1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1619 Cloud Storage Object Discovery — Detection Rules

Detection workspace for T1619 Cloud Storage Object Discovery: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0578 Detection Strategy for Cloud Storage Object Discovery

AN1594 Analytic 1594

Detection of suspicious enumeration of cloud storage objects via API calls such as AWS S3 ListObjectsV2, Azure List Blobs, or GCP ListObjects. Correlate access with account role, user context, and prior authentication activity to identify anomalous usage patterns (e.g., unusual account, unexpected regions, or large-scale enumeration in short time windows).

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1619 simulation workspace

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.