heroui logo

AWS GuardDuty Detector Deletion

Elastic Detection Rules

View Source
Summary
The AWS GuardDuty Detector Deletion rule identifies instances where an Amazon GuardDuty detector has been deleted, which can significantly impact environmental security by halting monitoring capabilities and potentially allowing malicious actions to go undetected. This rule triggers when a detection event is logged that indicates the deletion of a GuardDuty detector. The rule utilizes data from AWS CloudTrail logs, specifically monitoring for deletion events initiated by users or roles. It has a defined interval and query structure that captures successful deletion actions within the specified timeframe.
Categories
  • Cloud
  • AWS
Data Sources
  • Cloud Storage
  • Network Traffic
  • Application Log
ATT&CK Techniques
  • T1562
  • T1562.001
Created: 2020-05-28