EC2

eventNameDescriptionSampleRule
anyCatch-all entry for EC2 rules that match the service but not a specific eventName.NY
AssociateIamInstanceProfileAssociates an IAM instance profile with a running or stopped EC2 instance.NY
AuthorizeSecurityGroupEgressAdds outbound rules to a security group to allow traffic to the specified destination.YY
AuthorizeSecurityGroupIngressAdds inbound rules to a security group to allow traffic from the specified source.YY
CreateInstanceExportTaskExports a running or stopped EC2 instance to an Amazon S3 bucket in OVA, VHD, or VMDK format.YY
CreateKeyPairCreates an ED25519 or 2048-bit RSA key pair and stores the public key in EC2, returning the private key material.YY
CreateNetworkAclCreates a new network ACL in the specified VPC.YY
CreateNetworkAclEntryCreates an entry (rule) in a network ACL with the specified rule number, protocol, and traffic action.YY
CreateRouteCreates a route in a route table within a VPC, specifying the destination CIDR and target.YY
CreateRouteTableCreates a route table for the specified VPC.YY
CreateSecurityGroupCreates a security group in a specified VPC or for EC2-Classic.YY
CreateStoreImageTaskStores an Amazon Machine Image (AMI) as a single object in an Amazon S3 bucket.NY
CreateTrafficMirrorSessionCreates a traffic mirror session that copies network traffic from a source network interface to a target.YY
DeleteFlowLogsDeletes one or more VPC flow logs.YY
DeleteNetworkAclDeletes the specified network ACL, which must not be associated with any subnets.YY
DeleteNetworkAclEntryDeletes the specified ingress or egress entry (rule) from the specified network ACL.YY
DeleteRouteDeletes the specified route from the specified route table.YY
DeleteRouteTableDeletes the specified route table, which must not be associated with any subnet.YY
DescribeCarrierGatewaysDescribes one or more carrier gateways associated with a VPC.YN
DescribeClientVpnRoutesDescribes the routes for a specified Client VPN endpoint.YN
DescribeDhcpOptionsDescribes one or more DHCP options sets in the account.YN
DescribeImagesDescribes one or more Amazon Machine Images (AMIs) available to the account.YY
DescribeInstanceAttributeDescribes the specified attribute of the specified EC2 instance.YY
DescribeInstancesReturns detailed information about one or more EC2 instances, including their state, type, network interfaces, and associated metadata.YY
DescribeRegionsReturns the AWS regions that are enabled for the caller's account, or all regions that are available to EC2.YY
DescribeSecurityGroupsReturns information about one or more EC2 security groups, including their inbound and outbound rules.YY
DescribeSnapshotAttributeDescribes the specified attribute of the specified EBS snapshot.YY
DescribeSnapshotTierStatusDescribes the storage tier status of one or more EBS snapshots.YN
DescribeTransitGatewayMulticastDomainsDescribes one or more transit gateway multicast domains.YN
DescribeVolumesDescribes the specified EBS volumes or all EBS volumes in the account.YN
DescribeVolumesModificationsDescribes the most recent volume modification request for the specified EBS volumes.YN
DescribeVpcEndpointConnectionNotificationsDescribes the connection notifications for VPC endpoints and VPC endpoint services.YN
DescribeVpcsReturns information about one or more VPCs in the account, including their CIDR blocks, state, and associated attributes.YY
DisableEbsEncryptionByDefaultDisables default EBS encryption for EBS volumes created in the current account and Region.YY
DisassociateRouteTableDisassociates a subnet or gateway from a route table.YY
EnableSerialConsoleAccessEnables access to the EC2 serial console for EC2 instances in the current account and Region.YY
ExportImageExports an Amazon Machine Image (AMI) to an Amazon S3 bucket.NY
GetEbsDefaultKmsKeyIdRetrieves the default KMS key ID used for EBS encryption in the current Region.YN
GetEbsEncryptionByDefaultRetrieves the default EBS encryption setting for the current account and Region.YN
GetPasswordDataRetrieves the encrypted administrator password for a Windows instance.YY
GetTransitGatewayRouteTableAssociationsGets information about the route table associations for the specified transit gateway route table.YN
ImportKeyPairImports the public key from an RSA or ED25519 key pair that you created with a third-party tool.YY
ModifyImageAttributeModifies the specified attribute of the specified AMI, such as launch permissions or description.YY
ModifyInstanceAttributeModifies the specified attribute of the specified EC2 instance, such as instance type or user data.YY
ModifySecurityGroupRulesModifies the rules of a security group.YY
ModifySnapshotAttributeAdds or removes permission settings for the specified EBS snapshot, such as sharing it with other accounts.YY
ReplaceNetworkAclEntryReplaces an entry (rule) in a network ACL, changing subnet traffic filtering.YY
ReplaceRouteReplaces an existing route within a route table in a VPC.YY
ReplaceRouteTableAssociationChanges the route table associated with a given subnet, internet gateway, or virtual private gateway in a VPC.YY
RevokeSecurityGroupEgressRemoves outbound rules from a security group.YY
RevokeSecurityGroupIngressRemoves inbound rules from a security group.YY
StartInstancesStarts one or more stopped EC2 instances, transitioning them to the running state.YY
StopInstancesStops one or more running EC2 instances, transitioning them to the stopped state.YY
AcceptAddressTransferAccepts an Elastic IP address transfer.NN
AcceptCapacityReservationBillingOwnershipAccepts a request to assign billing of the available capacity of a shared Capacity Reservation to your account.NN
AcceptReservedInstancesExchangeQuotePurchases Convertible Reserved Instance offerings described in the GetReservedInstancesExchangeQuote call.NN
AcceptTransitGatewayClientVpnAttachmentAccepts a Transit Gateway attachment request for a Client VPN endpoint.NN
AcceptTransitGatewayMulticastDomainAssociationsAccepts a request to associate subnets with a transit gateway multicast domain.NN
AcceptTransitGatewayPeeringAttachmentAccepts a transit gateway peering attachment request.NN
AcceptTransitGatewayVpcAttachmentAccepts a request to attach a VPC to a transit gateway.NN
AcceptVpcEndpointConnectionsAccepts connection requests to your VPC endpoint service.NN
AcceptVpcPeeringConnectionAccept a VPC peering connection request.YY
AdvertiseByoipCidrAdvertises an IPv4 or IPv6 address range that is provisioned for use with your Amazon Web Services resources through bring your own IP addresses (BYOIP).NN
AllocateAddressAcquires an Elastic IP address.YN
AllocateHostsAllocates a Dedicated host to your account.YN
AllocateIpamPoolCidrAllocate a CIDR from an IPAM pool.YN
ApplySecurityGroupsToClientVpnTargetNetworkApplies a security group to the association between the target network and the Client VPN endpoint.NN
AssignIpv6AddressesAssigns the specified IPv6 addresses to the specified network interface.NN
AssignPrivateIpAddressesAssigns one or more secondary private IP addresses to the specified network interface.YN
AssignPrivateNatGatewayAddressAssigns private IPv4 addresses to a private NAT gateway.NN
AssociateAddressAssociates an Elastic IP address with an instance or a network interface.YN
AssociateCapacityReservationBillingOwnerInitiates a request to assign billing of the unused capacity of a shared Capacity Reservation to a consumer account that is consolidated under the same Amazon Web Services organizations payer account.NN
AssociateClientVpnTargetNetworkAssociates a target network with a Client VPN endpoint.NN
AssociateDhcpOptionsAssociates a set of DHCP options (that you've previously created) with the specified VPC, or associates no DHCP options with the VPC.YN
AssociateEnclaveCertificateIamRoleAssociates an Identity and Access Management (IAM) role with an Certificate Manager (ACM) certificate.NN
AssociateInstanceEventWindowAssociates one or more targets with an event window.YY
AssociateIpamByoasnAssociates your Autonomous System Number (ASN) with a BYOIP CIDR that you own in the same Amazon Web Services Region.NN
AssociateIpamResourceDiscoveryAssociates an IPAM resource discovery with an Amazon VPC IPAM.NN
AssociateNatGatewayAddressAssociates Elastic IP addresses (EIPs) and private IPv4 addresses with a public NAT gateway.NN
AssociateRouteServerAssociates a route server with a VPC to enable dynamic route updates.NN
AssociateRouteTableAssociates a subnet with a route table.YN
AssociateSecurityGroupVpcAssociates a security group with another VPC in the same Region.YN
AssociateSubnetCidrBlockAssociates a CIDR block with your subnet.NN
AssociateTransitGatewayMulticastDomainAssociates the specified subnets and transit gateway attachments with the specified transit gateway multicast domain.NN
AssociateTransitGatewayPolicyTableAssociates the specified transit gateway attachment with a transit gateway policy table.NN
AssociateTransitGatewayRouteTableAssociates the specified attachment with the specified transit gateway route table.YN
AssociateTrunkInterfaceAssociates a branch network interface with a trunk network interface.NN
AssociateVpcCidrBlockAssociates a CIDR block with your VPC.YN
AttachClassicLinkVpcLinks an EC2-Classic instance to a ClassicLink-enabled VPC through one or more of the VPC's security groups.NY
AttachImageWatermarkAttaches a watermark to a non-public AMI.NN
AttachInternetGatewayAttaches an Internet gateway to a VPC, enabling connectivity between the Internet and the VPC.YY
AttachNetworkInterfaceAttaches a network interface to an instance.YN
AttachVerifiedAccessTrustProviderAttaches the specified Amazon Web Services Verified Access trust provider to the specified Amazon Web Services Verified Access instance.NN
AttachVolumeAttaches an Amazon EBS volume to a running or stopped instance and exposes it to the instance with the specified device name.YN
AttachVpnGatewayAttaches a virtual private gateway to a VPC.YN
AuthorizeClientVpnIngressAdds an ingress authorization rule to a Client VPN endpoint.NN
BundleInstanceBundles an Amazon instance store-backed Windows instance.NY
CancelBundleTaskCancels a bundling operation for an instance store-backed Windows instance.YN
CancelCapacityReservationCancels the specified Capacity Reservation, releases the reserved capacity, and changes the Capacity Reservation's state to cancelled.YN
CancelCapacityReservationFleetsCancels one or more Capacity Reservation Fleets.YN
CancelConversionTaskCancels an active conversion task.YN
CancelDeclarativePoliciesReportCancels the generation of an account status report.YN
CancelExportTaskCancels an active export task.YN
CancelImageLaunchPermissionRemoves your Amazon Web Services account from the launch permissions for the specified AMI.YN
CancelImportTaskCancels an in-process import virtual machine or import snapshot task.YN
CancelReservedInstancesListingCancels the specified Reserved Instance listing in the Reserved Instance Marketplace.YN
CancelSpotFleetRequestsCancels the specified Spot fleet requests.YN
CancelSpotInstanceRequestsCancels one or more Spot Instance requests.YY
ConfirmProductInstanceDetermines whether a product code is associated with an instance.NY
CopyFpgaImageCopies the specified Amazon FPGA Image (AFI) to the current Region.NY
CopyImageInitiates the copy of an AMI from the specified source region to the region in which the request was made.YY
CopySnapshotCopies a point-in-time snapshot of an Amazon EBS volume and stores it in Amazon S3.YN
CopyVolumesCreates a crash-consistent, point-in-time copy of an existing Amazon EBS volume within the same Availability Zone.NN
CreateCapacityManagerDataExportCreates a new data export configuration for EC2 Capacity Manager.NN
CreateCapacityReservationCreates a new Capacity Reservation with the specified attributes.NN
CreateCapacityReservationBySplittingCreate a new Capacity Reservation by splitting the capacity of the source Capacity Reservation.NN
CreateCapacityReservationCancellationQuoteGenerates a cancellation quote for a future-dated Capacity Reservation that is within its commitment duration.NN
CreateCapacityReservationFleetCreates a Capacity Reservation Fleet.NN
CreateCarrierGatewayCreates a carrier gateway.NN
CreateClientVpnEndpointCreates a Client VPN endpoint.NN
CreateClientVpnRouteAdds a route to a network to a Client VPN endpoint.NN
CreateCoipCidrCreates a range of customer-owned IP addresses.NN
CreateCoipPoolCreates a pool of customer-owned IP (CoIP) addresses.NN
CreateCustomerGatewayProvides information to AWS about your VPN customer gateway device.YY
CreateDefaultSubnetCreates a default subnet with a size /20 IPv4 CIDR block in the specified Availability Zone in your default VPC.NN
CreateDefaultVpcCreates a default VPC with a size /16 IPv4 CIDR block and a default subnet in each Availability Zone.YN
CreateDelegateMacVolumeOwnershipTaskDelegates ownership of the Amazon EBS root volume for an Apple silicon Mac instance to an administrative user.NN
CreateDhcpOptionsCreates a set of DHCP options for your VPC.YN
CreateEgressOnlyInternetGateway[IPv6 only] Creates an egress-only internet gateway for your VPC.YN
CreateFleetCreates an EC2 Fleet that contains the configuration information for On-Demand Instances and Spot Instances.NN
CreateFlowLogsCreates one or more flow logs to capture IP traffic for a specific network interface, subnet, or VPC.YN
CreateFpgaImageCreates an Amazon FPGA Image (AFI) from the specified design checkpoint (DCP).NY
CreateImageCreates an Amazon EBS-backed AMI from an Amazon EBS-backed instance that is either running or stopped.YY
CreateImageUsageReportCreates a report that shows how your image is used across other Amazon Web Services accounts.NN
CreateInstanceConnectEndpointCreates an EC2 Instance Connect Endpoint.NN
CreateInstanceEventWindowCreates an event window in which scheduled events for the associated Amazon EC2 instances can run.YY
CreateInternetGatewayCreates an Internet gateway for use with a VPC.YY
CreateInterruptibleCapacityReservationAllocationCreates an interruptible Capacity Reservation by specifying the number of unused instances you want to allocate from your source reservation.NN
CreateIpamCreate an IPAM.YN
CreateIpamExternalResourceVerificationTokenCreate a verification token.NN
CreateIpamPolicyCreates an IPAM policy.NN
CreateIpamPoolCreate an IP address pool for Amazon VPC IP Address Manager (IPAM).YN
CreateIpamPrefixListResolverCreates an IPAM prefix list resolver.NN
CreateIpamPrefixListResolverTargetCreates an IPAM prefix list resolver target.NN
CreateIpamResourceDiscoveryCreates an IPAM resource discovery.YN
CreateIpamScopeCreate an IPAM scope.YN
CreateLaunchTemplateCreates a launch template.YY
CreateLaunchTemplateVersionCreates a new version of a launch template.YN
CreateLocalGatewayRouteCreates a static route for the specified local gateway route table.NN
CreateLocalGatewayRouteTableCreates a local gateway route table.NN
CreateLocalGatewayRouteTableVirtualInterfaceGroupAssociationCreates a local gateway route table virtual interface group association.NN
CreateLocalGatewayRouteTableVpcAssociationAssociates the specified VPC with the specified local gateway route table.NN
CreateLocalGatewayVirtualInterfaceCreate a virtual interface for a local gateway.NN
CreateLocalGatewayVirtualInterfaceGroupCreate a local gateway virtual interface group.NN
CreateMacSystemIntegrityProtectionModificationTaskCreates a System Integrity Protection (SIP) modification task to configure the SIP settings for an x86 Mac instance or Apple silicon Mac instance.NN
CreateManagedPrefixListCreates a managed prefix list.YN
CreateNatGatewayCreates a NAT gateway in the specified subnet.YY
CreateNetworkInsightsAccessScopeCreates a Network Access Scope.YN
CreateNetworkInsightsPathCreates a path to analyze for reachability.YN
CreateNetworkInterfaceCreates a network interface in the specified subnet.YN
CreateNetworkInterfacePermissionGrants an Amazon Web Services-authorized account permission to attach the specified network interface to an instance in their account.YN
CreatePlacementGroupCreates a placement group that you launch cluster instances into.YN
CreatePublicIpv4PoolCreates a public IPv4 address pool.NN
CreateReplaceRootVolumeTaskReplaces the EBS-backed root volume for a running instance with a new volume that is restored to the original root volume's launch state, that is restored to a specific snapshot taken from the original root volume, or that is restored from.YN
CreateReservedInstancesListingCreates a listing for Amazon EC2 Reserved Instances to be sold in the Reserved Instance Marketplace.NN
CreateRestoreImageTaskStarts a task that restores an AMI from an Amazon S3 object that was previously created by using CreateStoreImageTask.NY
CreateRouteServerCreates a new route server to manage dynamic routing in a VPC.NN
CreateRouteServerEndpointCreates a new endpoint for a route server in a specified subnet.NN
CreateRouteServerPeerCreates a new BGP peer for a specified route server endpoint.NN
CreateSecondaryNetworkCreates a secondary network.NN
CreateSecondarySubnetCreates a secondary subnet in a secondary network.NN
CreateSnapshotCreates a snapshot of an Amazon EBS volume and stores it in Amazon S3.YN
CreateSnapshotsCreates crash-consistent snapshots of multiple EBS volumes attached to an Amazon EC2 instance.YN
CreateSpotDatafeedSubscriptionCreates a datafeed for Spot Instances, enabling you to view Spot Instance usage logs.NN
CreateSubnetCreates a subnet in an existing VPC.YN
CreateSubnetCidrReservationCreates a subnet CIDR reservation.YN
CreateTagsAdds or overwrites one or more tags for the specified EC2 resource or resources.YN
CreateTrafficMirrorFilterCreates a Traffic Mirror filter.YY
CreateTrafficMirrorFilterRuleCreates a Traffic Mirror filter rule.YY
CreateTrafficMirrorTargetCreates a target for your Traffic Mirror session.YY
CreateTransitGatewayCreates a transit gateway.YN
CreateTransitGatewayConnectCreates a Connect attachment from a specified transit gateway attachment.NN
CreateTransitGatewayConnectPeerCreates a Connect peer for a specified transit gateway Connect attachment between a transit gateway and an appliance.NN
CreateTransitGatewayMeteringPolicyCreates a metering policy for a transit gateway to track and measure network traffic.NN
CreateTransitGatewayMeteringPolicyEntryCreates an entry in a transit gateway metering policy to define traffic measurement rules.NN
CreateTransitGatewayMulticastDomainCreates a multicast domain using the specified transit gateway.NN
CreateTransitGatewayPeeringAttachmentRequests a transit gateway peering attachment between the specified transit gateway (requester) and a peer transit gateway (accepter).NN
CreateTransitGatewayPolicyTableCreates a transit gateway policy table.NN
CreateTransitGatewayPrefixListReferenceCreates a reference (route) to a prefix list in a specified transit gateway route table.NN
CreateTransitGatewayRouteCreates a static route for the specified transit gateway route table.YN
CreateTransitGatewayRouteTableCreates a route table for the specified transit gateway.YN
CreateTransitGatewayRouteTableAnnouncementAdvertises a new transit gateway route table.NN
CreateTransitGatewayVpcAttachmentAttaches the specified VPC to the specified transit gateway.YN
CreateVerifiedAccessEndpointAn Amazon Web Services Verified Access endpoint is where you define your application along with an optional endpoint-level access policy.NN
CreateVerifiedAccessGroupAn Amazon Web Services Verified Access group is a collection of Amazon Web Services Verified Access endpoints who's associated applications have similar security requirements.NN
CreateVerifiedAccessInstanceAn Amazon Web Services Verified Access instance is a regional entity that evaluates application requests and grants access only when your security requirements are met.NN
CreateVerifiedAccessTrustProviderA trust provider is a third-party entity that creates, maintains, and manages identity information for users and devices.NN
CreateVolumeCreates an Amazon EBS volume that can be attached to an instance in the same Availability Zone.YN
CreateVpcCreates a VPC with the specified CIDR block.YY
CreateVpcBlockPublicAccessExclusionCreate a VPC Block Public Access (BPA) exclusion.NN
CreateVpcEncryptionControlCreates a VPC Encryption Control configuration for a specified VPC.NN
CreateVpcEndpointCreates a VPC endpoint for a specified AWS service.YN
CreateVpcEndpointConnectionNotificationCreates a connection notification for a specified VPC endpoint or VPC endpoint service.NN
CreateVpcEndpointServiceConfigurationCreates a VPC endpoint service to which service consumers (Amazon Web Services accounts, users, and IAM roles) can connect.NN
CreateVpcPeeringConnectionRequests a VPC peering connection between two VPCs: a requester VPC that you own and a peer VPC with which to create the connection.YN
CreateVpnConcentratorCreates a VPN concentrator that aggregates multiple VPN connections to a transit gateway.NN
CreateVpnConnectionCreates a VPN connection between an existing virtual private gateway and a VPN customer gateway.YN
CreateVpnConnectionRouteCreates a static route associated with a VPN connection between an existing virtual private gateway and a VPN customer gateway.NN
CreateVpnGatewayCreates a virtual private gateway.YN
DeleteCapacityManagerDataExportDeletes an existing Capacity Manager data export configuration.YN
DeleteCarrierGatewayDeletes a carrier gateway.YN
DeleteClientVpnEndpointDeletes the specified Client VPN endpoint.YN
DeleteClientVpnRouteDeletes a route from a Client VPN endpoint.YN
DeleteCoipCidrDeletes a range of customer-owned IP addresses.YN
DeleteCoipPoolDeletes a pool of customer-owned IP (CoIP) addresses.YN
DeleteCustomerGatewayDeletes the specified customer gateway.YY
DeleteDhcpOptionsDeletes the specified set of DHCP options.YN
DeleteEgressOnlyInternetGatewayDeletes an egress-only internet gateway.YN
DeleteFleetsDeletes the specified EC2 Fleet request.YN
DeleteFpgaImageDeletes the specified Amazon FPGA Image (AFI).YN
DeleteImageUsageReportDeletes the specified image usage report.YN
DeleteInstanceConnectEndpointDeletes the specified EC2 Instance Connect Endpoint.YN
DeleteInstanceEventWindowDeletes the specified event window.YY
DeleteInternetGatewayDeletes the specified Internet gateway.YY
DeleteIpamDelete an IPAM.YN
DeleteIpamExternalResourceVerificationTokenDelete a verification token.YN
DeleteIpamPolicyDeletes an IPAM policy.YN
DeleteIpamPoolDelete an IPAM pool.YN
DeleteIpamPrefixListResolverDeletes an IPAM prefix list resolver.YN
DeleteIpamPrefixListResolverTargetDeletes an IPAM prefix list resolver target.YN
DeleteIpamResourceDiscoveryDeletes an IPAM resource discovery.YN
DeleteIpamScopeDelete the scope for an IPAM.YN
DeleteKeyPairDeletes the specified key pair, by removing the public key from Amazon EC2.YN
DeleteLaunchTemplateDeletes a launch template.YN
DeleteLaunchTemplateVersionsDeletes one or more versions of a launch template.YN
DeleteLocalGatewayRouteDeletes the specified route from the specified local gateway route table.YN
DeleteLocalGatewayRouteTableDeletes a local gateway route table.YN
DeleteLocalGatewayRouteTableVirtualInterfaceGroupAssociationDeletes a local gateway route table virtual interface group association.YN
DeleteLocalGatewayRouteTableVpcAssociationDeletes the specified association between a VPC and local gateway route table.YN
DeleteLocalGatewayVirtualInterfaceDeletes the specified local gateway virtual interface.YN
DeleteLocalGatewayVirtualInterfaceGroupDelete the specified local gateway interface group.YN
DeleteManagedPrefixListDeletes the specified managed prefix list.YN
DeleteNatGatewayDeletes the specified NAT gateway.YN
DeleteNetworkInsightsAccessScopeDeletes the specified Network Access Scope.YN
DeleteNetworkInsightsAccessScopeAnalysisDeletes the specified Network Access Scope analysis.YN
DeleteNetworkInsightsAnalysisDeletes the specified network insights analysis.YN
DeleteNetworkInsightsPathDeletes the specified path.YN
DeleteNetworkInterfaceDeletes the specified network interface.YN
DeleteNetworkInterfacePermissionDeletes a permission for a network interface.YN
DeletePlacementGroupDeletes the specified placement group.YN
DeletePublicIpv4PoolDelete a public IPv4 pool.YN
DeleteQueuedReservedInstancesDeletes the queued purchases for the specified Reserved Instances.YN
DeleteRouteServerDeletes the specified route server.YN
DeleteRouteServerEndpointDeletes the specified route server endpoint.YN
DeleteRouteServerPeerDeletes the specified BGP peer from a route server.YN
DeleteSecondaryNetworkDeletes a secondary network.YN
DeleteSecondarySubnetDeletes a secondary subnet.YN
DeleteSecurityGroupDeletes a security group.YY
DeleteSnapshotDeletes the specified snapshot.YN
DeleteSpotDatafeedSubscriptionDeletes the datafeed for Spot Instances.YN
DeleteSubnetDeletes the specified subnet.YN
DeleteSubnetCidrReservationDeletes a subnet CIDR reservation.YN
DeleteTagsDeletes the specified set of tags from the specified set of resources.YN
DeleteTrafficMirrorFilterDeletes the specified Traffic Mirror filter.YY
DeleteTrafficMirrorFilterRuleDeletes the specified Traffic Mirror rule.YY
DeleteTrafficMirrorSessionDeletes the specified Traffic Mirror session.YY
DeleteTrafficMirrorTargetDeletes the specified Traffic Mirror target.YY
DeleteTransitGatewayDeletes the specified transit gateway.YN
DeleteTransitGatewayClientVpnAttachmentDeletes a Transit Gateway attachment for a Client VPN endpoint.YN
DeleteTransitGatewayConnectDeletes the specified Connect attachment.YN
DeleteTransitGatewayConnectPeerDeletes the specified Connect peer.YN
DeleteTransitGatewayMeteringPolicyDeletes a transit gateway metering policy.YN
DeleteTransitGatewayMeteringPolicyEntryDeletes an entry from a transit gateway metering policy.YN
DeleteTransitGatewayMulticastDomainDeletes the specified transit gateway multicast domain.YN
DeleteTransitGatewayPeeringAttachmentDeletes a transit gateway peering attachment.YN
DeleteTransitGatewayPolicyTableDeletes the specified transit gateway policy table.YN
DeleteTransitGatewayPrefixListReferenceDeletes a reference (route) to a prefix list in a specified transit gateway route table.YN
DeleteTransitGatewayRouteDeletes the specified route from the specified transit gateway route table.YN
DeleteTransitGatewayRouteTableDeletes the specified transit gateway route table.YN
DeleteTransitGatewayRouteTableAnnouncementAdvertises to the transit gateway that a transit gateway route table is deleted.YN
DeleteTransitGatewayVpcAttachmentDeletes the specified VPC attachment.YN
DeleteVerifiedAccessEndpointDelete an Amazon Web Services Verified Access endpoint.YN
DeleteVerifiedAccessGroupDelete an Amazon Web Services Verified Access group.YN
DeleteVerifiedAccessInstanceDelete an Amazon Web Services Verified Access instance.YN
