Analytics Story: AWS Defense Evasion
Description
Identify activity and techniques associated with the Evasion of Defenses within AWS, such as Disabling CloudTrail, Deleting CloudTrail and many others.
Why it matters
Adversaries employ a variety of techniques in order to avoid detection and operate without barriers. This often involves modifying the configuration of security monitoring tools to get around them or explicitly disabling them to prevent them from running. This Analytic Story includes analytics that identify activity consistent with adversaries attempting to disable various security mechanisms on AWS. Such activity may involve deleting the CloudTrail logs , as this is where all the AWS logs get stored or explicitly changing the retention policy of S3 buckets. Other times, adversaries attempt deletion of a specified AWS CloudWatch log group.
Detections
Data Sources
| Name | Platform | Sourcetype | Source |
|---|---|---|---|
| ASL AWS CloudTrail | aws:asl |
aws_asl |
|
| AWS CloudTrail UpdateTrail | aws:cloudtrail |
aws_cloudtrail |
|
| AWS CloudTrail DeleteLogGroup | aws:cloudtrail |
aws_cloudtrail |
|
| AWS CloudTrail StopLogging | aws:cloudtrail |
aws_cloudtrail |
|
| AWS CloudTrail DeleteTrail | aws:cloudtrail |
aws_cloudtrail |
|
| AWS CloudTrail DeleteRule | aws:cloudtrail |
aws_cloudtrail |
|
| AWS CloudTrail DeleteIPSet | aws:cloudtrail |
aws_cloudtrail |
|
| AWS CloudTrail DeleteRuleGroup | aws:cloudtrail |
aws_cloudtrail |
|
| AWS CloudTrail DeleteAlarms | aws:cloudtrail |
aws_cloudtrail |
|
| AWS CloudTrail DeleteWebACL | aws:cloudtrail |
aws_cloudtrail |
|
| AWS CloudTrail DeleteDetector | aws:cloudtrail |
aws_cloudtrail |
|
| AWS CloudTrail DeleteLoggingConfiguration | aws:cloudtrail |
aws_cloudtrail |
|
| AWS CloudTrail DeleteLogStream | aws:cloudtrail |
aws_cloudtrail |
|
| AWS CloudTrail PutBucketLifecycle | aws:cloudtrail |
aws_cloudtrail |
References
Source: GitHub | Version: 2