Product
high
advisory
AWS Security Services Impairment via Deletion of Resources
2 rules 1 TTPDetection of adversaries attempting to impair or disable AWS security services by deleting resources across GuardDuty, AWS WAF, CloudWatch, Route 53, and CloudWatch Logs to evade detection and remove visibility.
CloudWatch +5
aws
cloudtrail
defense-evasion
cloud
2r
1t
high
advisory
AWS Security Services Configuration Deletion
2 rules 1 TTPDetection of deletion of critical AWS Security Services configurations like CloudWatch alarms, GuardDuty detectors, and Web Application Firewall rules to evade detection, potentially leading to data breaches and unauthorized access.
CloudWatch +5
aws
cloudtrail
defense-evasion
security-service
2r
1t
high
advisory
AWS CloudWatch Log Group Deletion for Defense Evasion
2 rules 1 TTPDetection of AWS CloudWatch log group deletions via CloudTrail logs, excluding console-based actions, indicating potential defense evasion by attackers attempting to hide their tracks.
Splunk Enterprise +3
aws
cloudwatch
defense-evasion
2r
1t