DeleteVerifiedAccessTrustProviderDelete an Amazon Web Services Verified Access trust provider.YN
DeleteVolumeDeletes the specified Amazon EBS volume.YN
DeleteVpcDeletes the specified VPC.YY
DeleteVpcBlockPublicAccessExclusionDelete a VPC Block Public Access (BPA) exclusion.YN
DeleteVpcEncryptionControlDeletes a VPC Encryption Control configuration.YN
DeleteVpcEndpointConnectionNotificationsDeletes the specified VPC endpoint connection notifications.YN
DeleteVpcEndpointsDeletes one or more specified VPC endpoints.YN
DeleteVpcEndpointServiceConfigurationsDeletes the specified VPC endpoint service configurations.YN
DeleteVpcPeeringConnectionDeletes a VPC peering connection.YN
DeleteVpnConcentratorDeletes the specified VPN concentrator.YN
DeleteVpnConnectionDeletes the specified VPN connection.YN
DeleteVpnConnectionRouteDeletes the specified static route associated with a VPN connection between an existing virtual private gateway and a VPN customer gateway.YN
DeleteVpnGatewayDeletes the specified virtual private gateway.YN
DeprovisionByoipCidrReleases the specified address range that you provisioned for use with your Amazon Web Services resources through bring your own IP addresses (BYOIP) and deletes the corresponding address pool.NN
DeprovisionIpamByoasnDeprovisions your Autonomous System Number (ASN) from your Amazon Web Services account.NN
DeprovisionIpamPoolCidrDeprovision a CIDR provisioned from an IPAM pool.YN
DeprovisionPublicIpv4PoolCidrDeprovision a CIDR from a public IPv4 pool.NN
DeregisterImageDeregisters the specified AMI.YN
DeregisterInstanceEventNotificationAttributesDeregisters tag keys to prevent tags that have the specified tag keys from being included in scheduled event notifications for resources in the Region.YY
DeregisterTransitGatewayMulticastGroupMembersDeregisters the specified members (network interfaces) from the transit gateway multicast group.YN
DeregisterTransitGatewayMulticastGroupSourcesDeregisters the specified sources (network interfaces) from the transit gateway multicast group.YN
DescribeAccountAttributesDescribes the specified attribute of your AWS account.YN
DescribeAddressesDescribes one or more of your Elastic IP addresses.YN
DescribeAddressesAttributeDescribes the attributes of the specified Elastic IP addresses.YN
DescribeAddressTransfersDescribes an Elastic IP address transfer.YN
DescribeAggregateIdFormatDescribes the longer ID format settings for all resource types in a specific Region.YN
DescribeAvailabilityZonesDescribes one or more of the Availability Zones that are available to you.YN
DescribeAwsNetworkPerformanceMetricSubscriptionsDescribes the current Infrastructure Performance metric subscriptions.YN
DescribeBundleTasksDescribes one or more of your bundling tasks.YN
DescribeByoipCidrsDescribes the IP address ranges that were provisioned for use with Amazon Web Services resources through through bring your own IP addresses (BYOIP).YN
DescribeCapacityBlockExtensionHistoryDescribes the events for the specified Capacity Block extension during the specified time.YN
DescribeCapacityBlockExtensionOfferingsDescribes Capacity Block extension offerings available for purchase in the Amazon Web Services Region that you're currently using.YN
DescribeCapacityBlockOfferingsDescribes Capacity Block offerings available for purchase in the Amazon Web Services Region that you're currently using.YN
DescribeCapacityBlocksDescribes details about Capacity Blocks in the Amazon Web Services Region that you're currently using.YN
DescribeCapacityBlockStatusDescribes the availability of capacity for the specified Capacity blocks, or all of your Capacity Blocks.YN
DescribeCapacityManagerDataExportsDescribes one or more Capacity Manager data export configurations.YN
DescribeCapacityReservationBillingRequestsDescribes a request to assign the billing of the unused capacity of a Capacity Reservation.YN
DescribeCapacityReservationCancellationQuotesDescribes one or more Capacity Reservation cancellation quotes.YN
DescribeCapacityReservationFleetsDescribes one or more Capacity Reservation Fleets.YN
DescribeCapacityReservationsDescribes one or more of your Capacity Reservations.YN
DescribeCapacityReservationTopologyDescribes a tree-based hierarchy that represents the physical host placement of your pending or active Capacity Reservations within an Availability Zone or Local Zone.YN
DescribeClassicLinkInstancesDescribes one or more of your linked EC2-Classic instances.YN
DescribeClientVpnAuthorizationRulesDescribes the authorization rules for a specified Client VPN endpoint.YN
DescribeClientVpnConnectionsDescribes active client connections and connections that have been terminated within the last 60 minutes for the specified Client VPN endpoint.YN
DescribeClientVpnEndpointsDescribes one or more Client VPN endpoints in the account.YN
DescribeClientVpnTargetNetworksDescribes the target networks associated with the specified Client VPN endpoint.YN
DescribeCoipPoolsDescribes the specified customer-owned address pools or all of your customer-owned address pools.YN
DescribeConversionTasksDescribes one or more of your conversion tasks.YN
DescribeCustomerGatewaysDescribes one or more of your VPN customer gateways.YN
DescribeDeclarativePoliciesReportsDescribes the metadata of an account status report, including the status of the report.YN
DescribeEgressOnlyInternetGatewaysDescribes your egress-only internet gateways.YN
DescribeElasticGpusAmazon Elastic Graphics reached end of life on January 8, 2024.YN
DescribeExportImageTasksDescribes the specified export image tasks or all of your export image tasks.YN
DescribeExportTasksDescribes one or more of your export tasks.YN
DescribeFastLaunchImagesDescribe details for Windows AMIs that are configured for Windows fast launch.YN
DescribeFastSnapshotRestoresDescribes the state of fast snapshot restores for your snapshots.YN
DescribeFleetHistoryDescribes the events for the specified EC2 Fleet during the specified time.YN
DescribeFleetInstancesDescribes the running instances for the specified EC2 Fleet.YN
DescribeFleetsDescribes the specified EC2 Fleet or all of your EC2 Fleets.YN
DescribeFlowLogsDescribes one or more flow logs.YN
DescribeFpgaImageAttributeDescribes the specified attribute of the specified Amazon FPGA Image (AFI).YN
DescribeFpgaImagesDescribes the Amazon FPGA Images (AFIs) available to you.YN
DescribeHostReservationOfferingsDescribes the Dedicated Host Reservations that are available to purchase.YN
DescribeHostReservationsDescribes Dedicated Host Reservations which are associated with Dedicated Hosts in your account.YN
DescribeHostsDescribes one or more of your Dedicated hosts.YN
DescribeIamInstanceProfileAssociationsDescribes your IAM instance profile associations.YN
DescribeIdentityIdFormatDescribes the ID format settings for resources for the specified IAM user, IAM role, or root user.YN
DescribeIdFormatDescribes the ID format settings for your resources on a per-region basis, for example, to view which resource types are enabled for longer IDs.YN
DescribeImageAttributeDescribes the specified attribute of the specified AMI.YN
DescribeImageReferencesDescribes your Amazon Web Services resources that are referencing the specified images.YN
DescribeImageUsageReportEntriesDescribes the entries in image usage reports, showing how your images are used across other Amazon Web Services accounts.YN
DescribeImageUsageReportsDescribes the configuration and status of image usage reports, filtered by report IDs or image IDs.YN
DescribeImportImageTasksDisplays details about an import virtual machine or import snapshot tasks that are already created.YN
DescribeImportSnapshotTasksDisplays details about an import snapshot tasks that is already created.YN
DescribeInstanceConnectEndpointsDescribes the specified EC2 Instance Connect Endpoints or all EC2 Instance Connect Endpoints.YN
DescribeInstanceCreditSpecificationsDescribes the credit option for CPU usage of the specified burstable performance instances.YN
DescribeInstanceEventNotificationAttributesDescribes the tag keys that are registered to appear in scheduled event notifications for resources in the current Region.YN
DescribeInstanceEventWindowsDescribes the specified event windows or all event windows.YN
DescribeInstanceImageMetadataDescribes the AMI that was used to launch an instance, even if the AMI is deprecated, deregistered, made private (no longer public or shared with your account), or not allowed.YN
DescribeInstanceSqlHaHistoryStatesDescribes the historical SQL Server High Availability states for Amazon EC2 instances that are enabled for Amazon EC2 High Availability for SQL Server monitoring.YN
DescribeInstanceSqlHaStatesDescribes the SQL Server High Availability states for Amazon EC2 instances that are enabled for Amazon EC2 High Availability for SQL Server monitoring.YN
DescribeInstanceStatusDescribes the status of one or more instances, including any scheduled events.YN
DescribeInstanceTopologyDescribes a tree-based hierarchy that represents the physical host placement of your EC2 instances within an Availability Zone or Local Zone.YN
DescribeInstanceTypeOfferingsLists the instance types that are offered for the specified location.YN
DescribeInstanceTypesDescribes the specified instance types.YN
DescribeInternetGatewaysDescribes one or more of your Internet gateways.YN
DescribeIpamByoasnDescribes your Autonomous System Numbers (ASNs), their provisioning statuses, and the BYOIP CIDRs with which they are associated.YN
DescribeIpamExternalResourceVerificationTokensDescribe verification tokens.YN
DescribeIpamPoliciesDescribes one or more IPAM policies.YN
DescribeIpamPoolAllocationsDescribes IPAM pool allocations.YN
DescribeIpamPoolsGet information about your IPAM pools.YN
DescribeIpamPrefixListResolversDescribes one or more IPAM prefix list resolvers.YN
DescribeIpamPrefixListResolverTargetsDescribes one or more IPAM prefix list resolver Targets.YN
DescribeIpamResourceDiscoveriesDescribes IPAM resource discoveries.YN
DescribeIpamResourceDiscoveryAssociationsDescribes resource discovery association with an Amazon VPC IPAM.YN
DescribeIpamsGet information about your IPAM pools.YN
DescribeIpamScopesGet information about your IPAM scopes.YN
DescribeIpv6PoolsDescribes your IPv6 address pools.YN
DescribeKeyPairsDescribes one or more of your key pairs.YN
DescribeLaunchTemplatesDescribes one or more launch templates.YN
DescribeLaunchTemplateVersionsDescribes one or more versions of a specified launch template.YN
DescribeLocalGatewayRouteTablesDescribes one or more local gateway route tables.YN
DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociationsDescribes the associations between virtual interface groups and local gateway route tables.YN
DescribeLocalGatewayRouteTableVpcAssociationsDescribes the specified associations between VPCs and local gateway route tables.YN
DescribeLocalGatewaysDescribes one or more local gateways.YN
DescribeLocalGatewayVirtualInterfaceGroupsDescribes the specified local gateway virtual interface groups.YN
DescribeLocalGatewayVirtualInterfacesDescribes the specified local gateway virtual interfaces.YN
DescribeLockedSnapshotsDescribes the lock status for a snapshot.YN
DescribeMacHostsDescribes the specified EC2 Mac Dedicated Host or all of your EC2 Mac Dedicated Hosts.YN
DescribeMacModificationTasksDescribes a System Integrity Protection (SIP) modification task or volume ownership delegation task for an Amazon EC2 Mac instance.YN
DescribeManagedPrefixListsDescribes your managed prefix lists and any Amazon Web Services-managed prefix lists.YN
DescribeMovingAddressesDescribes your Elastic IP addresses that are being moved to the EC2-VPC platform, or that are being restored to the EC2-Classic platform.YN
DescribeNatGatewaysDescribes one or more of the your NAT gateways.YN
DescribeNetworkAclsDescribes one or more of your network ACLs.YN
DescribeNetworkInsightsAccessScopeAnalysesDescribes the specified Network Access Scope analyses.YN
DescribeNetworkInsightsAccessScopesDescribes the specified Network Access Scopes.YN
DescribeNetworkInsightsAnalysesDescribes one or more of your network insights analyses.YN
DescribeNetworkInsightsPathsDescribes one or more of your paths.YN
DescribeNetworkInterfaceAttributeDescribes a network interface attribute.YN
DescribeNetworkInterfacePermissionsDescribes the permissions for your network interfaces.YN
DescribeNetworkInterfacesDescribes one or more of your network interfaces.YN
DescribeOutpostLagsDescribes the Outposts link aggregation groups (LAGs).YN
DescribePlacementGroupsDescribes one or more of your placement groups.YN
DescribePrefixListsDescribes available AWS services in a prefix list format, which includes the prefix list name and prefix list ID of the service and the IP address range for the service.YN
DescribePrincipalIdFormatDescribes the ID format settings for the root user and all IAM roles and IAM users that have explicitly specified a longer ID (17-character ID) preference.YN
DescribePublicIpv4PoolsDescribes the specified IPv4 address pools.YN
DescribeReplaceRootVolumeTasksDescribes a root volume replacement task.YN
DescribeReservedInstancesDescribes one or more of the Reserved Instances that you purchased.YN
DescribeReservedInstancesListingsDescribes your account's Reserved Instance listings in the Reserved Instance Marketplace.YN
DescribeReservedInstancesModificationsDescribes the modifications made to your Reserved Instances.YN
DescribeReservedInstancesOfferingsDescribes Reserved Instance offerings that are available for purchase.YN
DescribeRouteServerEndpointsDescribes one or more route server endpoints.YN
DescribeRouteServerPeersDescribes one or more route server peers.YN
DescribeRouteServersDescribes one or more route servers.YN
DescribeRouteTablesDescribes one or more of your route tables.YN
DescribeScheduledInstanceAvailabilityFinds available schedules that meet the specified criteria.YN
DescribeScheduledInstancesDescribes one or more of your Scheduled Instances.YN
DescribeSecondaryInterfacesDescribes one or more of your secondary interfaces.YN
DescribeSecondaryNetworksDescribes one or more secondary networks.YN
DescribeSecondarySubnetsDescribes one or more of your secondary subnets.YN
DescribeSecurityGroupReferences[EC2-VPC only] Describes the VPCs on the other side of a VPC peering connection that are referencing the security groups you've specified in this request.YY
DescribeSecurityGroupRulesDescribes one or more of your security group rules.YY
DescribeSecurityGroupVpcAssociationsDescribes security group VPC associations made with AssociateSecurityGroupVpc.YN
DescribeServiceLinkVirtualInterfacesDescribes the Outpost service link virtual interfaces.YN
DescribeSnapshotsDescribes one or more of the Amazon EBS snapshots available to you.YN
DescribeSpotDatafeedSubscriptionDescribes the datafeed for Spot Instances.YN
DescribeSpotFleetInstancesDescribes the running instances for the specified Spot fleet.YN
DescribeSpotFleetRequestHistoryDescribes the events for the specified Spot fleet request during the specified time.YN
DescribeSpotFleetRequestsDescribes your Spot fleet requests.YN
DescribeSpotInstanceRequestsDescribes the Spot Instance requests that belong to your account.YN
DescribeSpotPriceHistoryDescribes the Spot Price history.YN
DescribeStaleSecurityGroups[EC2-VPC only] Describes the stale security group rules for security groups in a specified VPC.YN
DescribeStoreImageTasksDescribes the progress of the AMI store tasks.YN
DescribeSubnetsDescribes one or more of your subnets.YY
DescribeTagsDescribes one or more of the tags for your EC2 resources.YN
DescribeTrafficMirrorFilterRulesDescribe traffic mirror filters that determine the traffic that is mirrored.YN
DescribeTrafficMirrorFiltersDescribes one or more Traffic Mirror filters.YN
DescribeTrafficMirrorSessionsDescribes one or more Traffic Mirror sessions.YN
DescribeTrafficMirrorTargetsInformation about one or more Traffic Mirror targets.YN
DescribeTransitGatewayAttachmentsDescribes one or more attachments between resources and transit gateways.YN
DescribeTransitGatewayConnectPeersDescribes one or more Connect peers.YN
DescribeTransitGatewayConnectsDescribes one or more Connect attachments.YN
DescribeTransitGatewayMeteringPoliciesDescribes one or more transit gateway metering policies.YN
DescribeTransitGatewayPeeringAttachmentsDescribes your transit gateway peering attachments.YN
DescribeTransitGatewayPolicyTablesDescribes one or more transit gateway route policy tables.YN
DescribeTransitGatewayRouteTableAnnouncementsDescribes one or more transit gateway route table advertisements.YN
DescribeTransitGatewayRouteTablesDescribes one or more transit gateway route tables.YN
DescribeTransitGatewaysDescribes one or more transit gateways.YN
DescribeTransitGatewayVpcAttachmentsDescribes one or more VPC attachments.YN
DescribeTrunkInterfaceAssociationsDescribes one or more network interface trunk associations.YN
DescribeVerifiedAccessEndpointsDescribes the specified Amazon Web Services Verified Access endpoints.YN
DescribeVerifiedAccessGroupsDescribes the specified Verified Access groups.YN
DescribeVerifiedAccessInstanceLoggingConfigurationsDescribes the specified Amazon Web Services Verified Access instances.YN
DescribeVerifiedAccessInstancesDescribes the specified Amazon Web Services Verified Access instances.YN
DescribeVerifiedAccessTrustProvidersDescribes the specified Amazon Web Services Verified Access trust providers.YN
DescribeVolumeAttributeDescribes the specified attribute of the specified volume.YN
DescribeVolumeStatusDescribes the status of the specified volumes.YN
DescribeVpcAttributeDescribes the specified attribute of the specified VPC.YN
DescribeVpcBlockPublicAccessExclusionsDescribe VPC Block Public Access (BPA) exclusions.YN
DescribeVpcBlockPublicAccessOptionsDescribe VPC Block Public Access (BPA) options.YN
DescribeVpcClassicLinkDescribes the ClassicLink status of one or more VPCs.YN
DescribeVpcClassicLinkDnsSupportDescribes the ClassicLink DNS support status of one or more VPCs.YN
DescribeVpcEncryptionControlsDescribes one or more VPC Encryption Control configurations.YN
DescribeVpcEndpointAssociationsDescribes the VPC resources, VPC endpoint services, Amazon Lattice services, or service networks associated with the VPC endpoint.YN
DescribeVpcEndpointConnectionsDescribes the VPC endpoint connections to your VPC endpoint services, including any endpoints that are pending your acceptance.YN
DescribeVpcEndpointsDescribes one or more of your VPC endpoints.YN
DescribeVpcEndpointServiceConfigurationsDescribes the VPC endpoint service configurations in your account (your services).YN
DescribeVpcEndpointServicePermissionsDescribes the principals (service consumers) that are permitted to discover your VPC endpoint service.YN
DescribeVpcEndpointServicesDescribes all supported AWS services that can be specified when creating a VPC endpoint.YN
DescribeVpcPeeringConnectionsDescribes one or more of your VPC peering connections.YN
DescribeVpnConcentratorsDescribes one or more of your VPN concentrators.YN
DescribeVpnConnectionsDescribes one or more of your VPN connections.YN
DescribeVpnGatewaysDescribes one or more of your virtual private gateways.YN
DetachClassicLinkVpcUnlinks (detaches) a linked EC2-Classic instance from a VPC.YY
DetachImageWatermarkRemoves a watermark from the specified AMI.YN
DetachInternetGatewayDetaches an Internet gateway from a VPC, disabling connectivity between the Internet and the VPC.YY
DetachNetworkInterfaceDetaches a network interface from an instance.YN
DetachVerifiedAccessTrustProviderDetaches the specified Amazon Web Services Verified Access trust provider from the specified Amazon Web Services Verified Access instance.YN
DetachVolumeDetaches an Amazon EBS volume from an instance.YN
DetachVpnGatewayDetaches a virtual private gateway from a VPC.YN
DisableAddressTransferDisables Elastic IP address transfer.YN
DisableAllowedImagesSettingsDisables Allowed AMIs for your account in the specified Amazon Web Services Region.YN
DisableAwsNetworkPerformanceMetricSubscriptionDisables Infrastructure Performance metric subscriptions.YN
DisableCapacityManagerDisables EC2 Capacity Manager for your account.YN
DisableFastLaunchDiscontinue Windows fast launch for a Windows AMI, and clean up existing pre-provisioned snapshots.YN
DisableFastSnapshotRestoresDisables fast snapshot restores for the specified snapshots in the specified Availability Zones.YN
DisableImageSets the AMI state to disabled and removes all launch permissions from the AMI.YN
DisableImageBlockPublicAccessDisables block public access for AMIs at the account level in the specified Amazon Web Services Region.YN
DisableImageDeprecationCancels the deprecation of the specified AMI.YN
DisableImageDeregistrationProtectionDisables deregistration protection for an AMI.YN
DisableInstanceSqlHaStandbyDetectionsDisable Amazon EC2 instances running in an SQL Server High Availability cluster from SQL Server High Availability instance standby detection monitoring.YN
DisableIpamOrganizationAdminAccountDisable the IPAM account.YN
DisableIpamPolicyDisables an IPAM policy.YN
DisableRouteServerPropagationDisables route propagation from a route server to a specified route table.YN
DisableSerialConsoleAccessDisables access to the EC2 serial console of all instances for your account.YN
DisableSnapshotBlockPublicAccessDisables the block public access for snapshots setting at the account level for the specified Amazon Web Services Region.YN
DisableTransitGatewayRouteTablePropagationDisables the specified resource attachment from propagating routes to the specified propagation route table.YN
DisableVgwRoutePropagationDisables a virtual private gateway (VGW) from propagating routes to a specified route table of a VPC.YN
DisableVpcClassicLinkDisables ClassicLink for a VPC.YY
DisableVpcClassicLinkDnsSupportDisables ClassicLink DNS support for a VPC.YN
DisassociateAddressDisassociates an Elastic IP address from the instance or network interface it's associated with.YN
DisassociateCapacityReservationBillingOwnerCancels a pending request to assign billing of the unused capacity of a Capacity Reservation to a consumer account, or revokes a request that has already been accepted.YN
DisassociateClientVpnTargetNetworkDisassociates a target network from the specified Client VPN endpoint.YN
DisassociateEnclaveCertificateIamRoleDisassociates an IAM role from an Certificate Manager (ACM) certificate.YN
DisassociateIamInstanceProfileDisassociates an IAM instance profile from a running or stopped instance.YY
DisassociateInstanceEventWindowDisassociates one or more targets from an event window.YY
DisassociateIpamByoasnRemove the association between your Autonomous System Number (ASN) and your BYOIP CIDR.YN
DisassociateIpamResourceDiscoveryDisassociates a resource discovery from an Amazon VPC IPAM.YN
DisassociateNatGatewayAddressDisassociates secondary Elastic IP addresses (EIPs) from a public NAT gateway.YN
DisassociateRouteServerDisassociates a route server from a VPC.YN
DisassociateSecurityGroupVpcDisassociates a security group from a VPC.YN
DisassociateSubnetCidrBlockDisassociates a CIDR block from a subnet.YN
DisassociateTransitGatewayMulticastDomainDisassociates the specified subnets from the transit gateway multicast domain.YN
DisassociateTransitGatewayPolicyTableRemoves the association between an an attachment and a policy table.YN
DisassociateTransitGatewayRouteTableDisassociates a resource attachment from a transit gateway route table.YN
DisassociateTrunkInterfaceRemoves an association between a branch network interface with a trunk network interface.YN
DisassociateVpcCidrBlockDisassociates a CIDR block from a VPC.YN
EnableAddressTransferEnables Elastic IP address transfer.NN
EnableAllowedImagesSettingsEnables Allowed AMIs for your account in the specified Amazon Web Services Region.YN
EnableAwsNetworkPerformanceMetricSubscriptionEnables Infrastructure Performance subscriptions.YN
EnableCapacityManagerEnables EC2 Capacity Manager for your account.NN
EnableEbsEncryptionByDefaultEnables EBS encryption by default for your account in the current Region.YN
EnableFastLaunchWhen you enable Windows fast launch for a Windows AMI, images are pre-provisioned, using snapshots to launch instances up to 65% faster.NN
EnableFastSnapshotRestoresEnables fast snapshot restores for the specified snapshots in the specified Availability Zones.YN
EnableImageRe-enables a disabled AMI.YN
EnableImageBlockPublicAccessEnables block public access for AMIs at the account level in the specified Amazon Web Services Region.YN
EnableImageDeprecationEnables deprecation of the specified AMI at the specified date and time.YN
EnableImageDeregistrationProtectionEnables deregistration protection for an AMI.NN
EnableInstanceSqlHaStandbyDetectionsEnable Amazon EC2 instances running in an SQL Server High Availability cluster for SQL Server High Availability instance standby detection monitoring.NN
EnableIpamOrganizationAdminAccountEnable an Organizations member account as the IPAM admin account.NN
EnableIpamPolicyEnables an IPAM policy.NN
EnableReachabilityAnalyzerOrganizationSharingEstablishes a trust relationship between Reachability Analyzer and Organizations.NN
EnableRouteServerPropagationDefines which route tables the route server can update with routes.NN
EnableSnapshotBlockPublicAccessEnables or modifies the block public access for snapshots setting at the account level for the specified Amazon Web Services Region.YN
EnableTransitGatewayRouteTablePropagationEnables the specified attachment to propagate routes to the specified propagation route table.YN
EnableVgwRoutePropagationEnables a virtual private gateway (VGW) to propagate routes to the specified route table of a VPC.YN
EnableVolumeIOEnables I/O operations for a volume that had I/O operations disabled because the data on the volume was potentially inconsistent.YN
EnableVpcClassicLinkEnables a VPC for ClassicLink.NY
EnableVpcClassicLinkDnsSupportEnables a VPC to support DNS hostname resolution for ClassicLink.NN
ExportClientVpnClientCertificateRevocationListDownloads the client certificate revocation list for the specified Client VPN endpoint.NN
ExportClientVpnClientConfigurationDownloads the contents of the Client VPN endpoint configuration file for the specified Client VPN endpoint.NN
ExportTransitGatewayRoutesExports routes from the specified transit gateway route table to the specified S3 bucket.NN
ExportVerifiedAccessInstanceClientConfigurationExports the client configuration for a Verified Access instance.NN
GetActiveVpnTunnelStatusReturns the currently negotiated security parameters for an active VPN tunnel, including IKE version, DH groups, encryption algorithms, and integrity algorithms.YN
