Cross-source coverage

T1685.002 / ATT&CK

Disable or Modify Tools: Disable or Modify Cloud Log

22 rules across 2 sources.

From MITRE ATT&CK 19.2

An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within the environment. If an adversary has sufficient permissions, they can disable or modify logging to avoid detection of their activities.

For example, in AWS an adversary may disable CloudWatch/CloudTrail integrations prior to conducting further malicious activity. They may alternatively tamper with logging functionality, for example, by removing any associated SNS topics, disabling multi-region logging, or disabling settings that validate and/or encrypt log files. In Office 365, an adversary may disable logging on mail collection activities for specific users by using the Set-MailboxAuditBypassAssociation cmdlet, by disabling M365 Advanced Auditing for the user, or by downgrading the user’s license from an Enterprise E5 to an Enterprise E3 license.

Platforms
IaaS · SaaS · Identity Provider · Office Suite
Telemetry
AWS:CloudTrailgcp:configazure:policym365:unifiedsaas:audit

How MITRE says to detect it DET0289

Detection Strategy for Disable or Modify Cloud Log

IaaS Analytic 0801

Cloud API events where logging services are stopped, deleted, or modified in a way that disables audit visibility. Defender view: unauthorized StopLogging, DeleteTrail, or UpdateSink operations correlated with privileged user activity.

  • AWS:CloudTrail Stop logging for an existing CloudTrail
  • gcp:config UpdateSink request modifying log export destinations

Identity Provider Analytic 0802

Disabling or modifying sign-in or audit log collection for user activities. Defender view: policy or configuration updates removing logging coverage for critical accounts.

  • azure:policy DisableAuditLogs or ConditionalAccess logging changes

Office Suite Analytic 0803

Disabling mailbox or tenant-level audit logging, often using Set-MailboxAuditBypassAssociation or downgrading license tiers. Defender view: sudden absence of mailbox activity logging for monitored users.

  • m365:unified Set-MailboxAuditBypassAssociation or disabling Advanced Auditing

SaaS Analytic 0804

Disabling or altering security and audit logs in SaaS admin panels (e.g., Slack, Zoom, Salesforce). Defender view: API calls or admin console changes that stop event exports or logging integrations.

  • saas:audit Log export integration removed or disabled

splunk/security_content

19 rules
Detection Severity Format
ASL AWS Defense Evasion Delete Cloudtrail Undefined SPL
ASL AWS Defense Evasion Delete CloudWatch Log Group Undefined SPL
ASL AWS Defense Evasion Impair Security Services Undefined SPL
ASL AWS Defense Evasion PutBucketLifecycle Undefined SPL
ASL AWS Defense Evasion Stop Logging Cloudtrail Undefined SPL
ASL AWS Defense Evasion Update Cloudtrail Undefined SPL
AWS Bedrock Delete GuardRails Undefined SPL
AWS Bedrock Delete Model Invocation Logging Configuration Undefined SPL
AWS Defense Evasion Delete Cloudtrail Undefined SPL
AWS Defense Evasion Delete CloudWatch Log Group Undefined SPL

+ 9 more from splunk/security_content → showing the 10 highest-severity

SigmaHQ/sigma

3 rules
Detection Severity Format
AWS Config Disabling Channel/Recorder High Sigma
AWS GuardDuty Detector Deleted Or Updated High Sigma
AWS CloudTrail Important Change Medium Sigma

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.