1200KM / simulation
T1685.002 Disable or Modify Cloud Log — Attack Simulation
An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within the environment. If an adversary has sufficient permissions, they can disable or modify logging to avoid detection of their activities. For example, in…
Technique description
An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within the environment. If an adversary has sufficient permissions, they can disable or modify logging to avoid detection of their activities. For example, in…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- AWS - CloudTrail Logs Impairment Through S3 Lifecycle Rule using Stratus
Procedure 22d89a2f-d475-4895-b2d4-68626d49c029; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- AWS CloudWatch Log Stream Deletes
Procedure 33ca84bc-4259-4943-bd36-4655dc420932; elevation not declared required; cleanup not declared. Not executed or individually validated.
- AWS - Config Logs Disabled
Procedure 4608bc1b-e682-466b-a7d7-dbd76760db31; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Azure - Eventhub Deletion
Procedure 5e09bed0-7d33-453b-9bf3-caea32bff719; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- AWS - CloudWatch Log Group Deletes
Procedure 89422c87-b57b-4a04-a8ca-802bb9d06121; elevation not declared required; cleanup not declared. Not executed or individually validated.
- AWS - Remove VPC Flow Logs using Stratus
Procedure 93c150f5-ad7b-4ee3-8992-df06dec2ac79; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- AWS - CloudTrail Changes
Procedure 9c10dc6b-20bd-403a-8e67-50ef7d07ed4e; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- AWS - Disable CloudTrail Logging Through Event Selectors using Stratus
Procedure a27418de-bdce-4ebd-b655-38f11142bf0c; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- GCP - Delete Activity Event Log
Procedure d56152ec-01d9-42a2-877c-aac1f6ebe8e6; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.