Logging was impaired via external encryption key
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: AWS Audit Log OR Gcp Audit Log
Detection Modules
Cloud
Detector Tags
Cloud Log Tampering Analytics
ATT&CK Tactic
Impact (TA0040), Defense Impairment (TA0112)
ATT&CK Technique
Data Manipulation (T1565), Disable or Modify Tools (T1685)
Severity
Medium
Description
The resource was configured with an external key
This might be an attempt to disrupt log inspection.
Attacker's Goals
Modifying the key used to encrypt the logs to remain undetected.
Investigative actions
Check the identity that updated the resource configuration.
Check the key used to encrypt the logs.
Was this helpful?
