heroui logo

AWS Audit or Security Service Tampering via CLI

Elastic Detection Rules

View Source
Summary
Identifies when the AWS CLI is used on an endpoint to disable, delete, or blind AWS audit logging and security monitoring services. The rule detects process-start events for commands invoked from aws, aws-cli, aws.exe, or aws2 that aim to modify or disable logging and monitoring components across AWS services (e.g., CloudTrail trails and data stores, GuardDuty detectors, AWS Config recorders, Security Hub, Access Analyzer, Macie, Inspector2, and related logs). Examples include cloudtrail delete-trail, cloudtrail stop-logging, cloudtrail put-event-selectors with restrictive flags, configservice delete-configuration-recorder, detective delete-graph, guardduty delete-detector or update-detector with --no-enable, inspector2 disable, logs delete-log-group/stream, macie2 disable-macie, s3api put-bucket-logging, securityhub batch-disable-standards, and securityhub disable-security-hub. The rule also flags put-retention-policy operations that set retention to 1 day, a common tactic to reduce log retention. Importantly, it fires at the endpoint on process start before the API call reaches AWS, so it can alert even if CloudTrail visibility is later suppressed. The rule maps to MITRE ATT&CK—Defense Evasion (T1562.008 Disable or Modify Cloud Logs; T1562.001 Disable or Modify Tools) and Indicator Removal (T1070)—and is aligned with cloud- and endpoint-focused threat activity. It is implemented as part of Elastic Defend on supported endpoints and relies on endpoint data ingestion (process events and command lines) to identify these manipulation attempts. False positives may occur from legitimate administrative or automated compliance actions; correlate with change management windows and operator identity. Remediation guidance emphasizes re-enabling disabled services, revoking compromised credentials, and auditing for unrecorded activity during the affected window, plus applying controls to prevent future disablement of logging and security services.
Categories
  • Endpoint
  • Cloud
  • AWS
Data Sources
  • Process
  • Command
ATT&CK Techniques
  • T1562
  • T1562.008
  • T1562.001
  • T1070
Created: 2026-09-14