AWS CloudTrail Account EnableRegion Command Usage

Alerts on AWS account region enablement via CloudTrail when the EnableRegion API call occurs.

FreeReviewedSigma · Medium · v5
Product
aws
Service
cloudtrail
Author
Ivan Saakov, Sergey Zelenskiy (SigmaHQ), DRL 1.1
Published
2025-10-19
Updated
2026-07-31

What it detects

This rule flags CloudTrail events where the AWS API call EnableRegion is executed against account.amazonaws.com. Enabling additional AWS regions can expand the environment available for operations, so attackers may use this to maintain or extend access across regions. The detection relies on CloudTrail eventName and eventSource telemetry identifying the specific API action.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.