For the complete documentation index, see llms.txt. This page is also available as Markdown.

Disable AWS audit logs through Event Selectors

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

AWS Audit Log

Detection Modules

Cloud

Detector Tags

Cloud Log Tampering Analytics

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify Tools: Disable or Modify Cloud Log (T1685.002)

Severity

Informational

Description

An AWS Cloudtrail Event Selector was modified. An attacker might use this technique to disable audit logs.

Attacker's Goals

Evade detection by filtering out audit logs.

Investigative actions

  • Review the new event selector policy.

  • Check The cloud identity activity prior/after to the event selectors policy modification.

Was this helpful?