AWS VPC Flow Log deleted

このページは日本語には対応しておりません。随時翻訳に取り組んでいます。翻訳に関してご質問やご意見ございましたら、お気軽にご連絡ください。

Goal

Detect when one or more AWS VPC Flow Log are deleted.

Strategy

Monitor CloudTrail and detect when AWS VPC FLow Logs are deleted by calling the DeleteFlowLogs API.

Triage and response

  1. Determine if the API call: {{@evt.name}} should have occurred.
  2. If the action was legitimate, consider allowing the invoking service: {{@userIdentity.invokedBy}}, user: {{@userIdentity.arn}}, or other appropriate attribute through a suppression list.
  3. If it shouldn’t have been made:
    • Contact the user: {{@userIdentity.arn}} and see if they made the API call.
  4. If the API call was not made by the user:
    • Rotate the user credentials.
    • Determine what other API calls were made with the old credentials that were not made by the user.