Defense Evasion (TA0005)(external, opens in a new tab or window)
text code block:event.category : "process" and event.type : "start" and event.action:(start or exec) and process.name : (aws or aws-cli or aws.exe or aws2) and ( process.command_line : ( *accessanalyzer delete-analyzer* or *cloudtrail delete-event-data-store* or *cloudtrail delete-trail* or *cloudtrail put-event-selectors*IncludeManagementEvents*false* or *cloudtrail put-event-selectors*ReadWriteType*ReadOnly* or *cloudtrail stop-logging* or *cloudtrail update-trail*--no-include-global-service-events* or *cloudtrail update-trail*--no-is-multi-region-trail* or *configservice delete-configuration-recorder* or *configservice delete-delivery-channel* or *configservice stop-configuration-recorder* or *detective delete-graph* or *guardduty create-filter*ARCHIVE* or *guardduty delete-detector* or *guardduty delete-publishing-destination* or *guardduty update-detector*--no-enable* or *inspector2 disable* or *logs delete-log-group* or *logs delete-log-stream* or *macie2 disable-macie* or *s3api put-bucket-logging*--bucket-logging-status*\{\}* or *securityhub batch-disable-standards* or *securityhub disable-security-hub* ) or process.args : ("put-retention-policy" and ("--retention-in-days=1" or "1")) ) and not process.args : "help"
Install detection rules in Elastic Security
Detect AWS Audit or Security Service Tampering via CLI in the Elastic Security detection engine by installing this rule into your Elastic Stack.
To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).