Potential Third-Party Cloud Storage Client Execution

Last updated 15 days ago on 2026-09-14
Created 15 days ago on 2026-09-14

About

Identifies execution of a third-party S3 or object-storage client (S3 Browser, s5cmd, s3cmd, MinIO mc, rclone, Cyberduck, s3fs, goofys, juicefs) launched by a script interpreter, a shell one-liner, or from a temporary or user-writable path. After stealing cloud credentials, adversaries switch from the AWS CLI to these clients to enumerate and drain buckets in bulk. Gating on a scripted context separates post-exploitation automation from interactive developer use.
Tags
Domain: EndpointDomain: CloudPlatform: AWSPlatform: LinuxPlatform: macOSPlatform: WindowsOS: LinuxOS: macOSOS: WindowsService: AWS S3Tactic: ExfiltrationTactic: CollectionUse Case: Threat DetectionData Source: Elastic DefendRule Type: New TermsLanguage: kuery
Severity
medium
Risk Score
47
MITRE ATT&CK™

Exfiltration (TA0010)(external, opens in a new tab or window)

Collection (TA0009)(external, opens in a new tab or window)

False Positive Examples
Data engineers and DevOps teams legitimately use rclone, s5cmd, and s3cmd for bulk data transfers. This rule gates on a scripted parent to suppress interactive use, but automation pipelines that shell out to these tools may still trigger alerts. The 7-day new-terms window suppresses recurring invocations of the same client on the same host after the first alert. Allowlist known pipeline executor paths if additional tuning is needed.
License
Elastic License v2(external, opens in a new tab or window)

Definition

Rule Type
New Terms Rule
Integration Pack
Prebuilt Security Detection Rules
Index Patterns
logs-endpoint.events.process*
Related Integrations

endpoint(external, opens in a new tab or window)

Query
text code block:
event.category : "process" and event.type : "start" and process.name : ( Cyberduck or S3Browser.exe or aws-shell or cyberduck or duck or duck.exe or goofys or juicefs or mc or mc.exe or rclone or rclone.exe or s3browser-con.exe or s3browser.exe or s3cmd or s3cmd.exe or s3fs or s5cmd or s5cmd.exe or *bucketexplorer* or *cloudberry* or *s3browser* ) and not ( process.name : (mc or mc.exe) and not process.args : (admin or alias or cat or cp or du or find or get or ls or mb or mirror or mv or pipe or put or rb or rm or share or stat or tree) ) and not process.executable : (/opt/Elastic/Agent/* or /usr/lib/systemd/*) and not process.args : (--help or --version or -h or selfupdate or version) and ( process.parent.name : ( bun or bun.exe or cscript.exe or deno or deno.exe or mshta.exe or node or node.exe or nodejs or perl* or php* or python* or ruby* or wscript.exe ) or ( process.parent.name : (bash or bash.exe or cmd.exe or dash or fish or ksh or powershell.exe or pwsh or pwsh.exe or sh or zsh) and process.parent.args : ("-Command" or "-EncodedCommand" or "-enc" or "-e" or "-c" or "-ilc" or "-lc" or "/c") ) or process.executable : ( *\\Users\\*\\AppData\\Local\\Temp\\* or *\\Users\\Public\\* or *\\Windows\\Temp\\* or /Users/Shared/* or /dev/shm/* or /private/tmp/* or /tmp/* or /var/tmp/* ) or process.parent.executable : ( *\\Users\\*\\AppData\\Local\\Temp\\* or *\\Users\\Public\\* or *\\Windows\\Temp\\* or /Users/Shared/* or /dev/shm/* or /private/tmp/* or /tmp/* or /var/tmp/* ) )

Install detection rules in Elastic Security

Detect Potential Third-Party Cloud Storage Client Execution in the Elastic Security detection engine by installing this rule into your Elastic Stack.

To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).