GetAllowedImagesSettingsGets the current state of the Allowed AMIs setting and the list of Allowed AMIs criteria at the account level in the specified Region.YN
GetAssociatedEnclaveCertificateIamRolesReturns the IAM roles that are associated with the specified ACM (ACM) certificate.YN
GetAssociatedIpv6PoolCidrsGets information about the IPv6 CIDR block associations for a specified IPv6 address pool.YN
GetAwsNetworkPerformanceDataGets network performance data.YN
GetCapacityManagerAttributesRetrieves the current configuration and status of EC2 Capacity Manager for your account, including enablement status, Organizations access settings, and data ingestion status.YN
GetCapacityManagerMetricDataRetrieves capacity usage metrics for your EC2 resources.YN
GetCapacityManagerMetricDimensionsRetrieves the available dimension values for capacity metrics within a specified time range.YN
GetCapacityManagerMonitoredTagKeysRetrieves the tag keys that are currently being monitored by EC2 Capacity Manager.YN
GetCapacityReservationUsageGets usage information about a Capacity Reservation.YN
GetCoipPoolUsageDescribes the allocations from the specified customer-owned address pool.YN
GetConsoleOutputGets the console output for the specified instance.YN
GetConsoleScreenshotRetrieve a JPG-format screenshot of a running instance to help with troubleshooting.YN
GetDeclarativePoliciesReportSummaryRetrieves a summary of the account status report.YN
GetDefaultCreditSpecificationDescribes the default credit option for CPU usage of a burstable performance instance family.YN
GetEnabledIpamPolicyGets the enabled IPAM policy.YN
GetFlowLogsIntegrationTemplateGenerates a CloudFormation template that streamlines and automates the integration of VPC flow logs with Amazon Athena.YN
GetGroupsForCapacityReservationLists the resource groups to which a Capacity Reservation has been added.YN
GetHostReservationPurchasePreviewPreview a reservation purchase with configurations that match those of your Dedicated Host.YN
GetImageAncestryRetrieves the ancestry chain of the specified AMI, tracing its lineage back to the root AMI.YN
GetImageBlockPublicAccessStateGets the current state of block public access for AMIs at the account level in the specified Amazon Web Services Region.YN
GetInstanceMetadataDefaultsGets the default instance metadata service (IMDS) settings that are set at the account level in the specified Amazon Web Services Region.YN
GetInstanceTpmEkPubGets the public endorsement key associated with the Nitro Trusted Platform Module (NitroTPM) for the specified instance.YN
GetInstanceTypesFromInstanceRequirementsReturns a list of instance types with the specified instance attributes.YN
GetInstanceUefiDataA binary representation of the UEFI variable store.YN
GetIpamAddressHistoryRetrieve historical information about a CIDR within an IPAM scope.YN
GetIpamDiscoveredAccountsGets IPAM discovered accounts.YN
GetIpamDiscoveredPublicAddressesGets the public IP addresses that have been discovered by IPAM.YN
GetIpamDiscoveredResourceCidrsReturns the resource CIDRs that are monitored as part of a resource discovery.YN
GetIpamPolicyAllocationRulesGets the allocation rules for an IPAM policy.YN
GetIpamPolicyOrganizationTargetsGets the Amazon Web Services Organizations targets for an IPAM policy.YN
GetIpamPoolAllocationsGet a list of all the CIDR allocations in an IPAM pool.YN
GetIpamPoolCidrsGet the CIDRs provisioned to an IPAM pool.YN
GetIpamPrefixListResolverRulesRetrieves the CIDR selection rules for an IPAM prefix list resolver.YN
GetIpamPrefixListResolverVersionEntriesRetrieves the CIDR entries for a specific version of an IPAM prefix list resolver.YN
GetIpamPrefixListResolverVersionsRetrieves version information for an IPAM prefix list resolver.YN
GetIpamResourceCidrsReturns resource CIDRs managed by IPAM in a given scope.YN
GetLaunchTemplateDataRetrieves the configuration data of the specified instance.YN
GetManagedPrefixListAssociationsGets information about the resources that are associated with the specified managed prefix list.YN
GetManagedPrefixListEntriesGets information about the entries for a specified managed prefix list.YN
GetManagedResourceVisibilityRetrieves the managed resource visibility configuration for the account.YN
GetNetworkInsightsAccessScopeAnalysisFindingsGets the findings for the specified Network Access Scope analysis.YN
GetNetworkInsightsAccessScopeContentGets the content for the specified Network Access Scope.YN
GetReservedInstancesExchangeQuoteReturns details about the values and term of your specified Convertible Reserved Instances.YN
GetRouteServerAssociationsGets information about the associations for the specified route server.YN
GetRouteServerPropagationsGets information about the route propagations for the specified route server.YN
GetRouteServerRoutingDatabaseGets the routing database for the specified route server.YN
GetSecurityGroupsForVpcGets security groups that can be associated by the Amazon Web Services account making the request with network interfaces in the specified VPC.YN
GetSerialConsoleAccessStatusRetrieves the access status of your account to the EC2 serial console of all instances.YN
GetSnapshotBlockPublicAccessStateGets the current state of block public access for snapshots setting for the account and Region.YN
GetSpotPlacementScoresCalculates the Spot placement score for a Region or Availability Zone based on the specified target capacity and compute requirements.YN
GetSubnetCidrReservationsGets information about the subnet CIDR reservations.YN
GetTransitGatewayAttachmentPropagationsLists the route tables to which the specified resource attachment propagates routes.YN
GetTransitGatewayMeteringPolicyEntriesRetrieves the entries for a transit gateway metering policy.YN
GetTransitGatewayMulticastDomainAssociationsGets information about the associations for the transit gateway multicast domain.YN
GetTransitGatewayPolicyTableAssociationsGets a list of the transit gateway policy table associations.YN
GetTransitGatewayPolicyTableEntriesReturns a list of transit gateway policy table entries.YN
GetTransitGatewayPrefixListReferencesGets information about the prefix list references in a specified transit gateway route table.YN
GetTransitGatewayRouteTablePropagationsGets information about the route table propagations for the specified transit gateway route table.YN
GetVerifiedAccessEndpointPolicyGet the Verified Access policy associated with the endpoint.YN
GetVerifiedAccessEndpointTargetsGets the targets for the specified network CIDR endpoint for Verified Access.YN
GetVerifiedAccessGroupPolicyShows the contents of the Verified Access policy associated with the group.YN
GetVpcResourcesBlockingEncryptionEnforcementGets information about resources in a VPC that are blocking encryption enforcement.YN
GetVpnConnectionDeviceSampleConfigurationDownload an Amazon Web Services-provided sample configuration file to be used with the customer gateway device specified for your Site-to-Site VPN connection.YN
GetVpnConnectionDeviceTypesObtain a list of customer gateway devices for which sample configuration files can be provided.YN
GetVpnTunnelReplacementStatusGet details of available tunnel endpoint maintenance.YN
ImportClientVpnClientCertificateRevocationListUploads a client certificate revocation list to the specified Client VPN endpoint.NN
ImportImageImport single or multi-volume disk images or Amazon EBS snapshots into an Amazon Machine Image (AMI).NY
ImportInstanceCreates an import instance task using metadata from the specified disk image.NY
ImportSnapshotImport a disk into an Amazon Elastic Block Store (Amazon EBS) snapshot.NN
ImportVolumeCreates an import volume task using metadata from the specified disk image.NN
ListImagesInRecycleBinLists one or more AMIs that are currently in the Recycle Bin.YN
ListSnapshotsInRecycleBinLists one or more snapshots that are currently in the Recycle Bin.YN
ListVolumesInRecycleBinLists one or more volumes that are currently in the Recycle Bin.YN
LockSnapshotLocks an Amazon EBS snapshot in either governance or compliance mode to protect it against accidental or malicious deletions for a specific duration.YN
ModifyAddressAttributeModifies an attribute of the specified Elastic IP address.YN
ModifyAvailabilityZoneGroupChanges the opt-in status of the specified zone group for your account.YN
ModifyCapacityReservationModifies a Capacity Reservation's capacity, instance eligibility, and the conditions under which it is to be released.YN
ModifyCapacityReservationFleetModifies a Capacity Reservation Fleet.YN
ModifyClientVpnEndpointModifies the specified Client VPN endpoint.YN
ModifyDefaultCreditSpecificationModifies the default credit option for CPU usage of burstable performance instances.YN
ModifyEbsDefaultKmsKeyIdChanges the default KMS key for EBS encryption by default for your account in this Region.YN
ModifyFleetModifies the specified EC2 Fleet.YN
ModifyFpgaImageAttributeModifies the specified attribute of the specified Amazon FPGA Image (AFI).YN
ModifyHostsModify the auto-placement setting of a Dedicated host.YN
ModifyIdentityIdFormatModifies the ID format of a resource for a specified IAM user, IAM role, or the root user for an account; or all IAM users, IAM roles, and the root user for an account.YN
ModifyIdFormatModifies the ID format for the specified resource on a per-region basis.YN
ModifyInstanceCapacityReservationAttributesModifies the Capacity Reservation settings for a stopped instance.YY
ModifyInstanceConnectEndpointModifies the specified EC2 Instance Connect Endpoint.YN
ModifyInstanceCpuOptionsBy default, all vCPUs for the instance type are active when you launch an instance.YN
ModifyInstanceCreditSpecificationModifies the credit option for CPU usage on a running or stopped burstable performance instance.YY
ModifyInstanceEventStartTimeModifies the start time for a scheduled Amazon EC2 instance event.YY
ModifyInstanceEventWindowModifies the specified event window.YY
ModifyInstanceMaintenanceOptionsModifies the recovery behavior of your instance to disable simplified automatic recovery or set the recovery behavior to default.YY
ModifyInstanceMetadataDefaultsModifies the default instance metadata service (IMDS) settings at the account level in the specified Amazon Web Services Region.YN
ModifyInstanceMetadataOptionsModify the instance metadata parameters on a running or stopped instance.YY
ModifyInstanceNetworkPerformanceOptionsChange the configuration of the network performance options for an existing instance.YN
ModifyInstancePlacementSet the instance affinity value for a specific stopped instance and modify the instance tenancy setting.YY
ModifyIpamModify the configurations of an IPAM.YN
ModifyIpamPolicyAllocationRulesModifies the allocation rules in an IPAM policy.YN
ModifyIpamPoolModify the configurations of an IPAM pool.YN
ModifyIpamPoolAllocationModifies the description of an IPAM pool allocation.YN
ModifyIpamPrefixListResolverModifies an IPAM prefix list resolver.YN
ModifyIpamPrefixListResolverTargetModifies an IPAM prefix list resolver target.YN
ModifyIpamResourceCidrModify a resource CIDR.YN
ModifyIpamResourceDiscoveryModifies a resource discovery.YN
ModifyIpamScopeModify an IPAM scope.YN
ModifyLaunchTemplateModifies a launch template.YN
ModifyLocalGatewayRouteModifies the specified local gateway route.YN
ModifyManagedPrefixListModifies the specified managed prefix list.YN
ModifyManagedResourceVisibilityModifies the managed resource visibility configuration for the account.YN
ModifyNetworkInterfaceAttributeModifies the specified network interface attribute.YN
ModifyPrivateDnsNameOptionsModifies the options for instance hostnames for the specified instance.YN
ModifyPublicIpDnsNameOptionsModify public hostname options for a network interface.YN
ModifyReservedInstancesModifies the Availability Zone, instance count, instance type, or network platform (EC2-Classic or EC2-VPC) of your Reserved Instances.YN
ModifyRouteServerModifies the configuration of an existing route server.YN
ModifySnapshotTierArchives an Amazon EBS snapshot.YN
ModifySpotFleetRequestModifies the specified Spot fleet request.YN
ModifySubnetAttributeModifies a subnet attribute.YN
ModifyTrafficMirrorFilterNetworkServicesAllows or restricts mirroring network services.YY
ModifyTrafficMirrorFilterRuleModifies the specified Traffic Mirror rule.YY
ModifyTrafficMirrorSessionModifies a Traffic Mirror session.YY
ModifyTransitGatewayModifies the specified transit gateway.YN
ModifyTransitGatewayMeteringPolicyModifies a transit gateway metering policy.YN
ModifyTransitGatewayPrefixListReferenceModifies a reference (route) to a prefix list in a specified transit gateway route table.YN
ModifyTransitGatewayVpcAttachmentModifies the specified VPC attachment.YN
ModifyVerifiedAccessEndpointModifies the configuration of the specified Amazon Web Services Verified Access endpoint.YN
ModifyVerifiedAccessEndpointPolicyModifies the specified Amazon Web Services Verified Access endpoint policy.YN
ModifyVerifiedAccessGroupModifies the specified Amazon Web Services Verified Access group configuration.YN
ModifyVerifiedAccessGroupPolicyModifies the specified Amazon Web Services Verified Access group policy.YN
ModifyVerifiedAccessInstanceModifies the configuration of the specified Amazon Web Services Verified Access instance.YN
ModifyVerifiedAccessInstanceLoggingConfigurationModifies the logging configuration for the specified Amazon Web Services Verified Access instance.YN
ModifyVerifiedAccessTrustProviderModifies the configuration of the specified Amazon Web Services Verified Access trust provider.YN
ModifyVolumeYou can modify several parameters of an existing EBS volume, including volume size, volume type, and IOPS capacity.YN
ModifyVolumeAttributeModifies a volume attribute.YN
ModifyVpcAttributeModifies the specified attribute of the specified VPC.YY
ModifyVpcBlockPublicAccessExclusionModify VPC Block Public Access (BPA) exclusions.YN
ModifyVpcBlockPublicAccessOptionsModify VPC Block Public Access (BPA) options.YN
ModifyVpcEncryptionControlModifies the encryption control configuration for a VPC.YN
ModifyVpcEndpointModifies attributes of a specified VPC endpoint.YN
ModifyVpcEndpointConnectionNotificationModifies a connection notification for VPC endpoint or VPC endpoint service.YN
ModifyVpcEndpointServiceConfigurationModifies the attributes of the specified VPC endpoint service configuration.YN
ModifyVpcEndpointServicePayerResponsibilityModifies the payer responsibility for your VPC endpoint service.YN
ModifyVpcEndpointServicePermissionsModifies the permissions for your VPC endpoint service.YN
ModifyVpcPeeringConnectionOptionsModifies the VPC peering connection options on one side of a VPC peering connection.YN
ModifyVpcTenancyModifies the instance tenancy attribute of the specified VPC.YN
ModifyVpnConnectionModifies the customer gateway or the target gateway of an Amazon Web Services Site-to-Site VPN connection.YN
ModifyVpnConnectionOptionsModifies the connection options for your Site-to-Site VPN connection.YN
ModifyVpnTunnelCertificateModifies the VPN tunnel endpoint certificate.YN
ModifyVpnTunnelOptionsModifies the options for a VPN tunnel in an Amazon Web Services Site-to-Site VPN connection.YN
MonitorInstancesEnables monitoring for a running instance.YY
MoveAddressToVpcMoves an Elastic IP address from the EC2-Classic platform to the EC2-VPC platform.NN
MoveByoipCidrToIpamMove a BYOIPv4 CIDR to IPAM from a public IPv4 pool.NN
MoveCapacityReservationInstancesMove available capacity from a source Capacity Reservation to a destination Capacity Reservation.NN
ProvisionByoipCidrProvisions an IPv4 or IPv6 address range for use with your Amazon Web Services resources through bring your own IP addresses (BYOIP) and creates a corresponding address pool.NN
ProvisionIpamByoasnProvisions your Autonomous System Number (ASN) for use in your Amazon Web Services account.NN
ProvisionIpamPoolCidrProvision a CIDR to an IPAM pool.YN
ProvisionPublicIpv4PoolCidrProvision a CIDR to a public IPv4 pool.NN
PurchaseCapacityBlockPurchase the Capacity Block for use with your account.NN
PurchaseCapacityBlockExtensionPurchase the Capacity Block extension for use with your account.NN
PurchaseHostReservationPurchase a reservation with configurations that match those of your Dedicated Host.NN
PurchaseReservedInstancesOfferingPurchases a Reserved Instance for use with your account.NN
PurchaseScheduledInstancesPurchases one or more Scheduled Instances with the specified schedule.NN
RebootInstancesRequests a reboot of one or more instances.YN
RegisterImageRegisters an AMI.YN
RegisterInstanceEventNotificationAttributesRegisters a set of tag keys to include in scheduled event notifications for your resources.YY
RegisterTransitGatewayMulticastGroupMembersRegisters members (network interfaces) with the transit gateway multicast group.NN
RegisterTransitGatewayMulticastGroupSourcesRegisters sources (network interfaces) with the specified transit gateway multicast group.NN
RejectCapacityReservationBillingOwnershipRejects a request to assign billing of the available capacity of a shared Capacity Reservation to your account.YN
RejectTransitGatewayClientVpnAttachmentRejects a Transit Gateway attachment request for a Client VPN endpoint.YN
RejectTransitGatewayMulticastDomainAssociationsRejects a request to associate cross-account subnets with a transit gateway multicast domain.YN
RejectTransitGatewayPeeringAttachmentRejects a transit gateway peering attachment request.YN
RejectTransitGatewayVpcAttachmentRejects a request to attach a VPC to a transit gateway.YN
RejectVpcEndpointConnectionsRejects VPC endpoint connection requests to your VPC endpoint service.YN
RejectVpcPeeringConnectionRejects a VPC peering connection request.YY
ReleaseAddressReleases the specified Elastic IP address.YN
ReleaseHostsWhen you no longer want to use a Dedicated host it can be released.YN
ReleaseIpamPoolAllocationRelease an allocation within an IPAM pool.YN
ReplaceIamInstanceProfileAssociationReplaces an IAM instance profile for the specified running instance.YN
ReplaceImageCriteriaInAllowedImagesSettingsSets or replaces the criteria for Allowed AMIs.NN
ReplaceNetworkAclAssociationChanges which network ACL a subnet is associated with.YY
ReplaceTransitGatewayRouteReplaces the specified route in the specified transit gateway route table.NN
ReplaceVpnTunnelTrigger replacement of specified VPN tunnel.NN
ReportInstanceStatusSubmits feedback about the status of an instance.YY
RequestSpotFleetCreates a Spot fleet request.NN
RequestSpotInstancesCreates a Spot Instance request.YY
ResetAddressAttributeResets the attribute of the specified IP address.YN
ResetEbsDefaultKmsKeyIdResets the default KMS key for EBS encryption for your account in this Region to the Amazon Web Services managed KMS key for EBS.YN
ResetFpgaImageAttributeResets the specified attribute of the specified Amazon FPGA Image (AFI) to its default value.YN
ResetImageAttributeResets an attribute of an AMI to its default value.YN
ResetInstanceAttributeResets an attribute of an instance to its default value.YY
ResetNetworkInterfaceAttributeResets a network interface attribute.YN
ResetSnapshotAttributeResets permission settings for the specified snapshot.YN
RestoreAddressToClassicRestores an Elastic IP address that was previously moved to the EC2-VPC platform back to the EC2-Classic platform.NN
RestoreImageFromRecycleBinRestores an AMI from the Recycle Bin.NN
RestoreManagedPrefixListVersionRestores the entries from a previous version of a managed prefix list to a new version of the prefix list.YN
RestoreSnapshotFromRecycleBinRestores a snapshot from the Recycle Bin.NN
RestoreSnapshotTierRestores an archived Amazon EBS snapshot for use temporarily or permanently, or modifies the restore period or restore type for a snapshot that was previously temporarily restored.NN
RestoreVolumeFromRecycleBinRestores a volume from the Recycle Bin.NN
RevokeClientVpnIngressRemoves an ingress authorization rule from a Client VPN endpoint.YN
RunInstancesLaunches the specified number of instances using an AMI for which you have permissions.YY
RunScheduledInstancesLaunches the specified Scheduled Instances.NY
SearchLocalGatewayRoutesSearches for routes in the specified local gateway route table.YN
SearchTransitGatewayMulticastGroupsSearches one or more transit gateway multicast groups and returns the group membership information.YN
SearchTransitGatewayRoutesSearches for routes in the specified transit gateway route table.YN
SendDiagnosticInterruptSends a diagnostic interrupt to the specified Amazon EC2 instance to trigger a kernel panic (on Linux instances), or a blue screen/stop error (on Windows instances).YN
StartDeclarativePoliciesReportGenerates an account status report.NN
StartNetworkInsightsAccessScopeAnalysisStarts analyzing the specified Network Access Scope.YN
StartNetworkInsightsAnalysisStarts analyzing the specified path.YN
StartVpcEndpointServicePrivateDnsVerificationInitiates the verification process to prove that the service provider owns the private DNS name domain for the endpoint service.NN
TerminateClientVpnConnectionsTerminates active Client VPN endpoint connections.YN
TerminateInstancesShuts down one or more instances.YY
UnassignIpv6AddressesUnassigns the specified IPv6 addresses or Prefix Delegation prefixes from a network interface.NN
UnassignPrivateIpAddressesUnassigns one or more secondary private IP addresses from a network interface.YN
UnassignPrivateNatGatewayAddressUnassigns secondary private IPv4 addresses from a private NAT gateway.NN
UnlockSnapshotUnlocks a snapshot that is locked in governance mode or that is locked in compliance mode but still in the cooling-off period.YN
UnmonitorInstancesDisables monitoring for a running instance.YY
UpdateCapacityManagerMonitoredTagKeysActivates or deactivates tag keys for monitoring by EC2 Capacity Manager.NN
UpdateCapacityManagerOrganizationsAccessUpdates the Organizations access setting for EC2 Capacity Manager.YN
UpdateInterruptibleCapacityReservationAllocationModifies the number of instances allocated to an interruptible reservation, allowing you to add more capacity or reclaim capacity to your source Capacity Reservation.YN
UpdateSecurityGroupRuleDescriptionsEgressUpdates the description of an egress (outbound) security group rule.YN
UpdateSecurityGroupRuleDescriptionsIngressUpdates the description of an ingress (inbound) security group rule.YN
WithdrawByoipCidrStops advertising an address range that is provisioned as an address pool.NN
BidEvictedEventBidEvictedEvent recorded by CloudTrail for Amazon EC2. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
DeleteVpcResourceDeletionDeleteVpcResourceDeletion recorded by CloudTrail for Amazon EC2. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
DescribeVerifiedAccessInstanceWebAclAssociationsDescribeVerifiedAccessInstanceWebAclAssociations recorded by CloudTrail for Amazon EC2. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
SharedSnapshotVolumeCreatedSharedSnapshotVolumeCreated recorded by CloudTrail for Amazon EC2. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.YN
AssociateApplicationStatusCheckAssociates an application status check with instances or tags.NN
BatchModifyIpamRoutingPolicyRegistrationsModifies multiple routing policy registrations in a single operation.NN
CreateApplicationStatusCheckCreates an application status check for monitoring the health of applications running on your instances.NN
CreateIpamInternetRegistryAssociationCreates an association between an IPAM and a Regional Internet Registry (RIR) for Resource Public Key Infrastructure (RPKI) management.NN
CreateIpamRoutingPolicyRegistrationCreates a routing policy registration and publishes Route Origin Authorizations (ROAs) to the RPKI for the specified CIDR prefix and ASNs.NN
CreateTransitGatewayPolicyTableEntryCreates an entry in a transit gateway policy table to route matching traffic to a specified route table.NN
DeleteApplicationStatusCheckDeletes an application status check.NN
DeleteIpamInternetRegistryAssociationDeletes an IPAM internet registry association.NN
DeleteIpamRoutingPolicyRegistrationDeletes a routing policy registration for a specified CIDR prefix.NN
DeleteTransitGatewayPolicyTableEntryDeletes the specified transit gateway policy table entry.NN
DescribeAccountVpcEncryptionControlDescribes the account-level VPC Encryption Control configuration for your account.NN
DescribeApplicationStatusDescribes the application status for the specified instances.NN
DescribeApplicationStatusCheckAssociationsDescribes the associations for one or more application status checks.NN
DescribeApplicationStatusChecksDescribes one or more application status checks.NN
DescribeIpamInternetRegistryAssociationsDescribes one or more IPAM internet registry associations.NN
DisableApplicationStatusCheckSuppressionDisables suppression of application status checks for the specified instances.NN
DisassociateApplicationStatusCheckDisassociates an application status check from instances or tags.NN
EnableApplicationStatusCheckSuppressionSuppresses application status checks for the specified instances.NN
EnableIpamInternetRegistryAssociationEnables Resource Public Key Infrastructure (RPKI) on an existing IPAM internet registry association by providing BGP Public Key Infrastructure (BPKI) certificate details.NN
GetIpamDiscoveredRoutesRetrieves Border Gateway Protocol (BGP) routes discovered by IPAM resource discovery for a specified Region.NN
GetIpamInternetRegistryAssociationAsnsRetrieves Autonomous System Numbers (ASNs) registered with an internet registry for an IPAM internet registry association.NN
GetIpamInternetRegistryAssociationCidrsRetrieves IP address CIDRs registered with an internet registry for an IPAM internet registry association.NN
GetIpamRouteOriginAuthorizationsRetrieves the current Route Origin Authorizations (ROAs) published to the RPKI for an IPAM internet registry association.NN
GetIpamRouteProtectionFindingsRetrieves route protection findings for an IPAM.NN
GetIpamRoutingPolicyRegistrationDeltasRetrieves the history of routing policy registration changes for an IPAM internet registry association.NN
GetIpamRoutingPolicyRegistrationsRetrieves routing policy registrations for an IPAM internet registry association.NN
ModifyAccountVpcEncryptionControlModifies the account-level VPC Encryption Control configuration.NN
ModifyApplicationStatusCheckModifies an existing application status check.NN
ModifyIpamRoutingPolicyRegistrationModifies an existing routing policy registration.NN
ModifyTransitGatewayPolicyTableEntryModifies the specified transit gateway policy table entry.NN
ModifyVpcEndpointPayerResponsibilityModifies the billing account for VPC endpoint usage/charges.NN

