AWS Route 53 Domain Transfer Lock Disabled via CloudTrail

Alerts when Route 53 domain transfer protection is removed through DisableDomainTransferLock events in CloudTrail.

FreeReviewedSigma · Low · v5
Product
aws
Service
cloudtrail
Author
Elastic, Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-07-22
Updated
2026-07-31
title: AWS Route 53 Domain Transfer Lock Disabled via CloudTrail
id: fe6d1dfd-c3f9-4539-8026-eb066ebed44c
status: test
description: This rule flags CloudTrail events where the Route 53 Domain Transfer Lock is disabled using the DisableDomainTransferLock operation. Disabling the transfer lock can enable or facilitate domain transfers to other registrars, which may be abused for persistence or unauthorized control. It relies on AWS CloudTrail telemetry containing eventSource route53.amazonaws.com and eventName DisableDomainTransferLock, including the actor identity details present in the event.
references:
  - https://github.com/elastic/detection-rules/blob/c76a39796972ecde44cb1da6df47f1b6562c9770/rules/integrations/aws/persistence_route_53_domain_transfer_lock_disabled.toml
  - https://docs.aws.amazon.com/Route53/latest/APIReference/API_Operations_Amazon_Route_53.html
  - https://docs.aws.amazon.com/Route53/latest/APIReference/API_domains_DisableDomainTransferLock.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/aws/cloudtrail/aws_route_53_domain_transferred_lock_disabled.yml
author: Elastic, Austin Songer @austinsonger, Huntrule Team
date: 2021-07-22
modified: 2022-10-09
tags:
  - attack.persistence
  - attack.privilege-escalation
  - attack.credential-access
  - attack.t1098
logsource:
  product: aws
  service: cloudtrail
detection:
  selection:
    eventSource: route53.amazonaws.com
    eventName: DisableDomainTransferLock
  condition: selection
falsepositives:
  - A domain transfer lock may be disabled by a system or network administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment. Activity from unfamiliar users or hosts should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: low
license: DRL-1.1
related:
  - id: 3940b5f1-3f46-44aa-b746-ebe615b879e0
    type: derived