Skip to content
← LibraryTechnique entry
C-S3-EXFILCollection

S3 / Blob / GCS Mass Exfil

ListObjects + GetObject loop across discovered buckets — straight data theft.

§ Where this technique fits

C-S3-EXFIL is catalogued under the Collection tactic of the offensive-security kill-chain. It appears in 4 approved dossiers in the registry, typically at step 4.3 on average.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Cloud SSRF → IMDS → Bucket Exfil (Capital One 2019)
    APT-CAPITAL-ONE-SSRF · Initial Access
    seen 1×
  2. 02
    Dev-Workstation Backup Exfil (LastPass 2022)
    APT-LASTPASS-DEV · Initial Access
    seen 1×
  3. 03
    Hardcoded Secrets in JS Bundles
    W-RECON-JS-SECRETS · Reconnaissance
    seen 1×