AWS VPC Flow Logs Deleted

Rule Info

Name
AWS VPC Flow Logs Deleted
Author
Ivan Saakov
Description
Detects the deletion of one or more VPC Flow Logs in AWS Elastic Compute Cloud (EC2) through the DeleteFlowLogs API call. Adversaries may delete flow logs to evade detection or remove evidence of network activity, hindering forensic investigations and visibility into malicious operations.
Date
2025-10-19 00:00:00
Modified
None
Id
e386b9b5-af12-450e-afff-761730fb8a98
Tags
attack.defense-evasion
Type
Community Rule

Rule History

Author
Title
Date
Commit
Ivan S
Merge PR #5021 from @saakovv - New rules for AWS
2025-10-22