Investigator/Investigation #2287
#2287

Permissive execution → S3 exfiltration chain

Critical
Built by Investigator · now
Open full threat analysis →
Verdict: true positive
Status
3 hosts
Blast radius
6
Correlated events
Critical
Severity
✦ Case summary

An external actor used a leaked GitHub key and an impossible-travel login to assume MaliciousEC2Role, granted a Lambda cross-account invoke, and opened cyngular-client-1-data to a wildcard principal to stage exfiltration. Correlated into one Critical campaign; containment staged.

What happened
15:42Observer
Leaked AWS key committed to a public GitHub repo
15:51Observer
AssumeRole to MaliciousEC2Role from 2.54.178.107
16:00:22Observer
Permissive execution permissions granted to a Lambda function
16:00:41Investigator
Correlated 6 events → Incident #2287, blast radius 3 hosts
16:06Investigator
S3 bucket policy opened to a wildcard account (exfil path)
16:09Resolver
Auto-contained — role isolated, sessions revoked, IP blocked