any: EC2 (catch-all)

#
Service
ec2

Description

Catch-all entry for EC2 rules that match the service but not a specific eventName.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

  • Query.EC2.CRUD.Activity.Role source: This query searches for CRUD activity in EC2 by role arn. Activities from a role outside typical deployment processes may warrant investigation.
  • Query.EC2.CRUD.Activity.Useragent source: This query searches for CRUD activity in EC2 by userAgent. A low count or previously unseen useragent may indicate that the action was not performed by an automated process.

AssociateIamInstanceProfile

#
Service
ec2

Description

Associates an IAM instance profile with a running or stopped EC2 instance.

CloudTrail management event, logged by default.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::errorCode (panther rule field)neClient.DryRunOperation1 rulepanther
readOnly (panther rule field)is_null1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS EC2 Instance Profile Associated with Running Instance source high: Identifies when an IAM instance profile is associated with a running EC2 instance or replaces the existing association. These APIs change which role credentials the instance obtains via the instance metadata service without terminating the instance. Attackers who can call AssociateIamInstanceProfile or ReplaceIamInstanceProfile may attach a more privileged role to a workload they control, enabling privilege escalation or lateral movement from the instance.T1078, T1078.004, T1548, T1548.005

Panther #

AuthorizeSecurityGroupEgress

#
Service
ec2

Description

Adds outbound rules to a security group to allow traffic to the specified destination.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "914469fc-c658-434c-a560-0219c0ac3b55",
  "eventName": "AuthorizeSecurityGroupEgress",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:10:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "b8dd3137-1553-4109-b927-8c974c244627",
  "requestParameters": {
    "groupId": "sg-04cfb7a4712d75b00",
    "ipPermissions": {
      "items": [
        {
          "groups": {},
          "ipProtocol": "-1",
          "ipRanges": {
            "items": [
              {
                "cidrIp": "0.0.0.0/0"
              }
            ]
          },
          "ipv6Ranges": {
            "items": [
              {
                "cidrIpv6": "::/0"
              }
            ]
          },
          "prefixListIds": {}
        }
      ]
    }
  },
  "responseElements": {
    "_return": true,
    "requestId": "b8dd3137-1553-4109-b927-8c974c244627",
    "securityGroupRuleSet": {
      "items": [
        {
          "cidrIpv4": "0.0.0.0/0",
          "fromPort": -1,
          "groupId": "sg-04cfb7a4712d75b00",
          "groupOwnerId": "123837392027",
          "ipProtocol": "-1",
          "isEgress": true,
          "securityGroupRuleId": "sgr-035a6016fe8ef01c5",
          "toPort": -1
        },
        {
          "cidrIpv6": "::/0",
          "fromPort": -1,
          "groupId": "sg-04cfb7a4712d75b00",
          "groupOwnerId": "123837392027",
          "ipProtocol": "-1",
          "isEgress": true,
          "securityGroupRuleId": "sgr-08d9fb7a2d678c6e8",
          "toPort": -1
        }
      ]
    }
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_2142a106-933f-4595-ad51-0ff5dfff60b7 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Kusto #

Panther #

References #

AuthorizeSecurityGroupIngress

#
Service
ec2

Description

Adds inbound rules to a security group to allow traffic from the specified source.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:58:35Z",
  "eventSource": "ec2.amazonaws.com",
  "eventName": "AuthorizeSecurityGroupIngress",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#ec2.authorize-security-group-ingress",
  "requestParameters": {
    "groupId": "sg-0200d267c43de2fbc",
    "ipPermissions": {
      "items": [
        {
          "ipProtocol": "tcp",
          "fromPort": 22,
          "toPort": 22,
          "groups": {},
          "ipRanges": {
            "items": [
              {
                "cidrIp": "203.0.113.0/24"
              }
            ]
          },
          "ipv6Ranges": {},
          "prefixListIds": {}
        }
      ]
    }
  },
  "responseElements": {
    "requestId": "cc4a44e3-25be-4adc-abe2-873a790f99d1",
    "_return": true,
    "securityGroupRuleSet": {
      "items": [
        {
          "groupOwnerId": "123456789012",
          "groupId": "sg-0200d267c43de2fbc",
          "securityGroupRuleId": "sgr-03ed9e32a143279c2",
          "isEgress": false,
          "ipProtocol": "tcp",
          "fromPort": 22,
          "toPort": 22,
          "cidrIpv4": "203.0.113.0/24",
          "securityGroupRuleArn": "arn:aws:ec2:us-west-1:123456789012:security-group-rule/sgr-03ed9e32a143279c2"
        }
      ]
    }
  },
  "requestID": "cc4a44e3-25be-4adc-abe2-873a790f99d1",
  "eventID": "50f6829b-d389-4490-9e0b-be18cab833f2",
  "readOnly": false,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Kusto #

YARA-L #

Panther #

CreateInstanceExportTask

#
Service
ec2

Description

Exports a running or stopped EC2 instance to an Amazon S3 bucket in OVA, VHD, or VMDK format.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "23a763b4-4a9c-4781-a670-9c160961f62dc",
  "eventName": "CreateInstanceExportTask",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-02-28T14:36:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "b09f8e07-3a66-40ee-b8fe-cae9e380f8df",
  "requestParameters": {
    "description": "blah",
    "exportToS3": {
      "containerFormat": "ova",
      "diskImageFormat": "vmdk",
      "s3Bucket": "14b6a528b915b3c0270e0174982e5ed78052eafd.flaws.cloud",
      "s3Prefix": "RHEL5"
    },
    "instanceId": "snap-2f6b292187c2304c2",
    "targetEnvironment": "vmware"
  },
  "responseElements": null,
  "sourceIPAddress": "0.102.218.8",
  "userAgent": "aws-cli/1.11.56 Python/2.7.10 Darwin/16.4.0 botocore/1.5.19",
  "userIdentity": {
    "accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
readOnly (panther rule field)is_null1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • AWS EC2 Export Task source medium: Identifies successful export tasks of EC2 instances via the APIs CreateInstanceExportTask, ExportImage, or CreateStoreImageTask. These exports can be used by administrators for legitimate VM migration or backup workflows however, an attacker with access to an EC2 instance or AWS credentials can export a VM or its image and then transfer it off-account for exfiltration of data.T1005, T1119, T1530, T1537, T1567, T1567.002↳ also matches CreateStoreImageTask, ExportImage

Panther #

References #

CreateKeyPair

#
Service
ec2

Description

Creates an ED25519 or 2048-bit RSA key pair and stores the public key in EC2, returning the private key material.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "ea9ba18b-6f28-42bd-9c6a-fc9e66b9adae",
  "eventName": "CreateKeyPair",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-02-12T20:20:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "dbfde5b5-58b7-4452-90bc-7d0b6e9efefd",
  "requestParameters": {
    "keyName": "Default"
  },
  "responseElements": {
    "keyFingerprint": "07:ac:63:2a:07:b7:e1:35:be:26:49:07:16:90:fe:e7:57:e0:2c:31",
    "keyMaterial": "<sensitiveDataRemoved>",
    "keyName": "Default"
  },
  "sourceIPAddress": "255.253.125.115",
  "userAgent": "console.ec2.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "ASIAIB6AB67SP5RKU9Z4",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:root",
    "principalId": "811596193553",
    "sessionContext": {
      "attributes": {
        "creationDate": "2017-02-12T19:57:05Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "Root"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
source.as.organization.name (elastic rule field)is_not_null1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS EC2 CreateKeyPair by New Principal from Non-Cloud AS Organization source high: Identifies the first time a given IAM principal successfully creates an EC2 key pair when the request is sourced from a network whose autonomous system organization is not attributed to common cloud or hyperscaler providers in your GeoIP data. Adversaries may call CreateKeyPair to stage SSH access material before launching or accessing instances. A new terms baseline on user_identity.arn suppresses repeated noise from the same principal while still surfacing the initial suspicious creation from an unusual egress label.T1021, T1021.004, T1098, T1552, T1552.004

References #

CreateNetworkAcl

#
Service
ec2

Description

Creates a new network ACL in the specified VPC.

Example CloudTrail Event #

{
  "awsRegion": "eu-central-1",
  "eventCategory": "Management",
  "eventID": "e6cfba5e-7b8d-413a-801c-e7d4f3843814",
  "eventName": "CreateNetworkAcl",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-01-12T08:37:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "111111111111",
  "requestID": "001b69eb-7486-48b5-a81b-45e08be4c7cb",
  "requestParameters": {
    "tagSpecificationSet": {
      "items": [
        {
          "resourceType": "network-acl",
          "tags": [
            {
              "key": "Name",
              "value": "patrick-test"
            }
          ]
        }
      ]
    },
    "vpcId": "vpc-0e59cf66"
  },
  "responseElements": {
    "networkAcl": {
      "associationSet": {},
      "entrySet": {
        "items": [
          {
            "aclProtocol": "-1",
            "cidrBlock": "0.0.0.0/0",
            "egress": true,
            "icmpTypeCode": {},
            "portRange": {},
            "ruleAction": "deny",
            "ruleNumber": 32767
          },
          {
            "aclProtocol": "-1",
            "cidrBlock": "0.0.0.0/0",
            "egress": false,
            "icmpTypeCode": {},
            "portRange": {},
            "ruleAction": "deny",
            "ruleNumber": 32767
          }
        ]
      },
      "isDefault": false,
      "networkAclId": "acl-078ccebebcbabe175",
      "ownerId": "111111111111",
      "tagSet": {
        "items": [
          {
            "key": "Name",
            "value": "patrick-test"
          }
        ]
      },
      "vpcId": "vpc-0e59cf66"
    },
    "requestId": "001b69eb-7486-48b5-a81b-45e08be4c7cb"
  },
  "sourceIPAddress": "95.90.199.65",
  "userAgent": "console.ec2.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "ASIAYTOGP2RLF3F7BXZK",
    "accountId": "111111111111",
    "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
    "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-01-12T08:36:15Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "111111111111",
        "arn": "arn:aws:iam::111111111111:role/okta_adm_role",
        "principalId": "AROAIJIESMXKGCJRCTPR6",
        "type": "Role",
        "userName": "okta_adm_role"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

References #

CreateNetworkAclEntry

#
Service
ec2

Description

Creates an entry (rule) in a network ACL with the specified rule number, protocol, and traffic action.

