Config

AWS Config records the configuration state of every resource over time and evaluates it against rules, so it captures the resource changes an operation leaves behind. Stopping the recorder or removing its delivery channel halts that history; deleting rules removes the compliance checks that would flag a change.

Stop the recorder and delivery#

bash
aws configservice describe-configuration-recorders
aws configservice stop-configuration-recorder --configuration-recorder-name default
aws configservice delete-delivery-channel --delivery-channel-name default
aws configservice delete-configuration-recorder --configuration-recorder-name default

Delete the rules that would flag you#

bash
aws configservice describe-config-rules
aws configservice delete-config-rule --config-rule-name <rule>

Exploitation notes#

  • Stopping the recorder is a recorded action in CloudTrail; sequence it with the CloudTrail work when silence matters.
  • Config is regional and can aggregate across accounts; an organization aggregator in another account keeps collecting even after a local recorder stops.
  • Removing the delivery channel quietly breaks history shipping without the obvious "recorder stopped" state.

Tools#

  • AWS CLI (configservice): recorder, delivery-channel, and rule control.
  • Pacu (detection__disruption): disables Config alongside CloudTrail and GuardDuty.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more