AWS Config Resources Deletion

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Identifies attempts to delete an AWS Config Service resource. An adversary may tamper with Config services in order to reduce visibility into the security posture of an account and / or its workload instances.

Severity

Attention

Rule Requirement

Criteria

Action1: actionname = "DETECTION_ACTION_AWS_CONFIG_RESOURCES_DELETED" select Action1.CALLER,Action1.HOSTNAME,Action1.IPADDRESS,Action1.LOG_EVENT_NAME,Action1.SOURCE,Action1.SOURCE_REGION,Action1.REQUESTPARAMETERS

Detection

Execution Mode

realtime

Log Sources

AWS