1200KM / simulation
T1619 Cloud Storage Object Discovery — Attack Simulation
Adversaries may enumerate objects in cloud storage infrastructure. Adversaries may use this information during automated discovery to shape follow-on behaviors, including requesting all or specific objects from cloud storage. Similar to File and Directory Discovery on a local host, after identifying available storage services (i.e. Cloud Infrastructure Discovery) adversaries may access the contents/objects stored in cloud infrastructure. Cloud…
Technique description
Adversaries may enumerate objects in cloud storage infrastructure. Adversaries may use this information during automated discovery to shape follow-on behaviors, including requesting all or specific objects from cloud storage. Similar to File and Directory Discovery on a local host, after identifying available storage services (i.e. Cloud Infrastructure Discovery) adversaries may access the contents/objects stored in cloud infrastructure. Cloud…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Azure - Enumerate Storage Account Objects via Shared Key authorization using Azure CLI
Procedure 070322a4-2c60-4c50-8ffb-c450a34fe7bf; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Azure - Scan for Anonymous Access to Azure Storage (Powershell)
Procedure 146af1f1-b74e-4aa7-9895-505eb559b4b0; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- AWS S3 Enumeration
Procedure 3c7094f8-71ec-4917-aeb8-a633d7ec4ef5; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Azure - Enumerate Azure Blobs with MicroBurst
Procedure 3dab4bcc-667f-4459-aea7-4162dd2d6590; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.