AWS CloudTrail: GuardDuty Detector Deleted or Disabled via DeleteDetector/UpdateDetector

Identifies successful GuardDuty detector deletion or disablement from CloudTrail, reducing GuardDuty monitoring coverage.

FreeUnreviewedSigmahighv1
title: "AWS CloudTrail: GuardDuty Detector Deleted or Disabled via DeleteDetector/UpdateDetector"
id: dda70786-7f8c-4143-bc96-4888e4a4bde4
status: experimental
description: This rule flags successful GuardDuty detector removal and disablement by matching CloudTrail events from guardduty.amazonaws.com. It detects DeleteDetector, or UpdateDetector requests where the enable parameter is set to false, and the event indicates Success. Attackers may use these actions to reduce detection coverage and potentially discard existing GuardDuty findings. The detection relies on CloudTrail eventName, eventSource, requestParameters.enable, and errorCode values to determine successful detector changes.
references:
  - https://docs.aws.amazon.com/guardduty/latest/APIReference/API_DeleteDetector.html
  - https://docs.aws.amazon.com/guardduty/latest/APIReference/API_UpdateDetector.html
  - https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_suspend-disable.html
  - https://docs.datadoghq.com/security/default_rules/719-39f-9cd/
  - https://docs.prismacloud.io/en/enterprise-edition/policy-reference/aws-policies/aws-general-policies/ensure-aws-guardduty-detector-is-enabled
  - https://docs.stellarcyber.ai/5.2.x/Using/ML/Alert-Rule-Based-Potentially_Malicious_AWS_Activity.html
  - https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Amazon%20Web%20Services/Analytic%20Rules/AWS_GuardDutyDisabled.yaml
  - https://github.com/elastic/detection-rules/blob/main/rules/integrations/aws/defense_evasion_guardduty_detector_deletion.toml
  - https://help.fortinet.com/fsiem/Public_Resource_Access/7_4_0/rules/PH_RULE_AWS_GuardDuty_Detector_Deletion.htm
  - https://research.splunk.com/sources/5d8bd475-c8bc-4447-b27f-efa508728b90/
  - https://suktech24.com/2025/07/17/aws-threat-detection-rule-guardduty-detector-disabled-or-suspended/
  - https://www.atomicredteam.io/atomic-red-team/atomics/T156001#atomic-test-46---aws---guardduty-suspension-or-deletion
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/aws/cloudtrail/aws_cloudtrail_guardduty_detector_deleted_or_updated.yml
author: suktech24, Huntrule Team
date: 2025-11-27
tags:
  - attack.defense-impairment
  - attack.t1685
  - attack.t1685.002
logsource:
  product: aws
  service: cloudtrail
detection:
  selection_event_source:
    eventSource: guardduty.amazonaws.com
  selection_action_delete:
    eventName: DeleteDetector
  selection_action_update:
    eventName: UpdateDetector
    requestParameters.enable: "false"
  selection_status_success:
    errorCode: Success
  selection_status_null:
    errorCode: null
  condition: selection_event_source and 1 of selection_action_* and 1 of selection_status_*
falsepositives:
  - Legitimate detector deletion by an admin (e.g., during account decommissioning).
  - Temporary disablement for troubleshooting (verify via change management tickets).
  - Automated deployment tools (e.g. Terraform) managing GuardDuty state.
level: high
license: DRL-1.1
related:
  - id: d2656e78-c069-4571-8220-9e0ab5913f19
    type: derived

What it detects

This rule flags successful GuardDuty detector removal and disablement by matching CloudTrail events from guardduty.amazonaws.com. It detects DeleteDetector, or UpdateDetector requests where the enable parameter is set to false, and the event indicates Success. Attackers may use these actions to reduce detection coverage and potentially discard existing GuardDuty findings. The detection relies on CloudTrail eventName, eventSource, requestParameters.enable, and errorCode values to determine successful detector changes.

Known false positives

  • Legitimate detector deletion by an admin (e.g., during account decommissioning).
  • Temporary disablement for troubleshooting (verify via change management tickets).
  • Automated deployment tools (e.g. Terraform) managing GuardDuty state.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.