Techniques
Sample rules
AWS Audit or Security Service Tampering via CLI
- source: elastic
- technicques:
- T1070
- T1562
Description
Identifies use of the AWS CLI to disable, delete, or blind AWS audit logging and security monitoring services, including CloudTrail trails and event data stores, GuardDuty detectors, AWS Config recorders, Security Hub, Access Analyzer, Macie, and Inspector. Adversaries disable these controls early in a cloud intrusion so that subsequent credential abuse, data theft, and destruction go unrecorded. Because the endpoint sees the command as it is issued, this fires even when subsequent CloudTrail visibility is lost.
Detection logic
event.category : "process" and event.type : "start" and event.action:(start or exec) and
process.name : (aws or aws-cli or aws.exe or aws2) and
(
process.command_line : (
*accessanalyzer delete-analyzer* or
*cloudtrail delete-event-data-store* or
*cloudtrail delete-trail* or
*cloudtrail put-event-selectors*IncludeManagementEvents*false* or
*cloudtrail put-event-selectors*ReadWriteType*ReadOnly* or
*cloudtrail stop-logging* or
*cloudtrail update-trail*--no-include-global-service-events* or
*cloudtrail update-trail*--no-is-multi-region-trail* or
*configservice delete-configuration-recorder* or
*configservice delete-delivery-channel* or
*configservice stop-configuration-recorder* or
*detective delete-graph* or
*guardduty create-filter*ARCHIVE* or
*guardduty delete-detector* or
*guardduty delete-publishing-destination* or
*guardduty update-detector*--no-enable* or
*inspector2 disable* or
*logs delete-log-group* or
*logs delete-log-stream* or
*macie2 disable-macie* or
*s3api put-bucket-logging*--bucket-logging-status*\{\}* or
*securityhub batch-disable-standards* or
*securityhub disable-security-hub*
) or
process.args : ("put-retention-policy" and ("--retention-in-days=1" or "1"))
) and
not process.args : "help"