S3 Bucket Security & Public Access Audit Prompt
Audit an S3 bucket's security posture end to end: public access blocks, bucket policy, ACLs, encryption, versioning, logging, and TLS enforcement, and rank exposure risks.
- Target user
- Cloud security engineers and AWS administrators
- Difficulty
- Intermediate
- Tools
- Claude, ChatGPT
The prompt
You are a senior AWS security engineer auditing an S3 bucket for accidental exposure and misconfiguration. I will provide: - The account/bucket Block Public Access settings (account-level and bucket-level) - Output of `aws s3api get-bucket-policy` and `get-bucket-acl` - Encryption config (`get-bucket-encryption`), versioning, and access-logging status - Whether Object Ownership is BucketOwnerEnforced (ACLs disabled) or not - The bucket's purpose (static assets, backups, sensitive data, log sink) and who/what should access it Your job: 1. **Assess public exposure** — evaluate Block Public Access at both levels, plus any policy/ACL grant to `*`, AllUsers, or AuthenticatedUsers, and state the real-world reachability. 2. **Review the policy** — check for overly broad Principals, missing `aws:SecureTransport` (TLS) deny, and conditions (SourceVpce, SourceIp, PrincipalOrgID) that should scope access. 3. **Encryption** — confirm default encryption (SSE-S3 vs SSE-KMS), whether a `aws:kms` deny-unencrypted-uploads policy exists, and key-policy alignment. 4. **Data durability/forensics** — check versioning, MFA delete (where used), and server access / CloudTrail data-event logging. 5. **ACL hygiene** — recommend disabling ACLs via BucketOwnerEnforced unless a specific cross-account ACL need exists. 6. **Rank risk** — order findings Critical/High/Medium with the concrete exposure each one creates. Output: (a) a risk-ranked finding table, (b) the exact policy/config remediation (JSON or CLI), (c) least-privilege access recommendations, (d) a short "verify it's now private" checklist. Audit and advise only: produce remediation steps and policy JSON, but do not apply changes or delete objects; the operator confirms intent before acting.
Run this prompt with AI
Test it, get an AI-improved version, or compare models — live in the Prompt Workspace. No copy-paste.
Related prompts
-
S3 Bucket Policy Condition Hardening Review Prompt
Review S3 bucket and access-point policies for over-broad principals, missing TLS/encryption conditions, and confused-deputy exposure
-
AWS S3 Lifecycle and Storage Class Optimization Prompt
Design S3 storage-class transitions, lifecycle rules, and Intelligent-Tiering so you cut storage cost without breaking retrieval SLAs, retention requirements, or paying more in transition and request fees than you save.
-
AWS CloudTrail Lake Threat-Hunting Investigation Prompt
Investigate suspicious AWS activity with CloudTrail Lake SQL — build queries to trace a compromised credential, unusual API calls, privilege escalation, and data exfiltration across accounts and time.
-
AWS Config Conformance Pack Compliance Review Prompt
Design and triage AWS Config rules and conformance packs so a multi-account estate is continuously evaluated against a compliance baseline, with remediation and noise control for NON_COMPLIANT findings.
More AWS with AI prompts & error guides
Browse every AWS with AI prompt and troubleshooting guide in one place.
Reading prompts? Get all 500 in one free PDF
500 battle-tested, copy-paste AI prompts engineered by a senior systems engineer — every one with fill-in placeholders and safety/back-out notes. Drop your email and it's yours.
- 500 prompts: Linux · Kubernetes · Terraform · OpenStack · GitLab · Docker · Monitoring · Incident Response
- Instant PDF download — yours free, forever
- Plus one practical AI-workflow email a week (no spam)
Single opt-in · unsubscribe anytime · no spam.