EXPLORE
← Back to Explore
T1562.008

Disable or Modify Cloud Logs

An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within the environment. If an adversary has sufficient permissions, they can disable or modify logging to avoid detection of their activities. For example, in AWS an adversary may disable CloudWatch/CloudTrail ...

IaaSSaaSOffice SuiteIdentity Provider
44
Detections
3
Sources
1
Threat Actors

BY SOURCE

22elastic19splunk_escu3sigma

PROCEDURES (19)

Cloud6 detections

Auto-extracted: 6 detections for cloud

Api4 detections

Auto-extracted: 4 detections for api

Service4 detections

Auto-extracted: 4 detections for service

Aws3 detections

Auto-extracted: 3 detections for aws

General Monitoring3 detections

Auto-extracted: 3 detections for general monitoring

Exfiltrat3 detections

Auto-extracted: 3 detections for exfiltrat

Evasion3 detections

Auto-extracted: 3 detections for evasion

Encrypt2 detections

Auto-extracted: 2 detections for encrypt

Azure2 detections

Auto-extracted: 2 detections for azure

C22 detections

Auto-extracted: 2 detections for c2

Suspicious2 detections

Auto-extracted: 2 detections for suspicious

Inject2 detections

Auto-extracted: 2 detections for inject

Cloud Monitoring2 detections

Auto-extracted: 2 detections for cloud monitoring

Office1 detections

Auto-extracted: 1 detections for office

Azure1 detections

Auto-extracted: 1 detections for azure

Container1 detections

Auto-extracted: 1 detections for container

Bypass1 detections

Auto-extracted: 1 detections for bypass

Office1 detections

Auto-extracted: 1 detections for office

Container1 detections

Auto-extracted: 1 detections for container

THREAT ACTORS (1)

DETECTIONS (44)

ASL AWS Defense Evasion Delete Cloudtrail
splunk_escu
ASL AWS Defense Evasion Delete CloudWatch Log Group
splunk_escu
ASL AWS Defense Evasion Impair Security Services
splunk_escu
ASL AWS Defense Evasion PutBucketLifecycle
splunk_escu
ASL AWS Defense Evasion Stop Logging Cloudtrail
splunk_escu
ASL AWS Defense Evasion Update Cloudtrail
splunk_escu
AWS Bedrock Delete GuardRails
splunk_escu
AWS Bedrock Delete Model Invocation Logging Configuration
splunk_escu
AWS CloudTrail Important Change
sigmamedium
AWS CloudTrail Log Created
elasticlow
AWS CloudTrail Log Deleted
elasticmedium
AWS CloudTrail Log Evasion
elasticmedium
AWS CloudTrail Log Suspended
elasticmedium
AWS CloudTrail Log Updated
elasticlow
AWS CloudWatch Log Group Deletion
elasticmedium
AWS CloudWatch Log Stream Deletion
elasticmedium
AWS Config Disabling Channel/Recorder
sigmahigh
AWS Config Resource Deletion
elasticmedium
AWS Configuration Recorder Stopped
elastichigh
AWS Defense Evasion Delete Cloudtrail
splunk_escu
AWS Defense Evasion Delete CloudWatch Log Group
splunk_escu
AWS Defense Evasion Impair Security Services
splunk_escu
AWS Defense Evasion PutBucketLifecycle
splunk_escu
AWS Defense Evasion Stop Logging Cloudtrail
splunk_escu
AWS Defense Evasion Update Cloudtrail
splunk_escu
AWS GuardDuty Detector Deleted Or Updated
sigmahigh
AWS Route 53 Resolver Query Log Configuration Deleted
elasticmedium
AWS S3 Bucket Configuration Deletion
elasticlow
AWS S3 Bucket Expiration Lifecycle Configuration Added
elasticlow
AWS S3 Bucket Server Access Logging Disabled
elasticmedium
AWS SQS Queue Purge
elasticmedium
AWS VPC Flow Logs Deletion
elastichigh
Azure Diagnostic Settings Deleted
elasticmedium
Azure Event Hub Deleted
elasticmedium
Azure Kubernetes Services (AKS) Kubernetes Events Deleted
elasticmedium
Azure VNet Network Watcher Deleted
elasticmedium
GCP Logging Bucket Deletion
elasticmedium
GCP Logging Sink Deletion
elasticmedium
GCP Logging Sink Modification
elasticlow
GitHub Enterprise Disable Audit Log Event Stream
splunk_escu
GitHub Enterprise Modify Audit Log Event Stream
splunk_escu
GitHub Enterprise Pause Audit Log Event Stream
splunk_escu
O365 Advanced Audit Disabled
splunk_escu
O365 Email Security Feature Changed
splunk_escu