Data exfiltration to AWS S3 via s5cmd cp/sync command execution
Detects the execution of the s5cmd utility using 'cp' or 'sync' commands directed towards S3 storage paths. This behavior is indicative of unauthorized data exfiltration to attacker-controlled cloud storage, a tactic identified in intrusions associated with the 'Ransom Busters' group.
YARA-L

