Cloud Storage Object Discovery

Threat actors may enumerate objects in cloud storage infrastructure. Threat actors may use this information during automated discovery to shape follow-on behaviors, including requesting all or specific objects from cloud storage. Similar to File and Directory Discovery on a local host, after identifying available storage services (i.e. Cloud Infrastructure Discovery) Threat actors may access the contents/objects stored in cloud infrastructure.

ID: ATAGS-T1132
Sub-techniques:  No sub-techniques
Tactic: Discovery
Targeted Components: Cloud Control Plane
Responsibility: Provider
Created: 18 April 2026
Last Modified: 18 April 2026

Mitigations

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.