S3 Bucket outbound Data transfer anomaly

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Identifies S3 data transfer spikes using GetObject API, BytesTransferredOut, and KQL anomaly detection. Investigate sudden action frequency increases. Adjust scorethreshold to 3+ to reduce noise.

Attribute Value
Type Hunting Query
Solution Business Email Compromise - Financial Fraud
ID 0ef8dee1-eb94-44c8-b59b-2eb096a4b983
Tactics Exfiltration
Techniques T1020
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
AwsBucketAPILogs_CL ? ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Business Email Compromise - Financial Fraud