Techniques
Sample rules
AWS CloudTrail Log Suspended
- source: elastic
- technicques:
- T1562
Description
Detects Cloudtrail logging suspension via StopLogging API. Stopping CloudTrail eliminates forward audit visibility and is a classic defense evasion step before sensitive changes or data theft. Investigate immediately and determine what occurred during the logging gap.
Detection logic
event.dataset: "aws.cloudtrail"
and event.provider: "cloudtrail.amazonaws.com"
and event.action: "StopLogging"
and event.outcome: "success"