Amazon Simple Storage Service

Version: AWS LogForwarder v1.0.10 and above.

Amazon Simple Storage Service (Amazon S3) is an object storage service that offers scalability, data availability, security, and performance. It provides management features to optimize, organize, and configure access to data and meet specific business, organizational, and compliance requirements.

Netsurion’s Open XDR platform seamlessly combines SIEM, Log Management, File Integrity Monitoring, machine analytics, and user behaviour monitoring. The dashboard, category, alerts, and reports in Netsurion’s Open XDR platform benefit in tracking critical activities, security warning activities, and others.

After configuring Amazon S3 to forward the logs to Netsurion’s Open XDR platform via syslog, configure the alerts, dashboards, and reports to the Netsurion Open XDR platform.

For a pre-integrated AWS instance, update the ETS AWS LogForwarder version to v1.0.10 or above.
The following are the key Data Source Integrations available in the Netsurion Open XDR platform.

Alerts

TypeNameDescription
SecurityAmazon S3 – Bucket encryption disabledThis alert is triggered when an attempt is made to disable the server-side encryption on the S3
bucket.
SecurityAmazon S3 – Inventory configuration changes detectedThis alert is triggered when an attempt is made to edit or delete the S3 inventory configuration.
SecurityAmazon S3 – Bucket ownership settings changedThis alert is triggered when an attempt is made to edit or delete the S3 bucket ownership settings.
SecurityAmazon S3 – Public access block settings changedThis alert is triggered when an attempt is made to edit or delete the S3 bucket public access settings.
SecurityAmazon S3 – Bucket replication detectedThis alert is triggered when an attempt is made to change the bucket replication settings for S3.
SecurityAmazon S3 – Access points modifiedThis alert is triggered when an attempt is made to modify the access point settings for the S3 bucket.
SecurityAmazon S3 – Unauthorized bucket configuration accessThis alert is triggered when multiple API calls are detected to access the details of the S3 bucket, which failed due to one or more errors.
SecurityAmazon S3 – New lifecycle policy addedThis alert is triggered when a new life cycle policy is added for the S3 bucket which has a limited object expiration period and may supersede existing policies.
SecurityAmazon S3 – Bucket policy changedThis alert is triggered based on the request of a privileged user of the activities related to modifications in the S3 bucket policy are detected.

Reports

TypeNameDescription
SecurityAmazon S3 – Unauthorized user activitiesThis report gives details of the specific actions carried out related to the S3 service, which failed due to one or more errors related to access management or data misconfiguration.
SecurityAmazon S3 – Activity overviewThis report gives the details of all the actions carried out related to S3 service. It provides details like the action name, the activity initiated time, the individual who performed it, and other information related to
the application and the user.
SecurityAmazon S3 – Bucket level activityThis report gives the details of all the actions carried out in the S3 service. It gives information about the action name, the time it was initiated, the individual who performed it, including other details related to the application and the user.

Dashboards

TypeNameDescription
SecurityAmazon S3 – Critical activitiesThis dashlet provides information about any critical or sensitive actions carried out related to the S3 service.
SecurityAmazon S3 – Configuration changes by IPThis dashlet provides the details of the WRITE actions related to S3 bucket configuration mapped to the IP addresses of the users.
SecurityAmazon S3 – Failed API callsThis dashlet provides the details of any failed API calls mapped to the user ARN, occurred due to the insufficient or unauthorized access.

Documentation

The configuration details are consistent with the Netsurion Open XDR platform version 9.3 and later, and ETS AWS LogForwarder.

Download How-to Guide and Integration Guide and for configuration instructions and more information.