AWS VPC Flow Log deleted

Goal

Detect when one or more AWS VPC Flow Log are deleted.

Strategy

Monitor CloudTrail and detect when AWS VPC FLow Logs are deleted by calling the DeleteFlowLogs API.

Triage and response

  1. Determine if the API call: {{@evt.name}} should have occurred.
  2. If the action was legitimate, consider allowing the invoking service: {{@userIdentity.invokedBy}}, user: {{@userIdentity.arn}}, or other appropriate attribute through a suppression list.
  3. If it shouldn’t have been made:
    • Contact the user: {{@userIdentity.arn}} and see if they made the API call.
  4. If the API call was not made by the user:
    • Rotate the user credentials.
    • Determine what other API calls were made with the old credentials that were not made by the user.