AWS ElastiCache Cache Security Group Modified or Deleted via CloudTrail
Flags CloudTrail activity indicating an ElastiCache security group was modified or deleted.
- Product
- aws
- Service
- cloudtrail
- Author
- Austin Songer @austinsonger (SigmaHQ), DRL 1.1
- Published
- 2021-07-24
- Updated
- 2026-07-31
ATT&CK techniques
ImpactRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
What it detects
This rule identifies ElastiCache security group changes in CloudTrail, including deletions and updates to inbound or outbound rules. Attackers can use security group modifications to weaken network access controls for ElastiCache resources. The detection relies on CloudTrail events with eventSource set to elasticache.amazonaws.com and eventName matching the specific security group action types.
Reporting behind it
- github.comhttps://github.com/elastic/detection-rules/blob/7d5efd68603f42be5e125b5a6a503b2ef3ac0f4e/rules/integrations/aws/impact_elasticache_security_group_modified_or_deleted.toml
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/cloud/aws/cloudtrail/aws_elasticache_security_group_modified_or_deleted.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: AWS ElastiCache Cache Security Group Modified or Deleted via CloudTrail
id: ec9f0a7f-cca0-488d-b001-7ec835ce28b1
status: test
description: This rule identifies ElastiCache security group changes in CloudTrail, including deletions and updates to inbound or outbound rules. Attackers can use security group modifications to weaken network access controls for ElastiCache resources. The detection relies on CloudTrail events with eventSource set to elasticache.amazonaws.com and eventName matching the specific security group action types.
references:
- https://github.com/elastic/detection-rules/blob/7d5efd68603f42be5e125b5a6a503b2ef3ac0f4e/rules/integrations/aws/impact_elasticache_security_group_modified_or_deleted.toml
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/aws/cloudtrail/aws_elasticache_security_group_modified_or_deleted.yml
author: Austin Songer @austinsonger, Huntrule Team
date: 2021-07-24
modified: 2022-10-09
tags:
- attack.impact
- attack.t1531
logsource:
product: aws
service: cloudtrail
detection:
selection:
eventSource: elasticache.amazonaws.com
eventName:
- DeleteCacheSecurityGroup
- AuthorizeCacheSecurityGroupIngress
- RevokeCacheSecurityGroupIngress
- AuthorizeCacheSecurityGroupEgress
- RevokeCacheSecurityGroupEgress
condition: selection
falsepositives:
- A ElastiCache security group deletion may be done by a system or network administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment. Security Group deletions from unfamiliar users or hosts should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: low
license: DRL-1.1
related:
- id: 7c797da2-9cf2-4523-ba64-33b06339f0cc
type: derived