2026 Critical Cloud Control Plane Detection: Storage Bucket Policy Modified to Allow Anonymous or Wildcard Principal Access

Detects 'PutBucketPolicy' API calls in AWS CloudTrail where the policy is modified to grant 'Allow' access to a wildcard ('*') or anonymous principal, without including restrictive conditional requirements such as VPC endpoints or organizational ID constraints. This behavior is a common precursor to data exfiltration from misconfigured S3 buckets.