Example CloudTrail Event #

{
  "awsRegion": "eu-central-1",
  "eventCategory": "Management",
  "eventID": "40b0e8a3-048f-4f44-a022-1ef26fade55e",
  "eventName": "CreateNetworkAclEntry",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-01-12T09:26:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "111111111111",
  "requestID": "cc527b25-0ec5-40f2-b09f-0c99bfada160",
  "requestParameters": {
    "aclProtocol": "6",
    "cidrBlock": "0.0.0.0/0",
    "egress": false,
    "icmpTypeCode": {},
    "networkAclId": "acl-078ccebebcbabe175",
    "portRange": {
      "from": 0,
      "to": 65000
    },
    "ruleAction": "allow",
    "ruleNumber": 40
  },
  "responseElements": {
    "_return": true,
    "requestId": "cc527b25-0ec5-40f2-b09f-0c99bfada160"
  },
  "sourceIPAddress": "95.90.199.65",
  "userAgent": "console.ec2.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "ASIAYTOGP2RLF3F7BXZK",
    "accountId": "111111111111",
    "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
    "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-01-12T08:36:15Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "111111111111",
        "arn": "arn:aws:iam::111111111111:role/okta_adm_role",
        "principalId": "AROAIJIESMXKGCJRCTPR6",
        "type": "Role",
        "userName": "okta_adm_role"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aclProtocoleq-12 ruleskusto, splunk
egresseqfalse2 ruleskusto, splunk
ruleActioneqallow2 ruleskusto, splunk
event.outcome (elastic rule field)insuccess1 ruleelastic
requestParameters.egress (splunk rule field)eqfalse1 rulesplunk
requestParameters.ruleAction (splunk rule field)eqallow1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • AWS EC2 NACL Entry Created or Replaced Allowing All Traffic by New Identity source medium: Detects a principal account creating or replacing - or attempts to create or replace - an AWS Network Access Control List (NACL) entry using protocol -1 (all traffic). Both successful and failed outcomes are included. A NACL entry with protocol -1 passes all traffic regardless of port, which would disable network-layer controls for the affected subnets. Monitoring for new identities performing this change helps surface freshly compromised credentials or unauthorized principals removing a defense-in-depth layer to facilitate lateral movement or data exfiltration. This signal only flags if this behavior was not observed historically in a specific time window.T1562, T1562.007↳ also matches ReplaceNetworkAclEntry
  • AWS EC2 Network Access Control List Creation source low: Identifies the creation of an AWS EC2 network access control list (ACL) or an entry in a network ACL with a specified rule number. Adversaries may exploit ACLs to establish persistence or exfiltrate data by creating permissive rules.T1133, T1562, T1562.007, T1578, T1578.005↳ also matches CreateNetworkAcl

Splunk #

Kusto #

Panther #

References #

CreateRoute

#
Service
ec2

Description

Creates a route in a route table within a VPC, specifying the destination CIDR and target.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "6445452c-c6df-4ebf-a1ed-2890f5aa7107",
  "eventName": "CreateRoute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "c78b8c19-af06-44ea-b707-60bb0c3124f9",
  "requestParameters": {
    "destinationCidrBlock": "0.0.0.0/0",
    "gatewayId": "igw-02a84e4222d62e16b",
    "routeTableId": "rtb-0c7c2f4aff3677054"
  },
  "responseElements": {
    "_return": true,
    "requestId": "c78b8c19-af06-44ea-b707-60bb0c3124f9"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • AWS EC2 Route Table Created source low: Identifies when an EC2 Route Table has been created. Route tables can be used by attackers to disrupt network traffic, reroute communications, or maintain persistence in a compromised environment. This is a New Terms rule that detects the first instance of this behavior by a user or role.T1578, T1578.005↳ also matches CreateRouteTable

References #

CreateRouteTable

#
Service
ec2

Description

Creates a route table for the specified VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "dc024e51-15e4-4829-a971-7e17d4be43be",
  "eventName": "CreateRouteTable",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "6448e604-a047-4564-ba7e-712d66db3d97",
  "requestParameters": {
    "tagSpecificationSet": {
      "items": [
        {
          "resourceType": "route-table",
          "tags": [
            {
              "key": "StratusRedTeam",
              "value": "true"
            },
            {
              "key": "Name",
              "value": "stratus-red-team-ec2-steal-credentials-vpc-public"
            }
          ]
        }
      ]
    },
    "vpcId": "vpc-06fe1a64761a0f720"
  },
  "responseElements": {
    "requestId": "6448e604-a047-4564-ba7e-712d66db3d97",
    "routeTable": {
      "associationSet": {},
      "ownerId": "123837392027",
      "propagatingVgwSet": {},
      "routeSet": {
        "items": [
          {
            "destinationCidrBlock": "10.0.0.0/16",
            "gatewayId": "local",
            "origin": "CreateRouteTable",
            "state": "active"
          }
        ]
      },
      "routeTableId": "rtb-0c7c2f4aff3677054",
      "tagSet": {
        "items": [
          {
            "key": "StratusRedTeam",
            "value": "true"
          },
          {
            "key": "Name",
            "value": "stratus-red-team-ec2-steal-credentials-vpc-public"
          }
        ]
      },
      "vpcId": "vpc-06fe1a64761a0f720"
    }
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS EC2 Route Table Created source low: Identifies when an EC2 Route Table has been created. Route tables can be used by attackers to disrupt network traffic, reroute communications, or maintain persistence in a compromised environment. This is a New Terms rule that detects the first instance of this behavior by a user or role.T1578, T1578.005↳ also matches CreateRoute

Kusto #

Panther #

References #

CreateSecurityGroup

#
Service
ec2

Description

Creates a security group in a specified VPC or for EC2-Classic.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:58:33Z",
  "eventSource": "ec2.amazonaws.com",
  "eventName": "CreateSecurityGroup",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#ec2.create-security-group",
  "requestParameters": {
    "groupName": "dw-harn-ec2-eb786637",
    "groupDescription": "dw harness",
    "vpcId": "vpc-0cf63cfb072f7d61f"
  },
  "responseElements": {
    "requestId": "35e65d8f-9426-418d-ae76-c7baf12b1899",
    "_return": true,
    "groupId": "sg-0200d267c43de2fbc",
    "securityGroupArn": "arn:aws:ec2:us-west-1:123456789012:security-group/sg-0200d267c43de2fbc"
  },
  "requestID": "35e65d8f-9426-418d-ae76-c7baf12b1899",
  "eventID": "254b9453-647c-4c63-8b0b-2f973bdfa5d0",
  "readOnly": false,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

CreateStoreImageTask

#
Service
ec2

Description

Stores an Amazon Machine Image (AMI) as a single object in an Amazon S3 bucket.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::errorCode (panther rule field)neClient.DryRunOperation1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS EC2 Export Task source medium: Identifies successful export tasks of EC2 instances via the APIs CreateInstanceExportTask, ExportImage, or CreateStoreImageTask. These exports can be used by administrators for legitimate VM migration or backup workflows however, an attacker with access to an EC2 instance or AWS credentials can export a VM or its image and then transfer it off-account for exfiltration of data.T1005, T1119, T1530, T1537, T1567, T1567.002↳ also matches CreateInstanceExportTask, ExportImage

Panther #

CreateTrafficMirrorSession

#
Service
ec2

Description

Creates a traffic mirror session that copies network traffic from a source network interface to a target.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation. User: arn:aws:iam::123456789012:user/TrailDiscover is not authorized to perform: ec2:CreateTrafficMirrorSession on resource: arn:aws:ec2:us-east-1:192374575148:traffic-mirror-filter/* because no identity-based policy allows the ec2:CreateTrafficMirrorSession action. Encoded authorization failure message: HJhYRHfNmRnmfLwYuoFYYZia0G-FhUf1Oe4osxJuO86JpVIhw6gMXS67RWasoBwP-srKZVJlihD_HC-wnUUlfHeRNPYlaR6WI289aN31GSE5oBu-EkL7jhf_8-7j_oCqrQ6Xwr37C7Cfdpr4Cyxw-JrxKOUYMTyMFRY3YRgcke2e_9QzAxnjr3C7ioQQMTEpI0dEN9M3x3YKWUbmddXMXKQAqs2eNGf9b6ISCtTBjIeV8rE0oOtOUZx8cS3CavD7aLJE4L9DZEBllFcSzNVq17mznRPC8l3_n6P0UusmdalelhW2KjCCKqjCSPVZ-T9mGGd4q4Q4s35nVPS2KI8R8Vlx6rV88yomFpQk_Ld6THhUkrp3Tpf6TswCLWRZlxElw-JlsCod9N0jANT2T2wkWVuCB-bf5fSqS7cJwJ3Jt1-EBr3ZviQdZHNLeYi5yQsEP0XdVHounoK7oE59wcEyclDehhUTkUluGrfTVdXKkoDUuy4qDebk5Hbax4d_PG-04HhPGJhJfrxfEWBdy3nrL8Mji-aLCA",
  "eventCategory": "Management",
  "eventID": "bdc6cf73-0710-4815-9cbc-e2944665d9ff",
  "eventName": "CreateTrafficMirrorSession",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2024-08-18T14:29:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.09",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "82310870-1409-41fe-b9a0-9283f159824f",
  "requestParameters": {
    "CreateTrafficMirrorSessionRequest": {
      "ClientToken": "32617bdc-4512-4f42-a69f-3da62c6692c6",
      "Description": "TrailDiscoverDescription",
      "NetworkInterfaceId": "eni-070203f901EXAMPLE",
      "PacketLength": 25,
      "SessionNumber": 1,
      "TrafficMirrorFilterId": "tmf-04812ff784EXAMPLE",
      "TrafficMirrorTargetId": "tmt-07f75d8feeEXAMPLE"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "0.0.0.0",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "aws-cli/2.17.32 md/awscrt#0.21.2 ua/2.0 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.11.9 md/pyimpl#CPython exec-env/grimoire_2955cdaf-7deb-4516-932b-b6aebaa38515 cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#ec2.create-traffic-mirror-session",
  "userIdentity": {
    "accessKeyId": "AKIA****************",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/TrailDiscover",
    "principalId": "AROA****************:User",
    "type": "IAMUser",
    "userName": "TrailDiscover"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS EC2 Full Network Packet Capture Detected source medium: Detects successful creation of an Amazon EC2 Traffic Mirroring session. A session copies full packets from a source Elastic Network Interface (ENI) to a mirror target (e.g., an ENI or NLB) using a mirror filter (ingress/egress rules). While used for diagnostics and NDR/IDS tooling, adversaries can abuse sessions to covertly capture and exfiltrate sensitive, potentially unencrypted, traffic from instances or subnets.T1020, T1040, T1074, T1537

Panther #

References #

DeleteFlowLogs

#
Service
ec2

Description

Deletes one or more VPC flow logs.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "de58d903-38d7-4f30-a84b-b79d858e8376",
  "eventName": "DeleteFlowLogs",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:02:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "bd26b4b4-133e-4610-8be1-9c5d645bb2ee",
  "requestParameters": {
    "DeleteFlowLogsRequest": {
      "FlowLogId": {
        "content": "fl-064ed3a785e4a37ef",
        "tag": 1
      }
    }
  },
  "responseElements": {
    "DeleteFlowLogsResponse": {
      "requestId": "bd26b4b4-133e-4610-8be1-9c5d645bb2ee",
      "unsuccessful": "",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "stratus-red-team_20f9795b-aa02-4c8e-bad6-bd338ec09f59",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::errorCode (sigma rule field)eqsuccess1 rulesigma

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

  • AWS VPC Flow Logs Deleted source high: Detects the deletion of one or more VPC Flow Logs in AWS Elastic Compute Cloud (EC2) through the DeleteFlowLogs API call. Adversaries may delete flow logs to evade detection or remove evidence of network activity, hindering forensic investigations and visibility into malicious operations.

Elastic #

Kusto #

YARA-L #

Panther #

References #

DeleteNetworkAcl

#
Service
ec2

Description

Deletes the specified network ACL, which must not be associated with any subnets.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidNetworkAclId.Malformed",
  "errorMessage": "The network-acl ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "4c24ae67-78fd-4274-b675-434aa51abbf2",
  "eventName": "DeleteNetworkAcl",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6e26e5aa-c75c-4c1c-a2f9-7d4f4a3de07d",
  "requestParameters": {
    "networkAclId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

DeleteNetworkAclEntry

#
Service
ec2

Description

Deletes the specified ingress or egress entry (rule) from the specified network ACL.

Example CloudTrail Event #

{
  "awsRegion": "eu-central-1",
  "eventCategory": "Management",
  "eventID": "b9e05770-e9b0-4ba1-91e8-6537097e06e7",
  "eventName": "DeleteNetworkAclEntry",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-01-12T09:26:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "111111111111",
  "requestID": "607474bb-836b-46be-be4a-351ebbef67d6",
  "requestParameters": {
    "egress": false,
    "networkAclId": "acl-078ccebebcbabe175",
    "ruleNumber": 40
  },
  "responseElements": {
    "_return": true,
    "requestId": "607474bb-836b-46be-be4a-351ebbef67d6"
  },
  "sourceIPAddress": "95.90.199.65",
  "userAgent": "console.ec2.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "ASIAYTOGP2RLF3F7BXZK",
    "accountId": "111111111111",
    "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
    "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-01-12T08:36:15Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "111111111111",
        "arn": "arn:aws:iam::111111111111:role/okta_adm_role",
        "principalId": "AROAIJIESMXKGCJRCTPR6",
        "type": "Role",
        "userName": "okta_adm_role"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
egress (splunk rule field)eqfalse1 rulesplunk
requestParameters.egress (splunk rule field)eqfalse1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Splunk #

  • ASL AWS Network Access Control List Deleted source: The following analytic detects the deletion of AWS Network Access Control Lists (ACLs). It leverages AWS CloudTrail logs to identify events where a user deletes a network ACL entry. This activity is significant because deleting a network…T1686, T1686.001
  • AWS Network Access Control List Deleted source: The following analytic detects the deletion of AWS Network Access Control Lists (ACLs). It leverages AWS CloudTrail logs to identify events where a user deletes a network ACL entry. This activity is significant because deleting a network…T1686, T1686.001

Panther #

References #

DeleteRoute

#
Service
ec2

Description

Deletes the specified route from the specified route table.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "ffd9d334-1e18-4c5e-9ccf-e31d440f3dec",
  "eventName": "DeleteRoute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:08:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "cf090fc5-3d06-4571-a6cc-7c8de1229399",
  "requestParameters": {
    "destinationCidrBlock": "0.0.0.0/0",
    "routeTableId": "rtb-08838187a84b2f5bf"
  },
  "responseElements": {
    "_return": true,
    "requestId": "cf090fc5-3d06-4571-a6cc-7c8de1229399"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

DeleteRouteTable

#
Service
ec2

Description

Deletes the specified route table, which must not be associated with any subnet.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "9c924999-9fc4-4d24-8c17-e68efd788af4",
  "eventName": "DeleteRouteTable",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:08:07Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "ba265499-24f7-4fa0-984f-5f5ee5d848e6",
  "requestParameters": {
    "routeTableId": "rtb-01a1e48796093c514"
  },
  "responseElements": {
    "_return": true,
    "requestId": "ba265499-24f7-4fa0-984f-5f5ee5d848e6"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

References #

DescribeCarrierGateways

#
Service
ec2

Description

Describes one or more carrier gateways associated with a VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "a5acbb96-64bc-4b58-9a49-03ed3ec45d88",
  "eventName": "DescribeCarrierGateways",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-10-02T15:48:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "e92ac6bf-2623-4651-a4f5-a9232b591632",
  "requestParameters": {
    "DescribeCarrierGatewaysRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "253.237.6.192",
  "userAgent": "aws-cli/1.18.146 Python/3.8.4 Linux/5.7.0-kali1-amd64 botocore/1.18.5",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeClientVpnRoutes

#
Service
ec2

Description

Describes the routes for a specified Client VPN endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.DryRunOperation",
  "errorMessage": "Request would have succeeded, but DryRun flag is set.",
  "eventID": "f1e789a6-a761-4614-9f1a-cc9e4fee45db",
  "eventName": "DescribeClientVpnRoutes",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-05-19T17:44:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "2d3a06b9-5a2c-4d18-8a9f-616c91717ce9",
  "requestParameters": {
    "DescribeClientVpnRoutesRequest": {
      "ClientVpnEndpointId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "255.251.4.254",
  "userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeDhcpOptions

#
Service
ec2

Description

Describes one or more DHCP options sets in the account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "a93a1a71-0a8f-46bb-bec3-2b2e3702f180",
  "eventName": "DescribeDhcpOptions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:13:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "b417ae75-09b7-44b2-aded-e11041a4ae81",
  "requestParameters": {
    "dhcpOptionsSet": {},
    "filterSet": {},
    "maxResults": 1000
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCSUD2OWV6",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:13:16Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeImages

#
Service
ec2

Description

Describes one or more Amazon Machine Images (AMIs) available to the account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "9b77e3e5-b2a1-4274-a0f9-8f642f0ae426",
  "eventName": "DescribeImages",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:06:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "6723987a-8e90-4a4d-9f8a-102e30df02de",
  "requestParameters": {
    "executableBySet": {},
    "filterSet": {
      "items": [
        {
          "name": "name",
          "valueSet": {
            "items": [
              {
                "value": "amzn2-ami-hvm-*-x86_64-ebs"
              }
            ]
          }
        }
      ]
    },
    "imagesSet": {},
    "includeDeprecated": false,
    "ownersSet": {
      "items": [
        {
          "owner": "amazon"
        }
      ]
    }
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/4.67.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.261 (go1.19.8; linux; amd64) stratus-red-team_bc31c885-5ea0-4a6e-8bec-b6b10058bc44 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS EC2 Deprecated AMI Discovery source low: Identifies when a user has queried for deprecated Amazon Machine Images (AMIs) in AWS. This may indicate an adversary looking for outdated AMIs that may be vulnerable to exploitation. While deprecated AMIs are not inherently malicious or indicative of a breach, they may be more susceptible to vulnerabilities and should be investigated for potential security risks.T1580

References #

DescribeInstanceAttribute

#
Service
ec2

Description

Describes the specified attribute of the specified EC2 instance.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "61374265-b590-4f81-b09d-295ccc1a7de1",
  "eventName": "DescribeInstanceAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:33Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "82290b81-0e4f-4b01-b60b-aeace3a4c8fd",
  "requestParameters": {
    "attribute": "instanceInitiatedShutdownBehavior",
    "instanceId": "i-0dbc91f429e48eeed"
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS EC2 User Data Retrieval for EC2 Instance source medium: Identifies discovery request DescribeInstanceAttribute with the attribute userData and instanceId in AWS CloudTrail logs. This may indicate an attempt to retrieve user data from an EC2 instance. Adversaries may use this information to gather sensitive data from the instance such as hardcoded credentials or to identify potential vulnerabilities. This is a New Terms rule that identifies the first time an IAM user or role requests the user data for a specific EC2 instance.T1552, T1552.005, T1580

References #

DescribeInstances

#
Service
ec2

Description

Returns detailed information about one or more EC2 instances, including their state, type, network interfaces, and associated metadata.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "b5b603c2-7b7f-41d9-8932-f87be2fc78d6",
  "eventName": "DescribeInstances",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:13:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "ca74d893-b2e1-452a-9851-0ea9294dcb49",
  "requestParameters": {
    "filterSet": {
      "items": [
        {
          "name": "instance-state-name",
          "valueSet": {
            "items": [
              {
                "value": "running"
              }
            ]
          }
        }
      ]
    },
    "instancesSet": {},
    "maxResults": 1000
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCSUD2OWV6",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:13:16Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
Esql.cloud_region_count_distinct (elastic rule field)ge101 ruleelastic
Esql.event_count (elastic rule field)ge101 ruleelastic
aws::userIdentity.arn (elastic rule field)is_not_null1 ruleelastic
source.as.number (elastic rule field)in90091 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS EC2 Multi-Region DescribeInstances API Calls source low: Identifies when a single AWS resource is making DescribeInstances API calls in more than 10 regions within a 30-second window. This could indicate a potential threat actor attempting to discover the AWS infrastructure across multiple regions using compromised credentials or a compromised instance. Adversaries may use this information to identify potential targets for further exploitation or to gain a better understanding of the target's infrastructure.T1580
  • AWS Discovery API Calls from VPN ASN for the First Time by Identity source high: Flags the first time a given IAM principal invokes a narrow set of high-signal discovery APIs (credential check, account and IAM enumeration, bucket and compute inventory, logging introspection) from a source IP whose autonomous system number (ASN) matches a curated set commonly associated with consumer VPN brands, VPN-heavy hosting, and provider networks referenced in public reporting on TeamPCP activity (for example 31173 Services AB AS39351 and Oy Crea Nova Hosting Solution Ltd). Broad List*/Describe* patterns are intentionally omitted to reduce noise. Hosting ASNs are heavily dual-use; validate source.as.number in your data and extend event.action only when your baseline allows it.T1526, T1580↳ also matches DescribeRegions, DescribeSecurityGroups, DescribeVpcs

References #

DescribeRegions

#
Service
ec2

Description

Returns the AWS regions that are enabled for the caller's account, or all regions that are available to EC2.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "768ef4f1-4721-40e0-82d7-5504605a380b",
  "eventName": "DescribeRegions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:13:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "5ae4a7b8-8972-46a0-bee8-a1d0f4a42995",
  "requestParameters": {
    "allRegions": true,
    "regionSet": {}
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:102.0) Gecko/20100101 Firefox/102.0",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCXBBR47W6",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:13:16Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::userIdentity.arn (elastic rule field)is_not_null1 ruleelastic
source.as.number (elastic rule field)in90091 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS Discovery API Calls from VPN ASN for the First Time by Identity source high: Flags the first time a given IAM principal invokes a narrow set of high-signal discovery APIs (credential check, account and IAM enumeration, bucket and compute inventory, logging introspection) from a source IP whose autonomous system number (ASN) matches a curated set commonly associated with consumer VPN brands, VPN-heavy hosting, and provider networks referenced in public reporting on TeamPCP activity (for example 31173 Services AB AS39351 and Oy Crea Nova Hosting Solution Ltd). Broad List*/Describe* patterns are intentionally omitted to reduce noise. Hosting ASNs are heavily dual-use; validate source.as.number in your data and extend event.action only when your baseline allows it.T1526, T1580↳ also matches DescribeInstances, DescribeSecurityGroups, DescribeVpcs

References #

DescribeSecurityGroups

#
Service
ec2

Description

Returns information about one or more EC2 security groups, including their inbound and outbound rules.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:58:37Z",
  "eventSource": "ec2.amazonaws.com",
  "eventName": "DescribeSecurityGroups",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/n,Z,E,C,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#ec2.describe-security-groups",
  "requestParameters": {
    "securityGroupSet": {},
    "securityGroupIdSet": {
      "items": [
        {
          "groupId": "sg-0200d267c43de2fbc"
        }
      ]
    },
    "filterSet": {}
  },
  "responseElements": null,
  "requestID": "f04bdef2-c53f-4d23-891f-e8985aee8427",
  "eventID": "f3497cf7-0b5b-4b9c-8606-7c5501702693",
  "readOnly": true,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::userIdentity.arn (elastic rule field)is_not_null1 ruleelastic
source.as.number (elastic rule field)in90091 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS Discovery API Calls from VPN ASN for the First Time by Identity source high: Flags the first time a given IAM principal invokes a narrow set of high-signal discovery APIs (credential check, account and IAM enumeration, bucket and compute inventory, logging introspection) from a source IP whose autonomous system number (ASN) matches a curated set commonly associated with consumer VPN brands, VPN-heavy hosting, and provider networks referenced in public reporting on TeamPCP activity (for example 31173 Services AB AS39351 and Oy Crea Nova Hosting Solution Ltd). Broad List*/Describe* patterns are intentionally omitted to reduce noise. Hosting ASNs are heavily dual-use; validate source.as.number in your data and extend event.action only when your baseline allows it.T1526, T1580↳ also matches DescribeInstances, DescribeRegions, DescribeVpcs

Panther #

DescribeSnapshotAttribute

#
Service
ec2

Description

Describes the specified attribute of the specified EBS snapshot.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventCategory": "Management",
  "eventID": "d37285d0-239e-4538-ac85-88c5991c5648",
  "eventName": "DescribeSnapshotAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-01-12T09:28:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "111111111111",
  "requestID": "0ddf29d3-18c0-42f2-9eae-bec31b8ce549",
  "requestParameters": {
    "attributeType": "CREATE_VOLUME_PERMISSION",
    "snapshotId": "snap-0645a5c03e1a975db"
  },
  "responseElements": null,
  "sourceIPAddress": "204.107.141.240",
  "userAgent": "Boto3/1.10.32 Python/3.6.8 Linux/3.10.0-1062.18.1.el7.x86_64 Botocore/1.13.32",
  "userIdentity": {
    "accessKeyId": "ASIAYTOGP2RLP6F5ACON",
    "accountId": "111111111111",
    "arn": "arn:aws:sts::111111111111:assumed-role/okta_ro_role/botocore-session-1610443391",
    "principalId": "AROAIJN34TPOD7C3TZWUU:botocore-session-1610443391",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-01-12T09:23:12Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "111111111111",
        "arn": "arn:aws:iam::111111111111:role/okta_ro_role",
        "principalId": "AROAIJN34TPOD7C3TZWUU",
        "type": "Role",
        "userName": "okta_ro_role"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Splunk #

