Disable or Modify Cloud Log

T1685.002

Sub-technique of T1685 Disable or Modify Tools.View on attack.mitre.org

About this technique

An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within the environment. If an adversary has sufficient permissions, they can disable or modify logging to avoid detection of their activities.

For example, in AWS an adversary may disable CloudWatch/CloudTrail integrations prior to conducting further malicious activity. They may alternatively tamper with logging functionality, for example, by removing any associated SNS topics, disabling multi-region logging, or disabling settings that validate and/or encrypt log files. In Office 365, an adversary may disable logging on mail collection activities for specific users by using the Set-MailboxAuditBypassAssociation cmdlet, by disabling M365 Advanced Auditing for the user, or by downgrading the user’s license from an Enterprise E5 to an Enterprise E3 license.

Detection rules22

Rules on DetectionCode tagged with T1685.002.

Sigma3

Splunk19

RuleTypeRiskData source
ASL AWS Defense Evasion Delete CloudtrailTTPNULLASL AWS CloudTrail
ASL AWS Defense Evasion Delete CloudWatch Log GroupTTPNULLASL AWS CloudTrail
ASL AWS Defense Evasion Impair Security ServicesHuntingNULLASL AWS CloudTrail
ASL AWS Defense Evasion PutBucketLifecycleHuntingNULLASL AWS CloudTrail
ASL AWS Defense Evasion Stop Logging CloudtrailTTPNULLASL AWS CloudTrail
ASL AWS Defense Evasion Update CloudtrailTTPNULLASL AWS CloudTrail
AWS Bedrock Delete GuardRailsTTPNULLAWS CloudTrail DeleteGuardrail
AWS Bedrock Delete Model Invocation Logging ConfigurationTTPNULLAWS CloudTrail DeleteModelInvocationLoggingConfiguration
AWS Defense Evasion Delete CloudtrailTTPNULLAWS CloudTrail DeleteTrail
AWS Defense Evasion Delete CloudWatch Log GroupTTPNULLAWS CloudTrail DeleteLogGroup
AWS Defense Evasion Impair Security ServicesTTPNULLAWS CloudTrail DeleteLogStream, AWS CloudTrail DeleteDetector, AWS CloudTrail DeleteIPSet, AWS CloudTrail DeleteWebACL, AWS CloudTrail DeleteRule, AWS CloudTrail DeleteRuleGroup, AWS CloudTrail DeleteLoggingConfiguration, AWS CloudTrail DeleteAlarms
AWS Defense Evasion PutBucketLifecycleHuntingNULLAWS CloudTrail PutBucketLifecycle
AWS Defense Evasion Stop Logging CloudtrailTTPNULLAWS CloudTrail StopLogging
AWS Defense Evasion Update CloudtrailTTPNULLAWS CloudTrail UpdateTrail
GitHub Enterprise Disable Audit Log Event StreamAnomalyNULLGitHub Enterprise Audit Logs

Groups1

Software1

Campaigns0

None recorded.

Procedure examples2

Groups1

Used byProcedure example
GroupAPT29

APT29 has disabled Purview Audit on targeted accounts prior to stealing emails from Microsoft 365 tenants.

Software1

Used byProcedure example
ToolPacu

Pacu can disable or otherwise restrict various AWS logging services, such as AWS CloudTrail and VPC flow logs.

References3

  1. AWS Cloud Trail Open source
    AWS. (n.d.). update-trail. Retrieved April 15, 2026.
  2. Dark Reading Open source
    Kelly Sheridan. (2021, August 5). Retrieved April 15, 2026.
  3. Pacu Detection Disruption Module Open source
    Rhino Security Labs. (2021, April 29). Pacu Detection Disruption Module. Retrieved August 4, 2023.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.