Techniques
Sample rules
AWS CloudTrail Log Updated
- source: elastic
- technicques:
- T1530
- T1565
Description
Detects updates to an existing CloudTrail trail via UpdateTrail API which may reduce visibility, change destinations, or weaken integrity (e.g., removing global events, moving the S3 destination, or disabling validation). Adversaries can modify trails to evade detection while maintaining a semblance of logging. Validate any configuration change against approved baselines.
Detection logic
event.dataset: "aws.cloudtrail"
and event.provider: "cloudtrail.amazonaws.com"
and event.action: "UpdateTrail"
and event.outcome: "success"