{"id":"T1685.002","name":"Disable or Modify Cloud Log","url":"https://attack.mitre.org/techniques/T1685/002","tactics":["defense-impairment"],"platforms":["IaaS","SaaS","Identity Provider","Office Suite"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0289","stix_id":"x-mitre-detection-strategy--f0190654-2eda-42a7-9a4d-6edc95aada02","name":"Detection Strategy for Disable or Modify Cloud Log","url":"https://attack.mitre.org/detectionstrategies/DET0289","analytics":[{"id":"AN0801","stix_id":"x-mitre-analytic--a788e3ed-8faf-4443-bb26-fd530ca930d1","name":"Analytic 0801","description":"Cloud API events where logging services are stopped, deleted, or modified in a way that disables audit visibility. Defender view: unauthorized StopLogging, DeleteTrail, or UpdateSink operations correlated with privileged user activity.","url":"https://attack.mitre.org/detectionstrategies/DET0289#AN0801","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"Stop logging for an existing CloudTrail","data_component":"DC0090","data_component_name":"Cloud Service Disable","log_source_slug":"aws-cloudtrail"},{"name":"gcp:config","channel":"UpdateSink request modifying log export destinations","data_component":"DC0069","data_component_name":"Cloud Service Modification","log_source_slug":"gcp-config"}],"mutable_elements":[{"field":"AdminRoles","description":"Define which roles are authorized to stop or modify logging."},{"field":"RegionScope","description":"Adjust monitoring to ensure multi-region logging tampering is caught."}],"live":true,"detection_strategies":["DET0289"],"techniques":["T1685.002"]},{"id":"AN0802","stix_id":"x-mitre-analytic--8e0f5333-9fc0-4f03-ae12-cf98903e08ea","name":"Analytic 0802","description":"Disabling or modifying sign-in or audit log collection for user activities. Defender view: policy or configuration updates removing logging coverage for critical accounts.","url":"https://attack.mitre.org/detectionstrategies/DET0289#AN0802","platforms":["Identity Provider"],"log_source_references":[{"name":"azure:policy","channel":"DisableAuditLogs or ConditionalAccess logging changes","data_component":"DC0069","data_component_name":"Cloud Service Modification","log_source_slug":"azure-policy"}],"mutable_elements":[{"field":"CriticalAccounts","description":"Tune to prioritize logging changes that affect administrative or high-value accounts."}],"live":true,"detection_strategies":["DET0289"],"techniques":["T1685.002"]},{"id":"AN0803","stix_id":"x-mitre-analytic--e42656e7-6a0e-492e-82b6-90d0d5667993","name":"Analytic 0803","description":"Disabling mailbox or tenant-level audit logging, often using Set-MailboxAuditBypassAssociation or downgrading license tiers. Defender view: sudden absence of mailbox activity logging for monitored users.","url":"https://attack.mitre.org/detectionstrategies/DET0289#AN0803","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"Set-MailboxAuditBypassAssociation or disabling Advanced Auditing","data_component":"DC0010","data_component_name":"User Account Modification","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"UserScope","description":"Tune alerts for users where mailbox auditing should always remain enabled."}],"live":true,"detection_strategies":["DET0289"],"techniques":["T1685.002"]},{"id":"AN0804","stix_id":"x-mitre-analytic--967f7636-1547-4db7-921a-1b84f312a2cd","name":"Analytic 0804","description":"Disabling or altering security and audit logs in SaaS admin panels (e.g., Slack, Zoom, Salesforce). Defender view: API calls or admin console changes that stop event exports or logging integrations.","url":"https://attack.mitre.org/detectionstrategies/DET0289#AN0804","platforms":["SaaS"],"log_source_references":[{"name":"saas:audit","channel":"Log export integration removed or disabled","data_component":"DC0090","data_component_name":"Cloud Service Disable","log_source_slug":"saas-audit"}],"mutable_elements":[{"field":"IntegrationScope","description":"Define which SaaS log integrations are required and alert if removed."}],"live":true,"detection_strategies":["DET0289"],"techniques":["T1685.002"]}],"live":true,"version":"1.0","techniques":["T1685.002"]}],"sigma_rules":[{"id":"07330162-dba1-4746-8121-a9647d49d297","title":"AWS Config Disabling Channel/Recorder","author":"vitaliy0x1","status":"test","level":"high","date":"2020-01-21","modified":"2022-10-09","description":"Detects AWS Config Service disabling","references":["https://docs.aws.amazon.com/config/latest/developerguide/cloudtrail-log-files-for-aws-config.html"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.defense-impairment","attack.t1685.002"],"path":"rules/cloud/aws/cloudtrail/aws_config_disable_recording.yml","techniques":["T1685.002"],"cves":[]},{"id":"4db60cc0-36fb-42b7-9b58-a5b53019fb74","title":"AWS CloudTrail Important Change","author":"vitaliy0x1","status":"test","level":"medium","date":"2020-01-21","modified":"2022-10-09","description":"Detects disabling, deleting and updating of a Trail","references":["https://docs.aws.amazon.com/awscloudtrail/latest/userguide/best-practices-security.html"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.defense-impairment","attack.t1685.002"],"path":"rules/cloud/aws/cloudtrail/aws_cloudtrail_disable_logging.yml","techniques":["T1685.002"],"cves":[]},{"id":"d2656e78-c069-4571-8220-9e0ab5913f19","title":"AWS GuardDuty Detector Deleted Or Updated","author":"suktech24","status":"experimental","level":"high","date":"2025-11-27","modified":null,"description":"Detects successful deletion or disabling of an AWS GuardDuty detector, possibly by an attacker trying to avoid detection of its malicious activities.\nUpon deletion, GuardDuty stops monitoring the environment and all existing findings are lost.\nVerify with the user identity that this activity is legitimate.\n","references":["https://docs.aws.amazon.com/guardduty/latest/APIReference/API_DeleteDetector.html","https://docs.aws.amazon.com/guardduty/latest/APIReference/API_UpdateDetector.html","https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_suspend-disable.html","https://docs.datadoghq.com/security/default_rules/719-39f-9cd/","https://docs.prismacloud.io/en/enterprise-edition/policy-reference/aws-policies/aws-general-policies/ensure-aws-guardduty-detector-is-enabled","https://docs.stellarcyber.ai/5.2.x/Using/ML/Alert-Rule-Based-Potentially_Malicious_AWS_Activity.html","https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Amazon%20Web%20Services/Analytic%20Rules/AWS_GuardDutyDisabled.yaml","https://github.com/elastic/detection-rules/blob/main/rules/integrations/aws/defense_evasion_guardduty_detector_deletion.toml","https://help.fortinet.com/fsiem/Public_Resource_Access/7_4_0/rules/PH_RULE_AWS_GuardDuty_Detector_Deletion.htm","https://research.splunk.com/sources/5d8bd475-c8bc-4447-b27f-efa508728b90/","https://suktech24.com/2025/07/17/aws-threat-detection-rule-guardduty-detector-disabled-or-suspended/","https://www.atomicredteam.io/atomic-red-team/atomics/T156001#atomic-test-46---aws---guardduty-suspension-or-deletion"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.defense-impairment","attack.t1685","attack.t1685.002"],"path":"rules/cloud/aws/cloudtrail/aws_cloudtrail_guardduty_detector_deleted_or_updated.yml","techniques":["T1685","T1685.002"],"cves":[]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}