AWS Audit or Security Service Tampering via CLI

Last updated 15 days ago on 2026-09-14
Created 15 days ago on 2026-09-14

About

Identifies use of the AWS CLI to disable, delete, or blind AWS audit logging and security monitoring services, including CloudTrail trails and event data stores, GuardDuty detectors, AWS Config recorders, Security Hub, Access Analyzer, Macie, and Inspector. Adversaries disable these controls early in a cloud intrusion so that subsequent credential abuse, data theft, and destruction go unrecorded. Because the endpoint sees the command as it is issued, this fires even when subsequent CloudTrail visibility is lost.
Tags
Domain: EndpointDomain: CloudPlatform: AWSPlatform: LinuxPlatform: macOSPlatform: WindowsOS: LinuxOS: macOSOS: WindowsService: AWS GuardDutyUse Case: Threat DetectionTactic: Defense EvasionData Source: Elastic DefendRule Type: Custom Query (KQL)Language: kuery
Severity
high
Risk Score
73
MITRE ATT&CK™

Defense Evasion (TA0005)(external, opens in a new tab or window)

False Positive Examples
Security teams running authorized cloud posture assessments or infrastructure cleanup may legitimately issue these commands. Correlate with change management windows and operator identity before escalating.
License
Elastic License v2(external, opens in a new tab or window)

Definition

Rule Type
Query (Kibana Query Language)
Integration Pack
Prebuilt Security Detection Rules
Index Patterns
logs-endpoint.events.process*
Related Integrations

endpoint(external, opens in a new tab or window)

Query
text code block:
event.category : "process" and event.type : "start" and event.action:(start or exec) and process.name : (aws or aws-cli or aws.exe or aws2) and ( process.command_line : ( *accessanalyzer delete-analyzer* or *cloudtrail delete-event-data-store* or *cloudtrail delete-trail* or *cloudtrail put-event-selectors*IncludeManagementEvents*false* or *cloudtrail put-event-selectors*ReadWriteType*ReadOnly* or *cloudtrail stop-logging* or *cloudtrail update-trail*--no-include-global-service-events* or *cloudtrail update-trail*--no-is-multi-region-trail* or *configservice delete-configuration-recorder* or *configservice delete-delivery-channel* or *configservice stop-configuration-recorder* or *detective delete-graph* or *guardduty create-filter*ARCHIVE* or *guardduty delete-detector* or *guardduty delete-publishing-destination* or *guardduty update-detector*--no-enable* or *inspector2 disable* or *logs delete-log-group* or *logs delete-log-stream* or *macie2 disable-macie* or *s3api put-bucket-logging*--bucket-logging-status*\{\}* or *securityhub batch-disable-standards* or *securityhub disable-security-hub* ) or process.args : ("put-retention-policy" and ("--retention-in-days=1" or "1")) ) and not process.args : "help"

Install detection rules in Elastic Security

Detect AWS Audit or Security Service Tampering via CLI in the Elastic Security detection engine by installing this rule into your Elastic Stack.

To setup this rule, check out the installation guide for Prebuilt Security Detection Rules(external, opens in a new tab or window).