Cross-source coverage

T1562.008 / ATT&CK

Impair Defenses: Disable or Modify Cloud Logs

ATT&CK has retired this technique. Rules still tag it; the current id is T1685.002 Disable or Modify Tools: Disable or Modify Cloud Log.

60 rules · 58 families across 6 sources.

From MITRE ATT&CK 19.2

An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within the environment. If an adversary has sufficient permissions, they can disable or modify logging to avoid detection of their activities.

For example, in AWS an adversary may disable CloudWatch/CloudTrail integrations prior to conducting further malicious activity. They may alternatively tamper with logging functionality – for example, by removing any associated SNS topics, disabling multi-region logging, or disabling settings that validate and/or encrypt log files. In Office 365, an adversary may disable logging on mail collection activities for specific users by using the Set-MailboxAuditBypassAssociation cmdlet, by disabling M365 Advanced Auditing for the user, or by downgrading the user’s license from an Enterprise E5 to an Enterprise E3 license.

Tactics
Stealth
Platforms
IaaS · SaaS · Office Suite · Identity Provider
Telemetry

elastic/detection-rules

25 rules
Detection Severity Format
AWS Bedrock Model Invocation Logging Disabled or Modified High Elastic TOML
AWS CloudTrail Log Suspended High Elastic TOML
AWS CloudTrail Log Updated High Elastic TOML
AWS Configuration Recorder Stopped High Elastic TOML
AWS EKS Control Plane Logging Disabled High Elastic TOML
AWS S3 Bucket Server Access Logging Disabled High Elastic TOML
AWS VPC Flow Logs Deletion High Elastic TOML
AWS CloudTrail Log Deleted Medium Elastic TOML
AWS CloudTrail Log Evasion Medium Elastic TOML
AWS CloudTrail Management Events Disabled via PutEventSelectors Medium Elastic TOML

+ 15 more from elastic/detection-rules → showing the 10 highest-severity

panther-labs/panther-analysis

18 rules
Detection Severity Format
AWS RDS Activity Stream Stopped High Panther Python
Azure Event Hub Deleted High Panther Python
Carbon Black Data Forwarder Stopped High Panther Python
Databricks Verbose Audit Logging Disabled High Panther Python
Slack EKM Config Changed High Panther Python
Azure Alert Rules Deleted Medium Panther Python
Azure Diagnostic Settings Deleted Medium Panther Python
Azure Log Analytics Workspace Deleted Medium Panther Python
Databricks High Priority Configuration Changes Medium Panther Python
ZIA Backup Deleted Medium Panther Python

+ 8 more from panther-labs/panther-analysis → showing the 10 highest-severity

chronicle/detection-rules

11 rules
Detection Severity Format
o365_logging_disabled Critical YARA-L
o365_logging_enabled Critical YARA-L
aws_cloudtrail_logging_tampered High YARA-L
aws_config_service_modified High YARA-L
aws_delete_cloudwatch_log_group High YARA-L
gcp_cloud_audit_logging_removed_from_all_services High YARA-L
gcp_exempt_principals_from_audit_log High YARA-L
github_enterprise_audit_log_stream_destroyed High YARA-L
github_enterprise_audit_log_stream_modified High YARA-L
aws_delete_vpc_flow_logs Low YARA-L

+ 1 more from chronicle/detection-rules → showing the 10 highest-severity

Wazuh Core Ruleset

3 rules
Detection Severity Format
Possible disruption of CloudTrail Logging: Management events logging disabled with an event selector. High Wazuh XML
GCP logging bucket deleted. Low Wazuh XML
GCP logging sink deleted. Low Wazuh XML

Bert-JanP/Hunting-Queries-Detection-Rules

2 rules
Detection Severity Format
MITRE ATT&CK Mapping Undefined KQL
Sentinel Workspace Disconnected Undefined KQL

Azure/Azure-Sentinel

1 rule
Detection Severity Format
Azure Diagnostic settings removed from a resource Medium KQL

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.