Skip to main content
Open Bucket, Open Books operation cover
BeginnerCloud

Open Bucket, Open Books

A payments vendor's S3 bucket of bank-mandate PDFs was quietly made world-readable. Anonymous outsiders listed and bulk-downloaded the data with no credentials. Work the cloud audit trail to reconstruct the exposure and the theft.

25m
4 tasks
25 points
Free

Start this operation

Investigation Tasks

Complete each task by investigating alerts and submitting your findings.

1

Find what was exposed

10

Internal bank-mandate documents were downloaded by people who never authenticated. Identify the storage container they came out of.

SOC{bucket-name}Hint available
2

Trace the first outsider

15

Pinpoint the external address that first listed the bucket without credentials.

SOC{a.b.c.d}Hint available
3

Attribute the account

15

Identify the AWS account that owned the exposed bucket.

SOC{############}Hint available
4

Classify the root cause

10

Map the exposure to its MITRE ATT&CK technique for cloud-stored data.

SOC{Txxxx}Hint available

4 tasks · 50 points total

Training Tools

Cloud Console

Cloud infrastructure logs

Skills You'll Build

Investigate realistic security alerts
Cloud log analysis
MITRE ATT&CK® technique identification
Triage decisions: escalate, investigate, or close
Evidence collection and documentation
Job-ready incident response methodology
Beginner

Ideal for newcomers to SOC operations. Guided investigation with clear indicators.

Prerequisites

  • No prior experience required
  • Familiarity with Cloud concepts

Ready to investigate?

More Operations

View all