AWS Route 53 Domain Transfer Lock Disabled via CloudTrail
Alerts when Route 53 domain transfer protection is removed through DisableDomainTransferLock events in CloudTrail.
- Product
- aws
- Service
- cloudtrail
- Author
- Elastic, Austin Songer @austinsonger (SigmaHQ), DRL 1.1
- Published
- 2021-07-22
- Updated
- 2026-07-31
ATT&CK techniques
Persistence → Priv EscRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags CloudTrail events where the Route 53 Domain Transfer Lock is disabled using the DisableDomainTransferLock operation. Disabling the transfer lock can enable or facilitate domain transfers to other registrars, which may be abused for persistence or unauthorized control. It relies on AWS CloudTrail telemetry containing eventSource route53.amazonaws.com and eventName DisableDomainTransferLock, including the actor identity details present in the event.
Reporting behind it
- github.comhttps://github.com/elastic/detection-rules/blob/c76a39796972ecde44cb1da6df47f1b6562c9770/rules/integrations/aws/persistence_route_53_domain_transfer_lock_disabled.toml
- docs.aws.amazon.comhttps://docs.aws.amazon.com/Route53/latest/APIReference/API_Operations_Amazon_Route_53.html
- docs.aws.amazon.comhttps://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_DisableDomainTransferLock.html
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/cloud/aws/cloudtrail/aws_route_53_domain_transferred_lock_disabled.yml
Changelog
v5- v5Candidate ingested via manual entry.2026-07-31
- v4Candidate ingested via manual entry.2026-07-31
- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: AWS Route 53 Domain Transfer Lock Disabled via CloudTrail
id: fe6d1dfd-c3f9-4539-8026-eb066ebed44c
status: test
description: This rule flags CloudTrail events where the Route 53 Domain Transfer Lock is disabled using the DisableDomainTransferLock operation. Disabling the transfer lock can enable or facilitate domain transfers to other registrars, which may be abused for persistence or unauthorized control. It relies on AWS CloudTrail telemetry containing eventSource route53.amazonaws.com and eventName DisableDomainTransferLock, including the actor identity details present in the event.
references:
- https://github.com/elastic/detection-rules/blob/c76a39796972ecde44cb1da6df47f1b6562c9770/rules/integrations/aws/persistence_route_53_domain_transfer_lock_disabled.toml
- https://docs.aws.amazon.com/Route53/latest/APIReference/API_Operations_Amazon_Route_53.html
- https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_DisableDomainTransferLock.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/aws/cloudtrail/aws_route_53_domain_transferred_lock_disabled.yml
author: Elastic, Austin Songer @austinsonger, Huntrule Team
date: 2021-07-22
modified: 2022-10-09
tags:
- attack.persistence
- attack.privilege-escalation
- attack.credential-access
- attack.t1098
logsource:
product: aws
service: cloudtrail
detection:
selection:
eventSource: route53.amazonaws.com
eventName: DisableDomainTransferLock
condition: selection
falsepositives:
- A domain transfer lock may be disabled by a system or network administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment. Activity from unfamiliar users or hosts should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: low
license: DRL-1.1
related:
- id: 3940b5f1-3f46-44aa-b746-ebe615b879e0
type: derived