AWS ElastiCache Cache Security Group Modified or Deleted via CloudTrail

Flags CloudTrail activity indicating an ElastiCache security group was modified or deleted.

FreeReviewedSigma · Low · v5
Product
aws
Service
cloudtrail
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-07-24
Updated
2026-07-31

ATT&CK techniques

Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule identifies ElastiCache security group changes in CloudTrail, including deletions and updates to inbound or outbound rules. Attackers can use security group modifications to weaken network access controls for ElastiCache resources. The detection relies on CloudTrail events with eventSource set to elasticache.amazonaws.com and eventName matching the specific security group action types.

Related detections9 linkedT1531 — drag to rearrange
Suspicious Account Disable via net user active no (via process_creation)
AWS IAM SAML Provider Deletion via CloudTrail
Linux userdel Execution: User Account Deletion via userdel
Linux groupdel Executed to Delete a User Group
Windows Security Logoff Events (Event ID 4634/4647)
Windows PowerShell Script: Remove Account From Domain Admin Group via Remove-ADGroupMember
Okta User Account Lockout Triggered by Max Sign-In Attempts
Google Cloud: Service Account Disabled or Deleted via IAM Audit Events
Azure Kubernetes Service Service Account Modified or Deleted Activity Log Events
AWS ElastiCache Cache Security Group Modified or Deleted via CloudTrail
Pivot detection · T1531 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.