AWS Audit or Security Service Tampering via CLI
Identifies use of the AWS CLI to disable, delete, or blind AWS audit logging and security monitoring services, including CloudTrail trails and event data stores, GuardDuty detectors, AWS Config recorders, Security…
Description
Identifies use of the AWS CLI to disable, delete, or blind AWS audit logging and security monitoring services, including CloudTrail trails and event data stores, GuardDuty detectors, AWS Config recorders, Security Hub, Access Analyzer, Macie, and Inspector. Adversaries disable these controls early in a cloud intrusion so that subsequent credential abuse, data theft, and destruction go unrecorded. Because the endpoint sees the command as it is issued, this fires even when subsequent CloudTrail visibility is lost.
Detection logic
Its licence does not clear it for publishing here
Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.
Detection requirements
- Platform
- ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows
The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.
- Log source category
- event_index
Known benign triggers
- Security teams running authorized cloud posture assessments or infrastructure cleanup may legitimately issue these commands. Correlate with change management windows and operator identity before escalating.
MITRE ATT&CK mappings
0 exclusive techniques.This is coverage no other published rule has; it is not this rule's total technique count.
References
| Reference | Cited by |
|---|---|
| securitylabs.datadoghq.com/cloud-security-atlas/attacks/stopping-cloudtrail-trail/ | Only this detection cites it |
| socprime.com/active-threats/aws-guardduty-detector-disabled/ | Only this detection cites it |
| stratus-red-team.cloud/attack-techniques/AWS/aws.defense-evasion.cloudtrail-delete/ | Only this detection cites it |
| stratus-red-team.cloud/attack-techniques/AWS/aws.defense-evasion.cloudtrail-event-selectors/ | 2 |
| stratus-red-team.cloud/attack-techniques/AWS/aws.defense-evasion.cloudtrail-stop/ | Only this detection cites it |
| sysdig.com/blog/cloud-breach-terraform-data-theft/ | Only this detection cites it |
From the source
- At source
- Open at source
- Upstream identifier
- a495b1a1-69f1-423d-836b-08f13175eb49
- Tagged by the source as
- Data Source: Elastic DefendDomain: CloudDomain: EndpointOS: LinuxOS: macOSOS: WindowsPlatform: AWSPlatform: LinuxPlatform: macOSPlatform: WindowsResources: Investigation GuideRule Type: Custom Query (KQL)Service: AWS GuardDutyTactic: Defense EvasionUse Case: Threat Detection
Licence
- Published under
- Elastic License 2.0Read the licence
- Attribution
- Required
Authorship
- Written by
- Published
- Sep 29, 2026
- Version
- 1