MITRE ATT&CK Technique
T1619Cloud Storage Object Discovery
- First Reported
- Apr 29, 2025
- Latest Reported
- Apr 29, 2025
Official Description
Adversaries may enumerate objects in cloud storage infrastructure. Adversaries may use this information during automated discovery to shape follow-on behaviors, including requesting all or specific objects from cloud storage. Similar to [File and Directory Discovery](https://attack.mitre.org/techniques/T1083) on a local host, after identifying available storage services (i.e. [Cloud Infrastructure Discovery](https://attack.mitre.org/techniques/T1580)) adversaries may access the contents/objects stored in cloud infrastructure.
Cloud service providers offer APIs allowing users to enumerate objects stored within cloud storage. Examples include ListObjectsV2 in AWS (Citation: ListObjectsV2) and List Blobs in Azure(Citation: List Blobs) .
Cloud service providers offer APIs allowing users to enumerate objects stored within cloud storage. Examples include ListObjectsV2 in AWS (Citation: ListObjectsV2) and List Blobs in Azure(Citation: List Blobs) .
- Tactics
- Discovery
- Platforms
- IaaS
- MITRE Version
- 1.0
- Last Modified
- May 12, 2026
Reported Context (1)
- The described Glue job searches S3 buckets for service assets, including newly created CloudFormation templates that it can modify. Overly Broad AWS Default Roles Could Enable Cross-Service Privilege Escalation
MITRE ATT&CK (3)
Vendors (2)
Products (10)
Tools (1)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.