Disable CloudTrail Logging Through Event Selectors
idempotent
Platform: AWS
MITRE ATT&CK Tactics
- Defense Evasion
Description
Disrupt CloudTrail Logging by creating an event selector on the Trail, filtering out all management events.
Warm-up:
- Create a CloudTrail trail.
Detonation:
- Create a CloudTrail event selector to disable management events, through cloudtrail:PutEventSelectors
Instructions
Detection
Identify when event selectors of a CloudTrail trail are updated, through CloudTrail's PutEventSelectors
event.