Cross-source coverage
T1562.008 / ATT&CK
Impair Defenses: Disable or Modify Cloud Logs
ATT&CK has retired this technique. Rules still tag it; the current id is T1685.002 Disable or Modify Tools: Disable or Modify Cloud Log.
From MITRE ATT&CK 19.2
An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within the environment. If an adversary has sufficient permissions, they can disable or modify logging to avoid detection of their activities.
For example, in AWS an adversary may disable CloudWatch/CloudTrail integrations prior to conducting further malicious activity. They may alternatively tamper with logging functionality – for example, by removing any associated SNS topics, disabling multi-region logging, or disabling settings that validate and/or encrypt log files. In Office 365, an adversary may disable logging on mail collection activities for specific users by using the Set-MailboxAuditBypassAssociation cmdlet, by disabling M365 Advanced Auditing for the user, or by downgrading the user’s license from an Enterprise E5 to an Enterprise E3 license.
- Tactics
- Stealth
- Platforms
- IaaS · SaaS · Office Suite · Identity Provider
- Telemetry
- —
elastic/detection-rules
25 rules| Detection | Severity | Format |
|---|---|---|
| AWS Bedrock Model Invocation Logging Disabled or Modified | High | Elastic TOML |
| AWS CloudTrail Log Suspended | High | Elastic TOML |
| AWS CloudTrail Log Updated | High | Elastic TOML |
| AWS Configuration Recorder Stopped | High | Elastic TOML |
| AWS EKS Control Plane Logging Disabled | High | Elastic TOML |
| AWS S3 Bucket Server Access Logging Disabled | High | Elastic TOML |
| AWS VPC Flow Logs Deletion | High | Elastic TOML |
| AWS CloudTrail Log Deleted | Medium | Elastic TOML |
| AWS CloudTrail Log Evasion | Medium | Elastic TOML |
| AWS CloudTrail Management Events Disabled via PutEventSelectors | Medium | Elastic TOML |
+ 15 more from elastic/detection-rules → showing the 10 highest-severity
panther-labs/panther-analysis
18 rules| Detection | Severity | Format |
|---|---|---|
| AWS RDS Activity Stream Stopped | High | Panther Python |
| Azure Event Hub Deleted | High | Panther Python |
| Carbon Black Data Forwarder Stopped | High | Panther Python |
| Databricks Verbose Audit Logging Disabled | High | Panther Python |
| Slack EKM Config Changed | High | Panther Python |
| Azure Alert Rules Deleted | Medium | Panther Python |
| Azure Diagnostic Settings Deleted | Medium | Panther Python |
| Azure Log Analytics Workspace Deleted | Medium | Panther Python |
| Databricks High Priority Configuration Changes | Medium | Panther Python |
| ZIA Backup Deleted | Medium | Panther Python |
+ 8 more from panther-labs/panther-analysis → showing the 10 highest-severity
chronicle/detection-rules
11 rules| Detection | Severity | Format |
|---|---|---|
| o365_logging_disabled | Critical | YARA-L |
| o365_logging_enabled | Critical | YARA-L |
| aws_cloudtrail_logging_tampered | High | YARA-L |
| aws_config_service_modified | High | YARA-L |
| aws_delete_cloudwatch_log_group | High | YARA-L |
| gcp_cloud_audit_logging_removed_from_all_services | High | YARA-L |
| gcp_exempt_principals_from_audit_log | High | YARA-L |
| github_enterprise_audit_log_stream_destroyed | High | YARA-L |
| github_enterprise_audit_log_stream_modified | High | YARA-L |
| aws_delete_vpc_flow_logs | Low | YARA-L |
+ 1 more from chronicle/detection-rules → showing the 10 highest-severity
Wazuh Core Ruleset
3 rules| Detection | Severity | Format |
|---|---|---|
| Possible disruption of CloudTrail Logging: Management events logging disabled with an event selector. | High | Wazuh XML |
| GCP logging bucket deleted. | Low | Wazuh XML |
| GCP logging sink deleted. | Low | Wazuh XML |
Bert-JanP/Hunting-Queries-Detection-Rules
2 rules| Detection | Severity | Format |
|---|---|---|
| MITRE ATT&CK Mapping | Undefined | KQL |
| Sentinel Workspace Disconnected | Undefined | KQL |
Azure/Azure-Sentinel
1 rule| Detection | Severity | Format |
|---|---|---|
| Azure Diagnostic settings removed from a resource | Medium | KQL |