AWS SQS Queue Purge

Last updated on:

About the rule

Rule Type

Standard

Rule Description

Identifies when an AWS Simple Queue Service (SQS) queue is purged. Adversaries may purge SQS queues to disrupt operations, delete messages, or impair monitoring and alerting mechanisms. This action can be used to evade detection and cover tracks by removing evidence of malicious activities.

Severity

Trouble

Rule Requirement

Criteria

Action1: actionname = "DETECTION_ACTION_AWS_SQS_QUEUE_PURGED" select Action1.CALLER,Action1.HOSTNAME,Action1.IPADDRESS,Action1.LOG_EVENT_NAME,Action1.SOURCE,Action1.SOURCE_REGION,Action1.REQUESTPARAMETERS

Detection

Execution Mode

realtime

Log Sources

AWS