Defense Evasion via Deletion of Amazon Detective Behavior Graphs
Attackers with high-level IAM permissions may delete Amazon Detective behavior graphs to impair forensic investigations by destroying historical relationship mapping and telemetry analysis data.
The deletion of an Amazon Detective behavior graph via the DeleteGraph API is a defense evasion technique that targets an organization's forensic capabilities. Amazon Detective consumes logs from AWS CloudTrail, VPC Flow Logs, and Amazon GuardDuty to provide automated security insights and visual relationship mapping. Because the deletion of a behavior graph is an irreversible operation, it effectively destroys the historical analytical context required for post-compromise investigation.
This activity is significant for defenders because it is rarely performed as a routine maintenance task. When observed in production environments without accompanying change management records, the deletion of a Detective graph likely indicates an attempt by an adversary to obstruct security teams, hide their movements, or disrupt the incident response timeline. Security teams must monitor for this API call and correlate it with other environmental changes, such as the disabling of GuardDuty or the modification of logging configurations.
Attack Chain
- Attacker gains initial access to an AWS environment through compromised credentials or exploitation of a misconfigured resource.
- Attacker performs discovery to identify enabled security services and monitoring capabilities, including Amazon Detective.
- Attacker evaluates existing IAM permissions to determine if they possess the authorization to modify or delete security infrastructure.
- Attacker executes the
DeleteGraphAPI call, resulting in the permanent destruction of the behavior graph and historical data. - Attacker proceeds with further malicious objectives, such as data exfiltration or persistent resource deployment, now unhindered by Detective's behavior monitoring.
- Attacker clears or attempts to minimize trace artifacts while the environment's forensic investigation capabilities are degraded.
Impact
Successful deletion of an Amazon Detective behavior graph results in the permanent loss of historical security analytics and the inability to use graph theory-based investigation tools for existing incidents. This creates significant blind spots for incident responders who rely on Detective to trace resource interactions and identify the scope of an adversary's activity. The impact is primarily a severe reduction in forensic capability, which complicates incident scoping and increases the time required for threat hunting and remediation.
Recommendation
Prioritize the following actions to detect and mitigate the unauthorized deletion of security services:
- Implement a detection alert for the
DeleteGraphaction in AWS CloudTrail using the provided Sigma rule. - Apply Service Control Policies (SCPs) that restrict the
detective:DeleteGraphpermission to a limited set of break-glass or senior administrator identities. - Audit IAM permissions across all accounts to identify identities with excessive access to security service management APIs.
- Review change management logs when this alert triggers to differentiate between authorized environment decommissioning and malicious activity.
Immediate actions
Deploy the detection rule for AWS Detective graph deletion.
Mitigations
Implement SCPs to restrict detective:DeleteGraph permissions.
T1562.001
Detection coverage 1
Detect AWS Detective Graph Deletion
lowDetects the successful execution of the DeleteGraph API call in Amazon Detective, which may indicate an attempt to impair forensic investigation capabilities.
Detection queries are available on the platform. Get full rules →