Cloud storage bucket made publicly readable
A-106200:00time on this alert, target 10 minutes
Back to queueAlert details
- Source
- Cloud Audit Log
- Detection rule
- CLOUD-STORAGE-PUBLIC-001
- Affected user
- a.brennan
- Affected host
- SRV-ERP-02
- Source IP
- —
- First seen
- 2026-07-24T16:52:00Z
Why this fired, in plain English
A storage location was changed so that anyone on the internet can read what is inside it.
Suggested playbook
Data exfiltration to external storage
- 1. Determine whether the destination account is corporate or personal.
- 2. Compare volume against the host's own baseline, not an absolute number.
- 3. Identify the process: a backup agent and a browser upload mean very different things.
- 4. Check the classification and how many files were involved.
Raw log evidence
Exactly what the tools recorded — 3 events.
Guided hint: this line matters
ts=2026-07-24T16:51:02Z src="cloud_audit" event=PutBucketAcl actor="a.brennan@northwind-mfg.example" bucket="northwind-erp-exports" acl="public-read" src_ip=71.12.88.104 mfa=satisfied
public-read means no login is needed to download the contents.
Guided hint: this line matters
ts=2026-07-24T16:51:30Z src="cloud_audit" event=ListObjects bucket="northwind-erp-exports" object_count=812 sample="2026-Q2-customer-pricing.csv"
The bucket holds customer pricing exports — commercially sensitive data.
Guided hint: this line matters
ts=2026-07-24T16:52:00Z src="itsm" event=change_lookup resource="northwind-erp-exports" window_match=none result="no approved change"
Related events
The order things happened in.
16:51Z
Bucket ACL set to public-read
16:52Z
812 sensitive objects now exposed
Enrichment lookups
Mock lookups. Run each one yourself — a real analyst never guesses what a lookup would have said. There is no "run everything" button on purpose.
Not checked yet.
Not checked yet.
Not checked yet.
techniques
Your verdict
Keyboard shortcuts 1–4, or click. You can always change your mind afterwards.