October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk4 min

AWS S3 Bucket Security: Find Exposure and Sensitive Data Outside Git

A clean repository cannot show who can reach your live S3 buckets or what their objects contain. Review AWS permissions and sensitive data separately.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A clean Git repository does not prove your live Amazon S3 buckets are safe. To find exposure, review permissions in AWS—especially IAM Access Analyzer for S3 findings, bucket and access-point policies, ACLs, and identity-based policies. To find sensitive data stored in objects, use Amazon Macie. These checks answer different questions: who can reach a bucket, and what its objects contain.

What an S3 security review can—and cannot—find

Git scanners inspect repository contents. They do not establish whether a live S3 bucket is publicly accessible, whether a cross-account principal can read it, or whether sensitive data is stored in its objects. Those require separate reviews of AWS permissions and stored data.

As an Amazon Associate I earn from qualifying purchases.

A finding of sensitive data in an object does not by itself show that anyone accessed it or that it was publicly exposed. Likewise, a permissions review does not identify every sensitive object. Treat these as distinct investigations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to find publicly accessible or shared buckets

Start with IAM Access Analyzer for S3

Review S3 findings in IAM Access Analyzer and inspect both the access source and access level. Findings can identify public or cross-account access and point to grants from an ACL, bucket policy, access-point policy, or Multi-Region Access Point policy. AWS explains the review and remediation workflow in its IAM Access Analyzer for S3 guide.

#1 Best Overall

For each finding, decide whether the access is intended. Archive a finding only after verifying and documenting the business reason; an archived finding is not proof that the underlying access is safe.

Inspect every relevant policy layer

Analyzer findings are a useful starting point, not a substitute for reviewing all applicable permissions. Check:

  • Bucket ACLs and bucket policies.
  • Access-point and Multi-Region Access Point policies.
  • Identity-based policies attached to users, roles, or other principals that can reach the bucket.
  • KMS key policies and grants when objects use SSE-KMS.

Compare each principal, action, and resource with the actual use case. Remove broad wildcard grants that are not required and apply least privilege. S3 access may be governed by both identity and resource policies; AWS outlines the available approaches in its S3 access-management guide.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to reduce unintended public access

Use S3 Block Public Access deliberately

S3 Block Public Access provides four independent settings that can be applied at organization, account, and bucket scope. AWS recommends enabling all four settings at both account and bucket level, and considering organization-level enforcement when managing multiple accounts. S3 applies the most restrictive applicable settings. See AWS’s Block Public Access guidance for the settings and their behavior.

Before applying a block, verify whether an application intentionally depends on public access—for example, static website hosting or public downloads. If an exception is necessary, document the exact purpose and limit access to the intended objects and paths rather than leaving a broad grant in place.

Prefer policies over ACLs for most workloads

Object Ownership is set by default to bucket owner enforced, which disables ACLs. AWS recommends keeping ACLs disabled unless a workload needs object-level ACL control. For most modern workloads, use policies instead; choose bucket policies for one or a few similarly accessed buckets, identity policies for access managed through shared roles, and access points or S3 Access Grants when scaled or more granular sharing is needed.

Encryption protects stored data, not permissions

New S3 objects are encrypted at rest by default with SSE-S3. SSE-KMS is available when customer-managed key controls are required. Encryption does not prevent an authenticated caller with the necessary permissions from retrieving an object, so review S3 permissions and relevant KMS key policies together. AWS covers these controls in its S3 security best practices.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Protect data in transit too. Require HTTPS/TLS—for example, with a bucket-policy condition using aws:SecureTransport—and review whether the policy applies to the intended access paths.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Build a repeatable review and monitoring workflow

  1. Inventory scope: Identify the relevant AWS accounts, Regions, and buckets using your organization’s approved inventory process.
  2. Review sharing findings: Use IAM Access Analyzer for S3 to find public or cross-account access, then record whether each case is intentional.
  3. Trace the grant: Inspect the policy or ACL named in each finding, plus relevant identity policies and KMS permissions.
  4. Compare permissions with need: Narrow principals, actions, and resource scopes; remove grants that are not required.
  5. Apply public-access controls: Set Block Public Access at appropriate account or organization and bucket levels after checking application dependencies.
  6. Review ownership settings: Confirm Object Ownership and disable ACLs where object-level ACL behavior is unnecessary.
  7. Check protection in transit and at rest: Verify encryption and HTTPS requirements without treating encryption as authorization.
  8. Enable the right monitoring: Configure CloudTrail data events for the object operations you need to audit, use AWS Config for relevant configuration checks, and use Macie when sensitive-data discovery is needed.
  9. Keep an exception record: Document intentional public or cross-account access and schedule recurring reviews of findings and configuration changes.

Choose monitoring by the question you need answered

Control What it helps answer
IAM Access Analyzer for S3 Can the public or an external account reach this S3 resource, and which policy or ACL grants access?
CloudTrail data events Which logged object-level actions, such as GetObject, PutObject, or DeleteObject, occurred?
AWS Config Does a resource’s configuration match relevant rules, or has it drifted?
Amazon Macie Do S3 objects appear to contain sensitive data, based on machine learning and pattern matching?

These controls are complementary. CloudTrail data events require configuration for the object-level audit coverage you need. AWS Config managed rules cited in AWS’s S3 security guidance support general purpose buckets, not directory buckets. S3 Block Public Access also does not replace review of identity policies or related resources such as KMS keys. In rare policy cases, a service finding and S3’s public-access evaluation may differ; investigate unsupported policy actions instead of assuming either view is infallible.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.