An identity disabled bucket logging
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
Detector Tags
Data Detection & Response, Cloud Log Tampering Analytics
ATT&CK Tactic
Defense Impairment (TA0112)
ATT&CK Technique
Disable or Modify Tools: Disable or Modify Cloud Log (T1685.002)
Severity
Informational
Description
An identity disabled bucket logging.
Attacker's Goals
Avoid detection by disabling cloud logging capabilities.
Investigative actions
Determine whether this activity was done on purpose.
Examine additional API calls made by the identity.
PreviousAn identity created or updated password for an IAM user
NextAn identity initiated a download of multiple cloud objects
Was this helpful?
