For the complete documentation index, see llms.txt. This page is also available as Markdown.

Suspicious activity on logging bucket

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

AWS Audit Log

Detection Modules

Cloud

Detector Tags

Cloud Log Tampering Analytics

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify Tools (T1685), Disable or Modify Tools: Disable or Modify Cloud Log (T1685.002)

Severity

Informational

Description

An identity performed a suspicious activity on bucket used to store logs.

Attacker's Goals

Evade detection by tampering the logs.

Investigative actions

  • Verify whether the identity attempted to access the bucket.

  • Verify no logs were modified in the bucket.

Variations

Suspicious deletion on CloudTrail logging bucket

Synopsis

Field
Value

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify Tools (T1685), Disable or Modify Tools: Disable or Modify Cloud Log (T1685.002)

Severity

Medium

Description

An identity performed a suspicious activity on bucket used to store CloudTrail logs.

Attacker's Goals

Evade detection by tampering the logs.

Investigative actions

  • Verify whether the identity attempted to access the bucket.

  • Verify no logs were modified in the bucket.

Suspicious deletion on S3 access logs bucket

Synopsis

Field
Value

ATT&CK Tactic

Defense Impairment (TA0112)

ATT&CK Technique

Disable or Modify Tools (T1685), Disable or Modify Tools: Disable or Modify Cloud Log (T1685.002)

Severity

Medium

Description

An identity performed a suspicious activity on an S3 bucket used to store access logs.

Attacker's Goals

Evade detection by tampering the logs.

Investigative actions

  • Verify whether the identity attempted to access the bucket.

  • Verify no logs were modified in the bucket.

Was this helpful?