exfiltration-attempts commit 7871d9a5e6

Frequently asked questions

npx skillmds@latest add 26zl/detecting-s3-data-exfiltration-attempts