Attackers Can Silently Disable AWS CloudTrail Logging With a Single API Call
Security researchers warn that an attacker who gains access to an AWS account can halt audit logging with a single command — aws cloudtrail stop-logging — leaving the trail's configuration visually intact while new events stop being recorded. The technique, catalogued under MITRE ATT&CK as T1562.008, is well-documented in Mandiant incident reports and AWS security guidance. Because standard inspection commands like describe-trails and GetTrail do not reveal the logging state, only get-trail-status exposes the critical IsLogging: false flag. Inside this blind window, attackers can exfiltrate secrets, create persistent backdoor IAM users, and rotate KMS keys to prevent decryption of existing log archives — all without generating a CloudTrail record. Security teams are advised not to treat 'trail configured' as equivalent to 'trail running,' and to actively monitor the logging status field rather than relying solely on static configuration audits.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in