Back to results

AWS Audit or Security Service Tampering via CLI

Identifies use of the AWS CLI to disable, delete, or blind AWS audit logging and security monitoring services, including CloudTrail trails and event data stores, GuardDuty detectors, AWS Config recorders, Security…

Description

Identifies use of the AWS CLI to disable, delete, or blind AWS audit logging and security monitoring services, including CloudTrail trails and event data stores, GuardDuty detectors, AWS Config recorders, Security Hub, Access Analyzer, Macie, and Inspector. Adversaries disable these controls early in a cloud intrusion so that subsequent credential abuse, data theft, and destruction go unrecorded. Because the endpoint sees the command as it is issued, this fires even when subsequent CloudTrail visibility is lost.

Detection logic

Its licence does not clear it for publishing here

Sunturai publishes a detection's own text where the licence it arrived under has been reviewed and permits it, and Elastic License 2.0 has not. The query as its source wrote it, its canonical form and the hash that pins this revision are in the workspace record.

Detection requirements

Platform
ContainersESXiIaaSIdentity ProviderLinuxmacOSNetwork DevicesOffice SuiteSaaSWindows

The rule states no platform. This is derived from the 2 ATT&CK techniques it maps to.

Log source category
event_index

Known benign triggers

  • Security teams running authorized cloud posture assessments or infrastructure cleanup may legitimately issue these commands. Correlate with change management windows and operator identity before escalating.

Detections can measure how the public catalogue is used — which detections people look for, and which pages bring them here. It sets a cookie that recognises this browser for 180 days. It is never linked to an account and never follows you to other sites. Privacy notice