References #

DescribeSnapshotTierStatus

#
Service
ec2

Description

Describes the storage tier status of one or more EBS snapshots.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "836a322f-11fb-41f7-8272-9bb859e6a926",
  "eventName": "DescribeSnapshotTierStatus",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "5e9ae186-ef08-4de0-981e-dd7b94b8e68c",
  "requestParameters": {
    "DescribeSnapshotTierStatusRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeTransitGatewayMulticastDomains

#
Service
ec2

Description

Describes one or more transit gateway multicast domains.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "60485-5d74-4871-8c9a-dbf7b5d3582d",
  "eventName": "DescribeTransitGatewayMulticastDomains",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-06-10T05:33:39Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "e0078a3c-a69b-48b6-a029-28bf79f4a16f",
  "requestParameters": {
    "DescribeTransitGatewayMulticastDomainsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeVolumes

#
Service
ec2

Description

Describes the specified EBS volumes or all EBS volumes in the account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "29d37c53-9ab1-4702-8d11-0171eef6a77a",
  "eventName": "DescribeVolumes",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:27:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "eedef094-959c-4622-b910-d411eeac345c",
  "requestParameters": {
    "filterSet": {},
    "maxResults": 1000,
    "volumeSet": {}
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCVDQK5XKV",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeVolumesModifications

#
Service
ec2

Description

Describes the most recent volume modification request for the specified EBS volumes.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "01df144b-e838-4f5b-8675-a40529a6b344",
  "eventName": "DescribeVolumesModifications",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-07-07T15:55:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "43633774-1f66-404c-8816-7324e34ac161",
  "requestParameters": {
    "DescribeVolumesModificationsRequest": {
      "MaxResults": 1000
    }
  },
  "responseElements": null,
  "sourceIPAddress": "167.98.108.182",
  "userAgent": "console.ec2.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI37YFF5PNWP",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/sean",
    "principalId": "AIDA3TLZJI375TCG5FSRI",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:56:28Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "sean"
  }
}

References #

DescribeVpcEndpointConnectionNotifications

#
Service
ec2

Description

Describes the connection notifications for VPC endpoints and VPC endpoint services.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "233c2756-f647-4128-bb73-176bfba6327b",
  "eventName": "DescribeVpcEndpointConnectionNotifications",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-10-17T20:11:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "ab35edeb-dfb0-49c0-b377-dcbbcd5be9f4",
  "requestParameters": {
    "DescribeVpcEndpointConnectionNotificationsRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeVpcs

#
Service
ec2

Description

Returns information about one or more VPCs in the account, including their CIDR blocks, state, and associated attributes.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:58:31Z",
  "eventSource": "ec2.amazonaws.com",
  "eventName": "DescribeVpcs",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/n,Z,E,C,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#ec2.describe-vpcs",
  "requestParameters": {
    "vpcSet": {},
    "filterSet": {
      "items": [
        {
          "name": "isDefault",
          "valueSet": {
            "items": [
              {
                "value": "true"
              }
            ]
          }
        }
      ]
    }
  },
  "responseElements": null,
  "requestID": "f4bb2659-877f-4199-8872-ed3e7d11f7c7",
  "eventID": "062f0dd4-20bf-49e3-b194-b598a8cd72e3",
  "readOnly": true,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
source.as.number (elastic rule field)in90091 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS Discovery API Calls from VPN ASN for the First Time by Identity source high: Flags the first time a given IAM principal invokes a narrow set of high-signal discovery APIs (credential check, account and IAM enumeration, bucket and compute inventory, logging introspection) from a source IP whose autonomous system number (ASN) matches a curated set commonly associated with consumer VPN brands, VPN-heavy hosting, and provider networks referenced in public reporting on TeamPCP activity (for example 31173 Services AB AS39351 and Oy Crea Nova Hosting Solution Ltd). Broad List*/Describe* patterns are intentionally omitted to reduce noise. Hosting ASNs are heavily dual-use; validate source.as.number in your data and extend event.action only when your baseline allows it.T1526, T1580↳ also matches DescribeInstances, DescribeRegions, DescribeSecurityGroups

DisableEbsEncryptionByDefault

#
Service
ec2

Description

Disables default EBS encryption for EBS volumes created in the current account and Region.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "0ad6b464-f2c5-4aa4-8a00-f4eeeb2319b0",
  "eventName": "DisableEbsEncryptionByDefault",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:43:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "33810299-5768-4cb3-a200-3142f2c59930",
  "requestParameters": {
    "DisableEbsEncryptionByDefaultRequest": ""
  },
  "responseElements": {
    "DisableEbsEncryptionByDefaultResponse": {
      "ebsEncryptionByDefault": false,
      "requestId": "33810299-5768-4cb3-a200-3142f2c59930",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

  • AWS EC2 Disable EBS Encryption source medium: Identifies disabling of default Amazon Elastic Block Store (EBS) encryption in the current region. Disabling default encryption does not change the encryption status of your existing volumes.T1486, T1565

Elastic #

  • AWS EC2 Encryption Disabled source medium: Detects when Amazon Elastic Block Store (EBS) encryption by default is disabled in an AWS region. EBS encryption ensures that newly created volumes and snapshots are automatically protected with AWS Key Management Service (KMS) keys. Disabling this setting introduces significant risk as all future volumes created in that region will be unencrypted by default, potentially exposing sensitive data at rest. Adversaries may disable encryption to weaken data protection before exfiltrating or tampering with EBS volumes or snapshots. This may be a step in preparation for data theft or ransomware-style attacks that depend on unencrypted volumes.T1565, T1565.001, T1578, T1578.005

Panther #

DisassociateRouteTable

#
Service
ec2

Description

Disassociates a subnet or gateway from a route table.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "93487b25-01bb-410b-aa05-57565fca5172",
  "eventName": "DisassociateRouteTable",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:08:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "b31ac506-39c4-45f7-8f4f-2ec4c591e881",
  "requestParameters": {
    "associationId": "rtbassoc-06c42ea03f0967f18"
  },
  "responseElements": {
    "_return": true,
    "associationState": {
      "state": "disassociating"
    },
    "requestId": "b31ac506-39c4-45f7-8f4f-2ec4c591e881"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

References #

EnableSerialConsoleAccess

#
Service
ec2

Description

Enables access to the EC2 serial console for EC2 instances in the current account and Region.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "2e2ce75c-8a37-47c1-8056-f56502adace4",
  "eventName": "EnableSerialConsoleAccess",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:43:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "02003b33-61fe-435b-be78-9643837ac48c",
  "requestParameters": {
    "EnableSerialConsoleAccessRequest": ""
  },
  "responseElements": {
    "EnableSerialConsoleAccessResponse": {
      "requestId": "02003b33-61fe-435b-be78-9643837ac48c",
      "serialConsoleAccessEnabled": true,
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS EC2 Serial Console Access Enabled source high: Detects when EC2 Serial Console Access is enabled for an AWS account. The EC2 Serial Console provides direct, text-based access to an instance's serial port, bypassing the network layer entirely. While useful for troubleshooting boot issues or network misconfigurations, enabling serial console access in production environments is rare and potentially dangerous. Adversaries may enable this feature to establish an out-of-band communication channel that evades network-based security monitoring, firewalls, and VPC controls. This access method can be used for persistent backdoor access or to interact with compromised instances without triggering network-based detection mechanisms.T1562, T1562.001, T1578, T1578.005

ExportImage

#
Service
ec2

Description

Exports an Amazon Machine Image (AMI) to an Amazon S3 bucket.

CloudTrail management event, logged by default. No sample available (sample_count=0); event_class grounded from the AWS API reference (this is a control-plane operation that initiates an export task).

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS EC2 Export Task source medium: Identifies successful export tasks of EC2 instances via the APIs CreateInstanceExportTask, ExportImage, or CreateStoreImageTask. These exports can be used by administrators for legitimate VM migration or backup workflows however, an attacker with access to an EC2 instance or AWS credentials can export a VM or its image and then transfer it off-account for exfiltration of data.T1005, T1119, T1530, T1537, T1567, T1567.002↳ also matches CreateInstanceExportTask, CreateStoreImageTask

GetEbsDefaultKmsKeyId

#
Service
ec2

Description

Retrieves the default KMS key ID used for EBS encryption in the current Region.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "068e39b3-a0f9-4047-83f9-51ab1796a488",
  "eventName": "GetEbsDefaultKmsKeyId",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-05-19T17:44:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "54a851283-7d31-4ebe-b4f4-e1b2407f4b8a",
  "requestParameters": {
    "GetEbsDefaultKmsKeyIdRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "255.251.4.254",
  "userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

GetEbsEncryptionByDefault

#
Service
ec2

Description

Retrieves the default EBS encryption setting for the current account and Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventCategory": "Management",
  "eventID": "db7028ca-6e33-4502-a166-b548f996bf6d",
  "eventName": "GetEbsEncryptionByDefault",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-01-12T08:37:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "111111111111",
  "requestID": "22bbe5a2-251a-4170-9909-6cc6b9ae7fbb",
  "requestParameters": {
    "GetEbsEncryptionByDefaultRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "config.amazonaws.com",
  "userAgent": "config.amazonaws.com",
  "userIdentity": {
    "accountId": "111111111111",
    "arn": "arn:aws:sts::111111111111:assumed-role/config-role-us-west-2/configLambdaExecution",
    "invokedBy": "config.amazonaws.com",
    "principalId": "AROAIQ3J3AWJKHZRVZC62:configLambdaExecution",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-01-12T08:37:19Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "111111111111",
        "arn": "arn:aws:iam::111111111111:role/service-role/config-role-us-west-2",
        "principalId": "AROAIQ3J3AWJKHZRVZC62",
        "type": "Role",
        "userName": "config-role-us-west-2"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

References #

GetPasswordData

#
Service
ec2

Description

Retrieves the encrypted administrator password for a Windows instance.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation. Encoded authorization failure message: 1Qju1r-MUd3Ls-t7y4w4lpDtgZ-SW3htXqO4UWyYc3RRm71l29ME4w3IIewWhVC8ebqeZswLhkaNtKJcthIjmcqywqV1VgZqs4N-GL8hiyqyOvRy9rmG-ngQIz_Kcpi0mGOOCMd6TWGim0j6xYTiUVvdWURwLDOA5tPeD3lbCq13-0U29FMpt9V4D3RP_gUQ0gWAED4heCGuWygNHtwkM7kapWT0U_reDDIrpM6BANEpBV8hUZ0DM3Pd8arpnHnzQ93N0PZ8Agcw049fARhceT4yM1xMJw8T_iDnU2sgAJvj22MhubJf0Ni0jkEG3OyumbfAa-P7dlqGXT6Qj5FxVSnNOXfmowCbAgQWd9iJuNNpBt6HuYcUhNVhBOGaqNdsFLSqontKFUCCJoOQnBnV4xnIfVEXOUNUZyp8vg6tKI7ieoB71iiIjvLBB7SlSr9raQxnVLu8iPNDEpfLNlDBcFqlZ2PByaW21xKcLRqBFYJchBVhImo_ICrk8-Y_hisEL1L7IAiZASUYyRp5Xsm_uVY6GDIBaQfaegL7ZTOpMvs3OMd3oHW9uJkkp5ButArvKh4TNHwtW2OVkg",
  "eventCategory": "Management",
  "eventID": "fbd91225-39aa-4c00-822c-9f0b96e7758f",
  "eventName": "GetPasswordData",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:54:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "466cd3e7-0a68-4487-851f-d41c9145180f",
  "requestParameters": {
    "instanceId": "i-durz4ux740gjqvcm"
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "stratus-red-team_39f95f43-cd2f-4beb-b69e-be60b6fe1f57",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCWLLE7IWW",
    "accountId": "123837392027",
    "arn": "arn:aws:sts::123837392027:assumed-role/stratus-red-team-ec2-get-password-data-role/aws-go-sdk-1688990082523310002",
    "principalId": "AROATFQR7NSCWWVLB7BES:aws-go-sdk-1688990082523310002",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T11:54:47Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "123837392027",
        "arn": "arn:aws:iam::123837392027:role/stratus-red-team-ec2-get-password-data-role",
        "principalId": "AROATFQR7NSCWWVLB7BES",
        "type": "Role",
        "userName": "stratus-red-team-ec2-get-password-data-role"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::errorCode (elastic rule field)eqclient.unauthorizedoperation1 ruleelastic
aws::userIdentity.type (elastic rule field)eqassumedrole1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Splunk #

YARA-L #

Panther #

References #

GetTransitGatewayRouteTableAssociations

#
Service
ec2

Description

Gets information about the route table associations for the specified transit gateway route table.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "f4cd8da2-af3d-4b72-94f4-3a66822b40d0",
  "eventName": "GetTransitGatewayRouteTableAssociations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-05-19T17:44:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "72a841bf-9080-464e-8e0b-424d9975aa74",
  "requestParameters": {
    "GetTransitGatewayRouteTableAssociationsRequest": {
      "TransitGatewayRouteTableId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "255.251.4.254",
  "userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

ImportKeyPair

#
Service
ec2

Description

Imports the public key from an RSA or ED25519 key pair that you created with a third-party tool.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "84583c7-6829-4f84-b2d8-641fc3245b60",
  "eventName": "ImportKeyPair",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-07-12T13:32:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "be0e5d91-ffca-431f-8cf7-c318f71ade28",
  "requestParameters": {
    "keyName": "p0wn3d",
    "publicKeyMaterial": "YzNOb0xYSnpZU0JCUVVGQlFqTk9lbUZETVhsak1rVkJRVUZCUkVGUlFVSkJRVUZEUVZGRVRHVlNiRkpvTldWemRUTjJiemszTWxGbVNYY3pLelpzVTJ0NGNqUm1abVp4Y0dWd1JuTnFiRkZyZG1OM1NrVlNUR0pFWWs5QmEzQkVaVFJGWmxOaFEyVm9TbmxHWjBoTVRYbDVNMkpwYzJKeGJXUlVlbTUzZFhoRk1rMDRZWEI2Tkc1MmRtcENVVFJ2YWt4TFprRlllVFI1VERGb1lWTkJSVkJMYjFBeE1YRnBkRlo1UWtzcldFbEdMMWwxWlhwdFNscEhlR2hGTVZjMEwydDBUMnRoUVZaRGJqaHJXU3REVERaSlJqaFVlRkIxVFRWUFkwUk5PR1J3UkU0NVptZFBVbXh5Y0dsWmF6ZDNObnBYTWpoQmJWcHBkazVrV2xCREsxVlRWWEJJU25ZMk1GY3lSMUZ2Vm1KTGVHZGhTbXhyWTNGV2N6RnBWRGxqVW1aalVXSXllaXR0YkhNMEsxZHlNWEYwWjNaU04wMUdiblpwVW0xUGMzVm5kM1l6WVVSTFZUSjZUbnAwY1V4MFpFWTVTR2d3YUdWNlYyOUllbWQxUnpWVWJTOU1VV3A1WWtaVVdTOWlPSGxSTld0YVVVRnVTMnRNZFdWamMwOUpSalpUWlVaeGNtWnJOM3BaUVZaQ2VGaFVUV1kzYkdOWGNVcFlObEZJZGtvd1ptMW5VWFJVVVhBMWJrVjVVbTVTYjI1UGF5OTFkMEl6VVRVMlQwMVpXVGRxYVRRM1QyVXJha3RJVldJdk5FMVJMMVUzY1RSUVMxTlRObmhRUVRWU2RXOVNSbXhqZW5wSVpWWnFRVFIzVFZOTGEzZHJNRFZWUmtWb1ptVlRibVZoWnl0M1EyODBlbWxMZFV0aVpIaEJWRWRaWlhCQlQxZFhNakZyTUZOeWIwbFdUSGxCTVhZMmVGSk5heko0VjJOdmVYcEVaRVpzV1ZOSFdYQlRNVFpJTW5sUE0xRmhSSGRvT1VOc1YxZ3pWbmxLUlVoYVYwOHdUbnBhYURCRVJuTm1SelZCUzJRMk5sZFdXbFpIVEdoV1kyNWlOWFpLUVdsbVVFcDVPR280TVZJclJUZHBXVFZxUnpSeFVGWkVlQzk1VEVWbVJUTnBVbmd5VEdWbk9WQTVTV3BsTlZsMmFteFRhMDU1YnpaUU5FSnlMelJPYzA5TlNEbFBRbTFsU1ZWUWNDOWFOV1EyY21jM1VESTBkVVp3VUhjOVBTQm1iR0YzY3k1amJHOTFaQW89"
  },
  "responseElements": null,
  "sourceIPAddress": "62.252.86.211",
  "userAgent": "aws-cli/1.10.59 Python/2.7.10 Darwin/16.6.0 botocore/1.4.49",
  "userIdentity": {
    "accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

  • AWS Key Pair Import Activity source medium: Detects the import of SSH key pairs into AWS EC2, which may indicate an attacker attempting to gain unauthorized access to instances. This activity could lead to initial access, persistence, or privilege escalation, potentially compromising sensitive data and operations.T1078

References #

ModifyImageAttribute

#
Service
ec2

Description

Modifies the specified attribute of the specified AMI, such as launch permissions or description.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "8fe3095f-909c-41f5-a769-00b9ec6e95df",
  "eventName": "ModifyImageAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:11:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "9a32473d-7495-4050-aa14-572331ab538d",
  "requestParameters": {
    "attributeType": "launchPermission",
    "imageId": "ami-0aa1d83d0b0985c86",
    "launchPermission": {
      "add": {
        "items": [
          {
            "userId": "012345678901"
          }
        ]
      }
    }
  },
  "responseElements": {
    "_return": true,
    "requestId": "9a32473d-7495-4050-aa14-572331ab538d"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "stratus-red-team_b47d6b97-21d3-4b01-8937-6f0c23cb2d4b",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::requestParameters (elastic rule field)containsadd=1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS EC2 AMI Shared with Another Account source high: Identifies an AWS Amazon Machine Image (AMI) being shared with another AWS account. Adversaries with access may share an AMI with an external AWS account as a means of data exfiltration. AMIs can contain secrets, bash histories, code artifacts, and other sensitive data that adversaries may abuse if shared with unauthorized accounts. AMIs can be made publicly available accidentally as well.T1537

Splunk #

  • AWS AMI Attribute Modification for Exfiltration source: The following analytic detects suspicious modifications to AWS AMI attributes, such as sharing an AMI with another AWS account or making it publicly accessible. It leverages AWS CloudTrail logs to identify these changes by monitoring…T1537

YARA-L #

References #

ModifyInstanceAttribute

#
Service
ec2

Description

Modifies the specified attribute of the specified EC2 instance, such as instance type or user data.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "1bb6c2f9-b96b-485d-92ad-380e4be8b1b1",
  "eventName": "ModifyInstanceAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:08:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "6920dcec-599d-43ff-8718-060e4ca65a2a",
  "requestParameters": {
    "disableApiTermination": {
      "value": false
    },
    "instanceId": "i-0dbc91f429e48eeed"
  },
  "responseElements": {
    "_return": true,
    "requestId": "6920dcec-599d-43ff-8718-060e4ca65a2a"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::userIdentity.type (elastic rule field)neawsservice1 ruleelastic
readOnly (panther rule field)is_null1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Kusto #

YARA-L #

Panther #

References #

ModifySecurityGroupRules

#
Service
ec2

Description

Modifies the rules of a security group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidGroupId.Malformed",
  "errorMessage": "Invalid id: \"dw-probe\"",
  "eventCategory": "Management",
  "eventID": "3c366502-f456-49ff-997d-a17a03b76096",
  "eventName": "ModifySecurityGroupRules",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c6abadad-be41-41f2-b579-e900640d2fa9",
  "requestParameters": {
    "ModifySecurityGroupRulesRequest": {
      "GroupId": "dw-probe",
      "SecurityGroupRule": {
        "SecurityGroupRuleId": "dw-probe",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

ModifySnapshotAttribute

#
Service
ec2

Description

Adds or removes permission settings for the specified EBS snapshot, such as sharing it with other accounts.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "3ad01b1d-ebc1-4830-994b-9210534ab9f2",
  "eventName": "ModifySnapshotAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:11:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "f088a80d-123f-419d-9970-51fb5ee592b3",
  "requestParameters": {
    "attributeType": "CREATE_VOLUME_PERMISSION",
    "createVolumePermission": {
      "remove": {
        "items": [
          {
            "userId": "012345678912"
          }
        ]
      }
    },
    "snapshotId": "snap-083d3b857c13988bc"
  },
  "responseElements": {
    "_return": true,
    "requestId": "f088a80d-123f-419d-9970-51fb5ee592b3"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "stratus-red-team_8bec4cee-9e27-423f-a9af-2e0b8f6407f3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::requestParameters (elastic rule field)containsattributetype=create_volume_permission2 ruleselastic
aws::requestParameters (elastic rule field)containsadd=1 ruleelastic

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

  • AWS EC2 EBS Snapshot Shared or Made Public source medium: Detects when an Amazon Elastic Block Store (EBS) snapshot is shared with another AWS account or made public. EBS snapshots contain copies of data volumes that may include sensitive or regulated information. Adversaries may exploit ModifySnapshotAttribute to share snapshots with external accounts or the public, allowing them to copy and access data in an environment they control. This activity often precedes data exfiltration or persistence operations, where the attacker transfers stolen data out of the victim account or prepares a staging area for further exploitation.T1537
  • AWS EC2 EBS Snapshot Access Removed source medium: Identifies the removal of access permissions from a shared AWS EC2 EBS snapshot. EBS snapshots are essential for data retention and disaster recovery. Adversaries may revoke or modify snapshot permissions to prevent legitimate users from accessing backups, thereby obstructing recovery efforts after data loss or destructive actions. This tactic can also be used to evade detection or maintain exclusive access to critical backups, ultimately increasing the impact of an attack and complicating incident response.T1485, T1490, T1578, T1578.005

Splunk #

  • ASL AWS EC2 Snapshot Shared Externally source: The following analytic detects when an EC2 snapshot is shared publicly by analyzing AWS CloudTrail events. This detection method leverages CloudTrail logs to identify modifications in snapshot permissions, specifically when the snapshot is…T1537
  • AWS EC2 Snapshot Shared Externally source: The following analytic detects when an EC2 snapshot is shared with an external AWS account by analyzing AWS CloudTrail events. This detection method leverages CloudTrail logs to identify modifications in snapshot permissions, specifically…T1537
  • AWS Exfiltration via EC2 Snapshot source: The following analytic detects a series of AWS API calls related to EC2 snapshots within a short time window, indicating potential exfiltration via EC2 Snapshot modifications. It leverages AWS CloudTrail logs to identify actions such as…T1537↳ also matches DescribeSnapshotAttribute

YARA-L #

Panther #

References #

ReplaceNetworkAclEntry

#
Service
ec2

Description

Replaces an entry (rule) in a network ACL, changing subnet traffic filtering.

