AWS IAM SAML Provider Deletion via CloudTrail

Alerts on successful CloudTrail events where an AWS SAML provider is deleted, signaling potential disruption of admin/security access.

FreeReviewedSigma · Medium · v5
Product
aws
Service
cloudtrail
Author
Ivan Saakov (SigmaHQ), DRL 1.1
Published
2024-12-19
Updated
2026-07-31

ATT&CK techniques

Initial Access → Impact
  1. Recon

  2. Resource Dev

  3. Execution

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

What it detects

This rule identifies successful CloudTrail events where an AWS IAM SAML provider is deleted. Deleting a SAML provider can disrupt authentication for users who rely on that identity provider, affecting administrative and security access. The detection relies on CloudTrail telemetry, matching the IAM eventSource, DeleteSAMLProvider eventName, and a success status.

Related detections9 linkedT1078.004 — drag to rearrange
Suspicious Google Cloud Function Create or Update Triggering Build
Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365
Suspicious SES Account Sending Enablement and Identity Verification via CloudTrail
Possible Stolen AWS Credential Validation via STS GetCallerIdentity
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
Suspicious STS AssumeRole With Exfil Session Name via CloudTrail (via cloudtrail)
Suspicious AWS Console Login Without MFA
Suspicious Cloud Sign-In From an Anonymizer or High-Risk Session (via signinlogs)
AWS IAM SAML Provider Deletion via CloudTrail
Pivot detection · T1078.004 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.