AWSCloudTrail - Tampering to AWS CloudTrail logs

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Detects successful attempts to disable, delete, or weaken AWS logging telemetry, including CloudTrail, CloudWatch/EventBridge, and VPC flow logs. This behavior can indicate defense evasion and deliberate reduction of incident visibility by an attacker.

Attribute Value
Type Analytic Rule
Solution Amazon Web Services
ID 633a91df-d031-4b6e-a413-607a61540559
Severity High
Status Available
Kind Scheduled
Tactics DefenseEvasion
Techniques T1562.008
Required Connectors AWS
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
AWSCloudTrail EventName in "DeleteEventBus,DeleteFlowLogs,DeleteLogGroup,DeleteTrail,StopLogging,UpdateTrail"

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Analytic Rules · Back to Amazon Web Services