Example CloudTrail Event #

{
  "awsRegion": "eu-central-1",
  "eventCategory": "Management",
  "eventID": "46fe04b8-d007-4933-8bb8-c8b65c1121fa",
  "eventName": "ReplaceNetworkAclEntry",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-01-12T08:49:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "111111111111",
  "requestID": "97b40da9-9291-4a92-8e9e-892b6887ffc9",
  "requestParameters": {
    "aclProtocol": "-1",
    "cidrBlock": "0.0.0.0/0",
    "egress": false,
    "icmpTypeCode": {},
    "networkAclId": "acl-078ccebebcbabe175",
    "portRange": {},
    "ruleAction": "allow",
    "ruleNumber": 20
  },
  "responseElements": {
    "_return": true,
    "requestId": "97b40da9-9291-4a92-8e9e-892b6887ffc9"
  },
  "sourceIPAddress": "95.90.199.65",
  "userAgent": "console.ec2.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "ASIAYTOGP2RLF3F7BXZK",
    "accountId": "111111111111",
    "arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
    "principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-01-12T08:36:15Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "111111111111",
        "arn": "arn:aws:iam::111111111111:role/okta_adm_role",
        "principalId": "AROAIJIESMXKGCJRCTPR6",
        "type": "Role",
        "userName": "okta_adm_role"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aclProtocoleq-12 ruleskusto, splunk
egresseqfalse2 ruleskusto, splunk
ruleActioneqallow2 ruleskusto, splunk
event.outcome (elastic rule field)insuccess1 ruleelastic
requestParameters.egress (splunk rule field)eqfalse1 rulesplunk
requestParameters.ruleAction (splunk rule field)eqallow1 rulesplunk

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS EC2 NACL Entry Created or Replaced Allowing All Traffic by New Identity source medium: Detects a principal account creating or replacing - or attempts to create or replace - an AWS Network Access Control List (NACL) entry using protocol -1 (all traffic). Both successful and failed outcomes are included. A NACL entry with protocol -1 passes all traffic regardless of port, which would disable network-layer controls for the affected subnets. Monitoring for new identities performing this change helps surface freshly compromised credentials or unauthorized principals removing a defense-in-depth layer to facilitate lateral movement or data exfiltration. This signal only flags if this behavior was not observed historically in a specific time window.T1562, T1562.007↳ also matches CreateNetworkAclEntry

Splunk #

Kusto #

Panther #

References #

ReplaceRoute

#
Service
ec2

Description

Replaces an existing route within a route table in a VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "e3375d69-4b28-4ff6-9666-66827aab6d05",
  "eventName": "ReplaceRoute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:59:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3d677f6d-dede-423a-8b82-56888201c93f",
  "requestParameters": {
    "destinationCidrBlock": "0.0.0.0/0",
    "gatewayId": "igw-0dbea4ea3477eb902",
    "routeTableId": "rtb-0ddfb417e20642f73"
  },
  "responseElements": {
    "_return": true,
    "requestId": "3d677f6d-dede-423a-8b82-56888201c93f"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

ReplaceRouteTableAssociation

#
Service
ec2

Description

Changes the route table associated with a given subnet, internet gateway, or virtual private gateway in a VPC.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:58:49Z",
  "eventSource": "ec2.amazonaws.com",
  "eventName": "ReplaceRouteTableAssociation",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#ec2.replace-route-table-association",
  "requestParameters": {
    "associationId": "rtbassoc-0c6f61e58e08fd22b",
    "routeTableId": "rtb-0ec9cda21de307a6b"
  },
  "responseElements": {
    "requestId": "1dc9f17c-400f-4780-a4f8-5df00e02d775",
    "newAssociationId": "rtbassoc-0e791b0a24b6d08c2",
    "associationState": {
      "state": "associated"
    }
  },
  "requestID": "1dc9f17c-400f-4780-a4f8-5df00e02d775",
  "eventID": "8bd1155a-a61a-4f1e-9a1f-b29bfe42e377",
  "readOnly": false,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

Panther #

RevokeSecurityGroupEgress

#
Service
ec2

Description

Removes outbound rules from a security group.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "d2dedbf2-62a8-4362-bcad-aa1670e80c0f",
  "eventName": "RevokeSecurityGroupEgress",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:10:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "5fbf4781-20ed-475e-94b4-0159c242c255",
  "requestParameters": {
    "groupId": "sg-04cfb7a4712d75b00",
    "ipPermissions": {
      "items": [
        {
          "fromPort": 0,
          "groups": {},
          "ipProtocol": "-1",
          "ipRanges": {
            "items": [
              {
                "cidrIp": "0.0.0.0/0"
              }
            ]
          },
          "ipv6Ranges": {},
          "prefixListIds": {},
          "toPort": 0
        }
      ]
    }
  },
  "responseElements": {
    "_return": true,
    "requestId": "5fbf4781-20ed-475e-94b4-0159c242c255"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_2142a106-933f-4595-ad51-0ff5dfff60b7 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Kusto #

Panther #

References #

RevokeSecurityGroupIngress

#
Service
ec2

Description

Removes inbound rules from a security group.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "8733f811-267d-4c46-8e5b-000fe7c6a9f2",
  "eventName": "RevokeSecurityGroupIngress",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:11:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "d7ba453f-54ce-4c38-98a1-01757c45994e",
  "requestParameters": {
    "cidrIp": "0.0.0.0/0",
    "fromPort": 22,
    "groupId": "sg-04cfb7a4712d75b00",
    "ipPermissions": {},
    "ipProtocol": "tcp",
    "toPort": 22
  },
  "responseElements": {
    "_return": true,
    "requestId": "d7ba453f-54ce-4c38-98a1-01757c45994e"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "stratus-red-team_4277e8d8-8ab5-4267-a2da-439e2df93964",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Sigma #

Elastic #

Kusto #

Panther #

References #

StartInstances

#
Service
ec2

Description

Starts one or more stopped EC2 instances, transitioning them to the running state.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "177b7f6d-b28d-4d45-a1fd-cf4c4ca49d65",
  "eventName": "StartInstances",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-07-07T17:31:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "797507667711",
  "requestID": "6ace67aa-1ddd-4af1-a5ec-a17a0d9db71c",
  "requestParameters": {
    "instancesSet": {
      "items": [
        {
          "instanceId": "i-0c13b9b6d209978fc"
        }
      ]
    }
  },
  "responseElements": {
    "instancesSet": {
      "items": [
        {
          "currentState": {
            "code": 16,
            "name": "running"
          },
          "instanceId": "i-0c13b9b6d209978fc",
          "previousState": {
            "code": 16,
            "name": "running"
          }
        }
      ]
    },
    "requestId": "6ace67aa-1ddd-4af1-a5ec-a17a0d9db71c"
  },
  "sourceIPAddress": "3.142.206.200",
  "userAgent": "Boto3/1.17.24 Python/3.6.13 Linux/4.19.0-17-cloud-amd64 Botocore/1.20.98 Resource",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI37S4KUWNVD",
    "accountId": "797507667711",
    "arn": "arn:aws:sts::797507667711:assumed-role/Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG/1625678983.751919",
    "principalId": "AROA3TLZJI37S6HPJWVJ2:1625678983.751919",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T17:29:43Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "797507667711",
        "arn": "arn:aws:iam::797507667711:role/Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG",
        "principalId": "AROA3TLZJI37S6HPJWVJ2",
        "type": "Role",
        "userName": "Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::userIdentity.type (elastic rule field)neawsservice1 ruleelastic
readOnly (panther rule field)is_null1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS EC2 Stop, Start, and User Data Modification Correlation source high: Identifies a short sequence of EC2 management APIs against the same instance that is consistent with modifying instance user data and forcing it to run on the next boot: ModifyInstanceAttribute with user data, followed by stop and start. Adversaries may update userData and cycle instance state so malicious scripts execute as root on Linux or as the system context on Windows. This rule correlates successful StopInstances, StartInstances, and ModifyInstanceAttribute events that reference userData within a five-minute window, grouped by instance, user.name, account, source IP, and user agent. A hit requires exactly three distinct API names in that bucket.T1059, T1059.009, T1578↳ also matches ModifyInstanceAttribute, StopInstances

Panther #

References #

StopInstances

#
Service
ec2

Description

Stops one or more running EC2 instances, transitioning them to the stopped state.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidInstanceID.NotFound",
  "errorMessage": "The instance ID 'i-aa2d3b42e5c6e801a' does not exist",
  "eventID": "dc0dfe91-d710-44c7-9329-582a892fa67d",
  "eventName": "StopInstances",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-04-07T08:41:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "23840-7c24-4527-895e-95133564543b",
  "requestParameters": {
    "force": false,
    "instancesSet": {
      "items": [
        {
          "instanceId": "i-aa2d3b42e5c6e801a"
        }
      ]
    }
  },
  "responseElements": null,
  "sourceIPAddress": "253.246.250.252",
  "userAgent": "aws-cli/1.11.72 Python/2.7.10 Darwin/15.6.0 botocore/1.5.35",
  "userIdentity": {
    "accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::userIdentity.type (elastic rule field)neawsservice1 ruleelastic
readOnly (panther rule field)is_null1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS EC2 Stop, Start, and User Data Modification Correlation source high: Identifies a short sequence of EC2 management APIs against the same instance that is consistent with modifying instance user data and forcing it to run on the next boot: ModifyInstanceAttribute with user data, followed by stop and start. Adversaries may update userData and cycle instance state so malicious scripts execute as root on Linux or as the system context on Windows. This rule correlates successful StopInstances, StartInstances, and ModifyInstanceAttribute events that reference userData within a five-minute window, grouped by instance, user.name, account, source IP, and user agent. A hit requires exactly three distinct API names in that bucket.T1059, T1059.009, T1578↳ also matches ModifyInstanceAttribute, StartInstances

Panther #

References #

AcceptAddressTransfer

#
Service
ec2

Description

Accepts an Elastic IP address transfer.

AcceptCapacityReservationBillingOwnership

#
Service
ec2

Description

Accepts a request to assign billing of the available capacity of a shared Capacity Reservation to your account.

AcceptReservedInstancesExchangeQuote

#
Service
ec2

Description

Purchases Convertible Reserved Instance offerings described in the GetReservedInstancesExchangeQuote call.

AcceptTransitGatewayClientVpnAttachment

#
Service
ec2

Description

Accepts a Transit Gateway attachment request for a Client VPN endpoint.

AcceptTransitGatewayMulticastDomainAssociations

#
Service
ec2

Description

Accepts a request to associate subnets with a transit gateway multicast domain.

AcceptTransitGatewayPeeringAttachment

#
Service
ec2

Description

Accepts a transit gateway peering attachment request.

AcceptTransitGatewayVpcAttachment

#
Service
ec2

Description

Accepts a request to attach a VPC to a transit gateway.

AcceptVpcEndpointConnections

#
Service
ec2

Description

Accepts connection requests to your VPC endpoint service.

AcceptVpcPeeringConnection

#
Service
ec2

Description

Accept a VPC peering connection request.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "The request must contain the parameter vpcPeeringConnectionId",
  "eventID": "1a15843b-adb2-4d39-8461-ce2708d95fb0",
  "eventName": "AcceptVpcPeeringConnection",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2019-11-17T04:57:39Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "25a99520-381c-431f-b22e-b74a16171dac",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "8.103.248.255",
  "userAgent": "aws-cli/1.14.44 Python/3.6.8 Linux/4.4.0-039049-Microsoft botocore/1.8.48",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

AdvertiseByoipCidr

#
Service
ec2

Description

Advertises an IPv4 or IPv6 address range that is provisioned for use with your Amazon Web Services resources through bring your own IP addresses (BYOIP).

AllocateAddress

#
Service
ec2

Description

Acquires an Elastic IP address.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "a4ff516f-8f9a-4c36-9700-b31a883c1a6e",
  "eventName": "AllocateAddress",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:08Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "c6671a81-468c-41e2-abd5-0ec843ee0db3",
  "requestParameters": {
    "domain": "vpc",
    "tagSpecificationSet": {
      "items": [
        {
          "resourceType": "elastic-ip",
          "tags": [
            {
              "key": "StratusRedTeam",
              "value": "true"
            },
            {
              "key": "Name",
              "value": "stratus-red-team-ec2-steal-credentials-vpc-us-east-1a"
            }
          ]
        }
      ]
    }
  },
  "responseElements": {
    "allocationId": "eipalloc-08a083beb7e83dbc0",
    "domain": "vpc",
    "networkBorderGroup": "us-east-1",
    "publicIp": "3.225.16.109",
    "publicIpv4Pool": "amazon",
    "requestId": "c6671a81-468c-41e2-abd5-0ec843ee0db3"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

AllocateHosts

#
Service
ec2

Description

Allocates a Dedicated host to your account.

Example CloudTrail Event #

{
  "awsRegion": "eu-central-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "0f1a55f6-8037-47c9-a18e-acbe82d028ec",
  "eventName": "AllocateHosts",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2019-11-29T15:27:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "be142301d-3728-4735-b9d7-41e8b8622c8d",
  "requestParameters": {
    "AllocateHostsRequest": {
      "AvailabilityZone": "us-west-2",
      "InstanceType": "ec2-bucket",
      "Quantity": 5
    }
  },
  "responseElements": null,
  "sourceIPAddress": "7.253.56.8",
  "userAgent": "aws-cli/1.16.283 Python/3.8.0 Linux/5.3.13-arch1-1 botocore/1.13.19",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

AllocateIpamPoolCidr

#
Service
ec2

Description

Allocate a CIDR from an IPAM pool.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "be4066de-94e9-4b39-bc18-43f93feaa6b8",
  "eventName": "AllocateIpamPoolCidr",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:48:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "180726fb-9a1f-4ea0-bf7d-6eeed0a63e84",
  "requestParameters": {
    "AllocateIpamPoolCidrRequest": {
      "ClientToken": "01735761-51a6-4431-8f95-b22a07933940",
      "IpamPoolId": "ipam-pool-0b5795c40ef5b6d99",
      "NetmaskLength": 24
    }
  },
  "responseElements": {
    "AllocateIpamPoolCidrResponse": {
      "ipamPoolAllocation": {
        "cidr": "10.99.0.0/24",
        "ipamPoolAllocationId": "ipam-pool-alloc-08d34d8a8aa0b4bfbaabdfc4faf06af7d",
        "resourceOwner": 123456789012,
        "resourceType": "custom"
      },
      "requestId": "180726fb-9a1f-4ea0-bf7d-6eeed0a63e84",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ApplySecurityGroupsToClientVpnTargetNetwork

#
Service
ec2

Description

Applies a security group to the association between the target network and the Client VPN endpoint.

AssignIpv6Addresses

#
Service
ec2

Description

Assigns the specified IPv6 addresses to the specified network interface.

AssignPrivateIpAddresses

#
Service
ec2

Description

Assigns one or more secondary private IP addresses to the specified network interface.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "ad0c4a96-134c-491d-944b-a69b82e5e7ba",
  "eventName": "AssignPrivateIpAddresses",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:45:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "155fa9a2-f153-46ef-a2d5-a2f85534a71e",
  "requestParameters": {
    "ipv4Prefixes": {},
    "networkInterfaceId": "eni-025f9aaa17cd9ff32",
    "privateIpAddressesSet": {},
    "secondaryPrivateIpAddressCount": 1
  },
  "responseElements": {
    "_return": true,
    "assignedIpv4PrefixSet": {},
    "assignedPrivateIpAddressesSet": {
      "assignedPrivateIpAddressSetType": [
        {
          "privateIpAddress": "10.0.1.174"
        }
      ]
    },
    "networkInterfaceId": "eni-025f9aaa17cd9ff32",
    "requestId": "155fa9a2-f153-46ef-a2d5-a2f85534a71e"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

AssignPrivateNatGatewayAddress

#
Service
ec2

Description

Assigns private IPv4 addresses to a private NAT gateway.

AssociateAddress

#
Service
ec2

Description

Associates an Elastic IP address with an instance or a network interface.

Example CloudTrail Event #

{
  "awsRegion": "eu-central-1",
  "eventCategory": "Management",
  "eventID": "efada543-5dac-4f94-b096-88220d344e2f",
  "eventName": "AssociateAddress",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-01-12T08:37:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "111111111111",
  "requestID": "605dde78-b714-4c16-b2e2-61b76cfe2375",
  "requestParameters": {
    "allocationId": "eipalloc-e0d96cc5",
    "instanceId": "i-0d0e3add0666f1aba"
  },
  "responseElements": {
    "_return": true,
    "associationId": "eipassoc-01cb5aa4d99f385a5",
    "requestId": "605dde78-b714-4c16-b2e2-61b76cfe2375"
  },
  "sourceIPAddress": "95.90.199.65",
  "userAgent": "aws-sdk-go/1.36.7 (go1.15.5; darwin; amd64) APN/1.0 HashiCorp/1.0 Terraform/0.14.4 (+https://www.terraform.io)",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E",
    "accountId": "111111111111",
    "arn": "arn:aws:iam::111111111111:user/patrick_cli",
    "principalId": "AIDAYTOGP2RLNALZHZ6KX",
    "type": "IAMUser",
    "userName": "patrick_cli"
  }
}

References #

AssociateCapacityReservationBillingOwner

#
Service
ec2

Description

Initiates a request to assign billing of the unused capacity of a shared Capacity Reservation to a consumer account that is consolidated under the same Amazon Web Services organizations payer account.

AssociateClientVpnTargetNetwork

#
Service
ec2

Description

Associates a target network with a Client VPN endpoint.

AssociateDhcpOptions

#
Service
ec2

Description

Associates a set of DHCP options (that you've previously created) with the specified VPC, or associates no DHCP options with the VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "8f88b9d0-c8df-4a8b-a157-9dc5f8995e10",
  "eventName": "AssociateDhcpOptions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:40:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d16a5bce-ebe5-420f-be5d-e3aef4d5a4bd",
  "requestParameters": {
    "dhcpOptionsId": "dopt-04bc4cfc118aff25e",
    "vpcId": "vpc-00c0dad452596a616"
  },
  "responseElements": {
    "_return": true,
    "requestId": "d16a5bce-ebe5-420f-be5d-e3aef4d5a4bd"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

AssociateEnclaveCertificateIamRole

#
Service
ec2

Description

Associates an Identity and Access Management (IAM) role with an Certificate Manager (ACM) certificate.

AssociateInstanceEventWindow

#
Service
ec2

Description

Associates one or more targets with an event window.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "0d2060bc-f98d-4d90-ac0f-511320613b5d",
  "eventName": "AssociateInstanceEventWindow",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:40:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e8ba6499-10e0-46cd-8eda-5741c5a11986",
  "requestParameters": {
    "AssociateInstanceEventWindowRequest": {
      "AssociationTarget": {
        "InstanceId": {
          "content": "i-0a4c8f9124bcc1a50",
          "tag": 1
        }
      },
      "InstanceEventWindowId": "iew-0812df4e4314df613"
    }
  },
  "responseElements": {
    "AssociateInstanceEventWindowResponse": {
      "instanceEventWindow": {
        "associationTarget": {
          "dedicatedHostIdSet": "",
          "instanceIdSet": {
            "item": "i-0a4c8f9124bcc1a50"
          },
          "tagSet": ""
        },
        "instanceEventWindowId": "iew-0812df4e4314df613",
        "name": "dwfix-ec2-d393e412-iew",
        "state": "associating",
        "timeRangeSet": {
          "item": {
            "endHour": 7,
            "endWeekDay": "monday",
            "startHour": 3,
            "startWeekDay": "monday"
          }
        }
      },
      "requestId": "e8ba6499-10e0-46cd-8eda-5741c5a11986",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
readOnly (panther rule field)is_null1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

AssociateIpamByoasn

#
Service
ec2

Description

Associates your Autonomous System Number (ASN) with a BYOIP CIDR that you own in the same Amazon Web Services Region.

AssociateIpamResourceDiscovery

#
Service
ec2

Description

Associates an IPAM resource discovery with an Amazon VPC IPAM.

AssociateNatGatewayAddress

#
Service
ec2

Description

Associates Elastic IP addresses (EIPs) and private IPv4 addresses with a public NAT gateway.

AssociateRouteServer

#
Service
ec2

Description

Associates a route server with a VPC to enable dynamic route updates.

AssociateRouteTable

#
Service
ec2

Description

Associates a subnet with a route table.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "a8126719-8ca9-43a1-9c1c-4fddd2bef9a8",
  "eventName": "AssociateRouteTable",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "baeec94d-10e0-455c-8a97-c17cec60fd66",
  "requestParameters": {
    "routeTableId": "rtb-0c7c2f4aff3677054",
    "subnetId": "subnet-01ed430875cff578d"
  },
  "responseElements": {
    "associationId": "rtbassoc-0b911e98f29251a51",
    "associationState": {
      "state": "associated"
    },
    "requestId": "baeec94d-10e0-455c-8a97-c17cec60fd66"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

AssociateSecurityGroupVpc

#
Service
ec2

Description

Associates a security group with another VPC in the same Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "841bcc2b-a9d2-49cd-bf3d-5ec0183d84af",
  "eventName": "AssociateSecurityGroupVpc",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:39:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "37f0c994-2a00-4feb-a44b-bba672a6ca67",
  "requestParameters": {
    "AssociateSecurityGroupVpcRequest": {
      "GroupId": "sg-0cfd1af7bf967b6fc",
      "VpcId": "vpc-0fd8eff23767cf1e5"
    }
  },
  "responseElements": {
    "AssociateSecurityGroupVpcResponse": {
      "requestId": "37f0c994-2a00-4feb-a44b-bba672a6ca67",
      "state": "associating",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

AssociateSubnetCidrBlock

#
Service
ec2

Description

Associates a CIDR block with your subnet.

AssociateTransitGatewayMulticastDomain

#
Service
ec2

Description

Associates the specified subnets and transit gateway attachments with the specified transit gateway multicast domain.

AssociateTransitGatewayPolicyTable

#
Service
ec2

Description

Associates the specified transit gateway attachment with a transit gateway policy table.

AssociateTransitGatewayRouteTable

#
Service
ec2

Description

Associates the specified attachment with the specified transit gateway route table.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "d8a1daf0-c8f3-491e-aefb-fcdbd13080f6",
  "eventName": "AssociateTransitGatewayRouteTable",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:47:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c7aceb67-cf03-4ae5-8fe6-1459114c817a",
  "requestParameters": {
    "AssociateTransitGatewayRouteTableRequest": {
      "TransitGatewayAttachmentId": "tgw-attach-08d8a09ccdcb3d355",
      "TransitGatewayRouteTableId": "tgw-rtb-0f5c12c8b5c90a1a1"
    }
  },
  "responseElements": {
    "AssociateTransitGatewayRouteTableResponse": {
      "association": {
        "resourceId": "vpc-00c0dad452596a616",
        "resourceType": "vpc",
        "state": "associating",
        "transitGatewayAttachmentId": "tgw-attach-08d8a09ccdcb3d355",
        "transitGatewayRouteTableId": "tgw-rtb-0f5c12c8b5c90a1a1"
      },
      "requestId": "c7aceb67-cf03-4ae5-8fe6-1459114c817a",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

AssociateTrunkInterface

#
Service
ec2

Description

Associates a branch network interface with a trunk network interface.

