aws-ioc-detection.md (1557B)
1 --- 2 title: "AWS - IOC & Detections" 3 section: "Cloud" 4 sectionSlug: "cloud" 5 sourcePath: "docs/cloud/aws/aws-ioc-detection.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/aws/aws-ioc-detection.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # AWS - IOC & Detections 12 13 ## CloudTrail 14 15 ### Disable CloudTrail 16 17 ```powershell 18 aws cloudtrail delete-trail --name cloudgoat_trail --profile administrator 19 ``` 20 21 Disable monitoring of events from global services 22 23 ```powershell 24 aws cloudtrail update-trail --name cloudgoat_trail --no-include-global-service-event 25 ``` 26 27 Disable Cloud Trail on specific regions 28 29 ```powershell 30 aws cloudtrail update-trail --name cloudgoat_trail --no-include-global-service-event --no-is-multi-region --region=eu-west 31 ``` 32 33 ## GuardDuty 34 35 ### OS User Agent 36 37 :warning: When using awscli on Kali Linux, Pentoo and Parrot Linux, a log is generated based on the user-agent. 38 39 Pacu bypass this problem by defining a custom User-Agent: [pacu.py#L1473](https://web.archive.org/web/20201111195614/https://github.com/RhinoSecurityLabs/pacu/blob/master/pacu.py#L1303) 40 41 ```python 42 boto3_session = boto3.session.Session() 43 ua = boto3_session._session.user_agent() 44 if 'kali' in ua.lower() or 'parrot' in ua.lower() or 'pentoo' in ua.lower(): # If the local OS is Kali/Parrot/Pentoo Linux 45 # GuardDuty triggers a finding around API calls made from Kali Linux, so let's avoid that... 46 self.print('Detected environment as one of Kali/Parrot/Pentoo Linux. Modifying user agent to hide that from GuardDuty...') 47 ```