Techniques
Sample rules
AWS CloudTrail Log Updated
- source: elastic
- technicques:
- T1530
- T1565
Description
Identifies an update to an AWS log trail setting that specifies the delivery of log files.
Detection logic
event.dataset:aws.cloudtrail and event.provider:cloudtrail.amazonaws.com and event.action:UpdateTrail and event.outcome:success