Suspicious AWS CloudTrail Logging Disabled

PremiumReviewedSigma · High · v1
Product
aws
Service
cloudtrail
Author
HuntRule
Published
2026-06-27
Updated
2026-08-28

ATT&CK techniques

  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

  14. Impact

What it detects

This rule detects API calls that stop or delete AWS logging such as StopLogging, DeleteTrail and DeleteFlowLogs. Adversaries disable CloudTrail and VPC flow logs to blind defenders before carrying out further actions, a defense evasion step that should be rare and deliberate.

Related detections5 linkedT1685.002 — drag to rearrange
Malicious Mailbox Audit Bypass Association in Exchange Online (via exchange)
Suspicious GCP Log Sink Tampering for Defense Evasion (via gcp)
AWS CloudTrail GuardDuty Detector Deleted or Disabled via UpdateDetector
AWS CloudTrail: AWS Config Delivery Channel/Recorder Disabled
AWS CloudTrail Trail Stop/Update/Delete Activity
Suspicious AWS CloudTrail Logging Disabled
Pivot detection · T1685.002 · 5 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.