For the complete documentation index, see llms.txt. This page is also available as Markdown.

AWS config resource deletion

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

AWS Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify Tools (T1685)

Severity

Informational

Description

An AWS config resource deletion this includes: Config rule, organization rule, configuration recorder, remediation configuration, conformance pack, configuration aggregator, delivery channel, retention configuration.

Attacker's Goals

An attacker may modify Config configuration to evade detection.

Investigative actions

  • Check why the identity deleted the configuration.

  • Check what resources are relevant to the deleted config.

Was this helpful?