AWS CloudTrail Detects EC2 DeleteFlowLogs API Calls

Flags successful EC2 DeleteFlowLogs API calls in CloudTrail indicating VPC Flow Logs were removed.

FreeReviewedSigma · High · v5
Product
aws
Service
cloudtrail
Author
Ivan Saakov (SigmaHQ), DRL 1.1
Published
2025-10-19
Updated
2026-07-31

What it detects

This rule flags successful DeleteFlowLogs actions against VPC Flow Logs in AWS EC2 using CloudTrail event data. Deleting flow logs can remove visibility into network activity and can hinder investigations following suspicious or malicious behavior. It relies on telemetry containing the CloudTrail eventName "DeleteFlowLogs" and an errorCode indicating success or absence of an error.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.