AWS CloudTrail: CreateRoute Adds New Network Route to a Route Table

Flags CloudTrail EC2 CreateRoute events indicating a new route was added to an AWS route table.

FreeReviewedSigma · Medium · v5
Product
aws
Service
cloudtrail
Author
jamesc-grafana (SigmaHQ), DRL 1.1
Published
2024-07-11
Updated
2026-07-31

ATT&CK techniques

  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule alerts when an EC2 CreateRoute API call is made, indicating that a new network route was added to a route table. Attackers can abuse routing changes to redirect traffic, enable access to otherwise unreachable networks, or impair network visibility. The detection relies on AWS CloudTrail event fields for eventSource ec2.amazonaws.com and eventName CreateRoute.

Related detections4 linkedT1686.001 — drag to rearrange
AWS CloudTrail: CreateNetworkAclEntry Adds Network ACL Rules
Azure Network Firewall Policy Modified or Deleted via Activity Logs
Azure Firewall Rule Collection Modified or Deleted via Activity Logs
Azure Firewall Created, Modified, or Deleted via Activity Log
AWS CloudTrail: CreateRoute Adds New Network Route to a Route Table
Pivot detection · T1686.001 · 4 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.