AssociateVpcCidrBlock

#
Service
ec2

Description

Associates a CIDR block with your VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "dce0ccb0-e48b-4db4-b187-f78fa95dd22e",
  "eventName": "AssociateVpcCidrBlock",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:39:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cef3a6c9-8d5a-4cbe-8bac-d290334631b8",
  "requestParameters": {
    "AssociateVpcCidrBlockRequest": {
      "CidrBlock": "10.1.0.0/16",
      "VpcId": "vpc-00c0dad452596a616"
    }
  },
  "responseElements": {
    "AssociateVpcCidrBlockResponse": {
      "cidrBlockAssociation": {
        "associationId": "vpc-cidr-assoc-05797b2675bca50e1",
        "cidrBlock": "10.1.0.0/16",
        "cidrBlockState": {
          "state": "associating"
        }
      },
      "requestId": "cef3a6c9-8d5a-4cbe-8bac-d290334631b8",
      "vpcId": "vpc-00c0dad452596a616",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

AttachClassicLinkVpc

#
Service
ec2

Description

Links an EC2-Classic instance to a ClassicLink-enabled VPC through one or more of the VPC's security groups.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

AttachImageWatermark

#
Service
ec2

Description

Attaches a watermark to a non-public AMI.

AttachInternetGateway

#
Service
ec2

Description

Attaches an Internet gateway to a VPC, enabling connectivity between the Internet and the VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "2b4e0526-7813-410b-b6a5-366704c3b0d3",
  "eventName": "AttachInternetGateway",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "b095e717-86e3-4b4b-9f2b-42d319ba95c9",
  "requestParameters": {
    "internetGatewayId": "igw-02a84e4222d62e16b",
    "vpcId": "vpc-06fe1a64761a0f720"
  },
  "responseElements": {
    "_return": true,
    "requestId": "b095e717-86e3-4b4b-9f2b-42d319ba95c9"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

AttachNetworkInterface

#
Service
ec2

Description

Attaches a network interface to an instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.AttachmentLimitExceeded",
  "errorMessage": "Device index 2 exceeds the limit for t3.micro",
  "eventCategory": "Management",
  "eventID": "547b135a-b17e-4651-a15b-ae52196862a5",
  "eventName": "AttachNetworkInterface",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:45:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f089ddb8-5583-4dcd-87ef-e87a5c7e8633",
  "requestParameters": {
    "deviceIndex": 2,
    "instanceId": "i-0a4c8f9124bcc1a50",
    "networkInterfaceId": "eni-025f9aaa17cd9ff32"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

AttachVerifiedAccessTrustProvider

#
Service
ec2

Description

Attaches the specified Amazon Web Services Verified Access trust provider to the specified Amazon Web Services Verified Access instance.

AttachVolume

#
Service
ec2

Description

Attaches an Amazon EBS volume to a running or stopped instance and exposes it to the instance with the specified device name.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "eacfe628-253d-425e-ba32-17d1d36c2ffc",
  "eventName": "AttachVolume",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-07-07T17:31:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "797507667711",
  "requestID": "16f946c8-83ce-49b3-86c4-3b57f23eea38",
  "requestParameters": {
    "deleteOnTermination": false,
    "device": "/dev/sdf",
    "instanceId": "i-0c13b9b6d209978fc",
    "volumeId": "vol-0f760d9398c64e477"
  },
  "responseElements": {
    "attachTime": 1625679062578,
    "deleteOnTermination": false,
    "device": "/dev/sdf",
    "instanceId": "i-0c13b9b6d209978fc",
    "requestId": "16f946c8-83ce-49b3-86c4-3b57f23eea38",
    "status": "attaching",
    "volumeId": "vol-0f760d9398c64e477"
  },
  "sourceIPAddress": "3.142.206.200",
  "userAgent": "Boto3/1.17.24 Python/3.6.13 Linux/4.19.0-17-cloud-amd64 Botocore/1.20.98",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI37S4KUWNVD",
    "accountId": "797507667711",
    "arn": "arn:aws:sts::797507667711:assumed-role/Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG/1625678983.751919",
    "principalId": "AROA3TLZJI37S6HPJWVJ2:1625678983.751919",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T17:29:43Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "797507667711",
        "arn": "arn:aws:iam::797507667711:role/Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG",
        "principalId": "AROA3TLZJI37S6HPJWVJ2",
        "type": "Role",
        "userName": "Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

References #

AttachVpnGateway

#
Service
ec2

Description

Attaches a virtual private gateway to a VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "87701e6c-d68d-498d-bec4-17930ecb1492",
  "eventName": "AttachVpnGateway",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:46:04Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "fca35204-3649-4883-9c6e-c3083fa14707",
  "requestParameters": {
    "vpcId": "vpc-00c0dad452596a616",
    "vpnGatewayId": "vgw-03b7415aef1ba49a5"
  },
  "responseElements": {
    "attachment": {
      "state": "attaching",
      "vpcId": "vpc-00c0dad452596a616"
    },
    "requestId": "fca35204-3649-4883-9c6e-c3083fa14707"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

AuthorizeClientVpnIngress

#
Service
ec2

Description

Adds an ingress authorization rule to a Client VPN endpoint.

BundleInstance

#
Service
ec2

Description

Bundles an Amazon instance store-backed Windows instance.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
readOnly (panther rule field)is_null1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

CancelBundleTask

#
Service
ec2

Description

Cancels a bundling operation for an instance store-backed Windows instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidInstanceID.Malformed",
  "errorMessage": "Invalid id: \"dw-probe\"",
  "eventCategory": "Management",
  "eventID": "7a886e2b-6fb7-46a9-b37b-cc6cafa46bfe",
  "eventName": "CancelBundleTask",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cf00540e-439b-4b99-aa76-0dfe1cd6bb95",
  "requestParameters": {
    "bundleId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CancelCapacityReservation

#
Service
ec2

Description

Cancels the specified Capacity Reservation, releases the reserved capacity, and changes the Capacity Reservation's state to cancelled.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidCapacityReservationId.Malformed",
  "errorMessage": "The capacity-reservation ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "37993a1c-14d7-4919-952c-82968d85a7eb",
  "eventName": "CancelCapacityReservation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "bdfdfc32-df6a-4d66-8cc9-b2ea1ce66627",
  "requestParameters": {
    "CancelCapacityReservationRequest": {
      "CapacityReservationId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CancelCapacityReservationFleets

#
Service
ec2

Description

Cancels one or more Capacity Reservation Fleets.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidCapacityReservationFleetId.Malformed",
  "errorMessage": "The capacity-reservation-fleet ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "00390e66-11ca-4bb9-ba82-2d3a09025fbf",
  "eventName": "CancelCapacityReservationFleets",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "67b124e8-8596-40ba-aed7-9013766103f7",
  "requestParameters": {
    "CancelCapacityReservationFleetsRequest": {
      "CapacityReservationFleetId": {
        "content": "dw-probe",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CancelConversionTask

#
Service
ec2

Description

Cancels an active conversion task.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidConversionTaskId",
  "errorMessage": "Parameter conversion-task-id (dw-probe) has an invalid format.",
  "eventCategory": "Management",
  "eventID": "1da55b23-18e4-4620-97d3-9d8fe2537c90",
  "eventName": "CancelConversionTask",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9ad4be26-60cc-4582-92d8-5db21639fa27",
  "requestParameters": {
    "conversionTaskId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CancelDeclarativePoliciesReport

#
Service
ec2

Description

Cancels the generation of an account status report.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidDeclarativePoliciesReportId.Malformed",
  "errorMessage": "The declarative-policies-report ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "0585f329-2e92-4250-af93-bea1c280456e",
  "eventName": "CancelDeclarativePoliciesReport",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d43064f8-8dd1-4322-ac80-10bea32656ab",
  "requestParameters": {
    "CancelDeclarativePoliciesReportRequest": {
      "ReportId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CancelExportTask

#
Service
ec2

Description

Cancels an active export task.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidID",
  "errorMessage": "The ID 'dw-probe' is not valid",
  "eventCategory": "Management",
  "eventID": "95d2ae81-478b-4d12-ac18-4640e87d7d8c",
  "eventName": "CancelExportTask",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4f70769a-bae6-4c54-9518-d111821da65c",
  "requestParameters": {
    "exportTaskId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CancelImageLaunchPermission

#
Service
ec2

Description

Removes your Amazon Web Services account from the launch permissions for the specified AMI.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidAMIID.Malformed",
  "errorMessage": "The image ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "58a062f1-0b6c-4c68-b74a-17583e2629a3",
  "eventName": "CancelImageLaunchPermission",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2c1f0275-a5e9-4d0c-b73b-143c29416d7d",
  "requestParameters": {
    "CancelImageLaunchPermissionRequest": {
      "ImageId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CancelImportTask

#
Service
ec2

Description

Cancels an in-process import virtual machine or import snapshot task.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidConversionTaskId.Malformed",
  "errorMessage": "Missing the task ID.",
  "eventCategory": "Management",
  "eventID": "23184087-6e32-43fd-b7d9-405db9bf0d7b",
  "eventName": "CancelImportTask",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:45:16Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d39a3c74-cfea-4258-b5aa-4ddf42d0a8af",
  "requestParameters": {
    "CancelImportTaskRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CancelReservedInstancesListing

#
Service
ec2

Description

Cancels the specified Reserved Instance listing in the Reserved Instance Marketplace.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidInput",
  "errorMessage": "1 validation error detected: Value 'dw-probe' at 'reservedInstanceListingId' failed to satisfy constraint: Member must satisfy regular expression pattern: \\w{8}(-\\w{4}){3}-\\w{12}",
  "eventCategory": "Management",
  "eventID": "8868a6f9-17af-4264-a48f-33e20ecbdf4b",
  "eventName": "CancelReservedInstancesListing",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "47d9cb61-63f5-4fdf-8623-5ef51baa02e6",
  "requestParameters": {
    "reservedInstancesListingId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CancelSpotFleetRequests

#
Service
ec2

Description

Cancels the specified Spot fleet requests.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "1 validation error detected: Value '[dw-probe]' at 'spotFleetRequestId' failed to satisfy constraint: Member must satisfy constraint: [Member must satisfy regular expression pattern: ^(sfr|fleet)-[a-z0-9-]{36}\\b]",
  "eventCategory": "Management",
  "eventID": "e60c8329-8f60-4141-ae81-607b5758d62a",
  "eventName": "CancelSpotFleetRequests",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "66d22131-b273-4d78-a668-7817ce668a55",
  "requestParameters": {
    "CancelSpotFleetRequestsRequest": {
      "SpotFleetRequestId": {
        "content": "dw-probe",
        "tag": 1
      },
      "TerminateInstances": false
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CancelSpotInstanceRequests

#
Service
ec2

Description

Cancels one or more Spot Instance requests.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidSpotInstanceRequestID.Malformed",
  "errorMessage": "Invalid id :\"dw-probe\" (expecting \"sir-...\")",
  "eventCategory": "Management",
  "eventID": "f1fac11c-6a48-44ee-beae-6c222f18f168",
  "eventName": "CancelSpotInstanceRequests",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5e6dc90b-8193-40db-9397-4880962b9cd6",
  "requestParameters": {
    "spotInstanceRequestIdSet": {
      "items": [
        {
          "spotInstanceRequestId": "dw-probe"
        }
      ]
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
readOnly (panther rule field)is_null1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ConfirmProductInstance

#
Service
ec2

Description

Determines whether a product code is associated with an instance.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

CopyFpgaImage

#
Service
ec2

Description

Copies the specified Amazon FPGA Image (AFI) to the current Region.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::errorCode (panther rule field)neClient.DryRunOperation1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

CopyImage

#
Service
ec2

Description

Initiates the copy of an AMI from the specified source region to the region in which the request was made.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "d71c9a70-e919-4641-86b2-874c5cb234af",
  "eventName": "CopyImage",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-01-26T19:22:43Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "068366-1818-4dc9-a12a-c474b5df3937",
  "requestParameters": {
    "name": "flaws",
    "sourceImageId": "snap-83d15d668fb2941db",
    "sourceRegion": "us-west-2"
  },
  "responseElements": null,
  "sourceIPAddress": "34.254.7.53",
  "userAgent": "aws-cli/1.14.20 Python/3.6.4 Darwin/17.3.0 botocore/1.8.24",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::errorCode (panther rule field)neClient.DryRunOperation1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

CopySnapshot

#
Service
ec2

Description

Copies a point-in-time snapshot of an Amazon EBS volume and stores it in Amazon S3.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "b6b212431-df2c-47ed-b77d-3dda61348d9d",
  "eventName": "CopySnapshot",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-02-27T23:23:36Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "355e3f18-d1dd-4c1e-9f68-74df84d49b59",
  "requestParameters": {
    "description": "copying",
    "destinationRegion": "us-west-2",
    "presignedUrl": "https://ec2.us-west-2.amazonaws.com/?SourceRegion=us-west-2&SourceSnapshotId=snap-4fd281251b99202a3&Version=2015-04-15&Description=copying&Action=CopySnapshot&DestinationRegion=us-west-2&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Expires=3600&X-Amz-Credential=AKIA1ZBTOEKWKVHP6GHZ%2F172111%2Fus-west-2%2Fec2%2Faws4_request&X-Amz-SignedHeaders=host&X-Amz-Date=172111T50193Z&X-Amz-Signature=0f1eceb8733c78738443f70c6554022809f27d81ccce39ece8a5d6e0ae59bdd9",
    "sourceRegion": "us-west-2",
    "sourceSnapshotId": "snap-4fd281251b99202a3"
  },
  "responseElements": null,
  "sourceIPAddress": "3.239.132.95",
  "userAgent": "aws-cli/1.7.36 Python/2.7.11 Linux/4.4.0-34-generic",
  "userIdentity": {
    "accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

CopyVolumes

#
Service
ec2

Description

Creates a crash-consistent, point-in-time copy of an existing Amazon EBS volume within the same Availability Zone.

CreateCapacityManagerDataExport

#
Service
ec2

Description

Creates a new data export configuration for EC2 Capacity Manager.

CreateCapacityReservation

#
Service
ec2

Description

Creates a new Capacity Reservation with the specified attributes.

CreateCapacityReservationBySplitting

#
Service
ec2

Description

Create a new Capacity Reservation by splitting the capacity of the source Capacity Reservation.

CreateCapacityReservationCancellationQuote

#
Service
ec2

Description

Generates a cancellation quote for a future-dated Capacity Reservation that is within its commitment duration.

CreateCapacityReservationFleet

#
Service
ec2

Description

Creates a Capacity Reservation Fleet.

CreateCarrierGateway

#
Service
ec2

Description

Creates a carrier gateway.

CreateClientVpnEndpoint

#
Service
ec2

Description

Creates a Client VPN endpoint.

CreateClientVpnRoute

#
Service
ec2

Description

Adds a route to a network to a Client VPN endpoint.

CreateCoipCidr

#
Service
ec2

Description

Creates a range of customer-owned IP addresses.

CreateCoipPool

#
Service
ec2

Description

Creates a pool of customer-owned IP (CoIP) addresses.

CreateCustomerGateway

#
Service
ec2

Description

Provides information to AWS about your VPN customer gateway device.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "0cabba5e-aabf-47bc-b521-8b0011f722da",
  "eventName": "CreateCustomerGateway",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:46:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "64cec76d-0b1f-490b-9372-97cfd2adf293",
  "requestParameters": {
    "bgpAsn": 65000,
    "ipAddress": "1.2.3.4",
    "tagSpecificationSet": {
      "items": [
        {
          "resourceType": "customer-gateway",
          "tags": [
            {
              "key": "Name",
              "value": "dwfix-ec2-d393e412"
            },
            {
              "key": "dwfix",
              "value": "1"
            }
          ]
        }
      ]
    },
    "type": "ipsec.1"
  },
  "responseElements": {
    "customerGateway": {
      "bgpAsn": 65000,
      "customerGatewayId": "cgw-04a9f55555b346fed",
      "ipAddress": "1.2.3.4",
      "state": "available",
      "tagSet": {
        "items": [
          {
            "key": "Name",
            "value": "dwfix-ec2-d393e412"
          },
          {
            "key": "dwfix",
            "value": "1"
          }
        ]
      },
      "type": "ipsec.1"
    },
    "requestId": "64cec76d-0b1f-490b-9372-97cfd2adf293"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

CreateDefaultSubnet

#
Service
ec2

Description

Creates a default subnet with a size /20 IPv4 CIDR block in the specified Availability Zone in your default VPC.

CreateDefaultVpc

#
Service
ec2

Description

Creates a default VPC with a size /16 IPv4 CIDR block and a default subnet in each Availability Zone.

Example CloudTrail Event #

{
  "awsRegion": "ap-northeast-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "645598b92-f4ed-486a-9f23-995199a8c64",
  "eventName": "CreateDefaultVpc",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-04-16T06:59:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "c4e40e01-0455-42b3-a35b-8c47f9fd7151",
  "requestParameters": {
    "CreateDefaultVpcRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "155.63.17.217",
  "userAgent": "Boto3/1.7.4 Python/2.7.12 Linux/4.4.0-119-generic Botocore/1.10.4",
  "userIdentity": {
    "accessKeyId": "ASIAGD2JRX0V6RJGWR59",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "sessionContext": {
      "attributes": {
        "creationDate": "2018-04-16T06:59:20Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

CreateDelegateMacVolumeOwnershipTask

#
Service
ec2

Description

Delegates ownership of the Amazon EBS root volume for an Apple silicon Mac instance to an administrative user.

CreateDhcpOptions

#
Service
ec2

Description

Creates a set of DHCP options for your VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "d4bb67e1-9a7e-4faa-b719-d00c14c0bd26",
  "eventName": "CreateDhcpOptions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:59:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a7e080d1-deb6-4e10-b48e-c1aa83e6882c",
  "requestParameters": {
    "dhcpConfigurationSet": {
      "items": [
        {
          "key": "domain-name-servers",
          "valueSet": {
            "items": [
              {
                "value": "AmazonProvidedDNS"
              }
            ]
          }
        }
      ]
    }
  },
  "responseElements": {
    "dhcpOptions": {
      "dhcpConfigurationSet": {
        "items": [
          {
            "key": "domain-name-servers",
            "valueSet": {
              "items": [
                {
                  "value": "AmazonProvidedDNS"
                }
              ]
            }
          }
        ]
      },
      "dhcpOptionsId": "dopt-0ea629e1ced764e60",
      "ownerId": "123456789012",
      "tagSet": {}
    },
    "requestId": "a7e080d1-deb6-4e10-b48e-c1aa83e6882c"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateEgressOnlyInternetGateway

#
Service
ec2

Description

[IPv6 only] Creates an egress-only internet gateway for your VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "c189c6ef-c216-4ade-b131-c87a115e0117",
  "eventName": "CreateEgressOnlyInternetGateway",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:39:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9a93e065-12ea-48cf-b7e1-a68143758ddd",
  "requestParameters": {
    "CreateEgressOnlyInternetGatewayRequest": {
      "TagSpecification": {
        "ResourceType": "egress-only-internet-gateway",
        "Tag": [
          {
            "Key": "Name",
            "Value": "dwfix-ec2-d393e412",
            "tag": 1
          },
          {
            "Key": "dwfix",
            "Value": "1",
            "tag": 2
          }
        ],
        "tag": 1
      },
      "VpcId": "vpc-00c0dad452596a616"
    }
  },
  "responseElements": {
    "CreateEgressOnlyInternetGatewayResponse": {
      "egressOnlyInternetGateway": {
        "attachmentSet": {
          "item": {
            "state": "attached",
            "vpcId": "vpc-00c0dad452596a616"
          }
        },
        "egressOnlyInternetGatewayId": "eigw-03694f0561cfaf667",
        "tagSet": {
          "item": [
            {
              "key": "dwfix",
              "value": "1"
            },
            {
              "key": "Name",
              "value": "dwfix-ec2-d393e412"
            }
          ]
        }
      },
      "requestId": "9a93e065-12ea-48cf-b7e1-a68143758ddd",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateFleet

#
Service
ec2

Description

Creates an EC2 Fleet that contains the configuration information for On-Demand Instances and Spot Instances.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "341440fc-40b5-3df9-a2a1-14a67f96b841",
  "eventSource": "ec2.amazonaws.com",
  "eventName": "CreateFleet",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "93e1ef8b-5291-4004-8bad-426436c135c6",
  "userAgent": "aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 exec-env/AWS_ECS_FARGATE api/ec2#1.307.0 app/APN_1.1-pc_2b9joblhmcbhnqakspwshptlz$ m/z",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com"
  }
}

CreateFlowLogs

#
Service
ec2

Description

Creates one or more flow logs to capture IP traffic for a specific network interface, subnet, or VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "a3fbe842-f8df-4bb3-accf-1407cc925cbd",
  "eventName": "CreateFlowLogs",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:02:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "353ea5d4-f889-46d4-a632-ed784656dda4",
  "requestParameters": {
    "CreateFlowLogsRequest": {
      "DeliverLogsPermissionArn": "arn:aws:iam::123837392027:role/stratus-red-team-remove-flow-logs-role",
      "LogDestination": "arn:aws:logs:us-east-1:123837392027:log-group:/stratus-red-team/vpc-flow-logs",
      "LogDestinationType": "cloud-watch-logs",
      "MaxAggregationInterval": 600,
      "ResourceId": {
        "content": "vpc-0255d384b4b458b46",
        "tag": 1
      },
      "ResourceType": "VPC",
      "TagSpecification": {
        "ResourceType": "vpc-flow-log",
        "Tag": {
          "Key": "StratusRedTeam",
          "Value": true,
          "tag": 1
        },
        "tag": 1
      },
      "TrafficType": "REJECT"
    }
  },
  "responseElements": {
    "CreateFlowLogsResponse": {
      "clientToken": "oueUIFMk93wJinrrwc0QUGz+O0GaqjxHhhquvXQ1UQc=",
      "flowLogIdSet": {
        "item": "fl-064ed3a785e4a37ef"
      },
      "requestId": "353ea5d4-f889-46d4-a632-ed784656dda4",
      "unsuccessful": "",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_20f9795b-aa02-4c8e-bad6-bd338ec09f59 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

CreateFpgaImage

#
Service
ec2

Description

Creates an Amazon FPGA Image (AFI) from the specified design checkpoint (DCP).

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::errorCode (panther rule field)neClient.DryRunOperation1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

CreateImage

#
Service
ec2

Description

Creates an Amazon EBS-backed AMI from an Amazon EBS-backed instance that is either running or stopped.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "9c3f2709-3739-4fae-b9a0-eba022562f93",
  "eventName": "CreateImage",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-01-23T10:33:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "c6a8e00d-575a-46d0-b251-32883f483a4",
  "requestParameters": {
    "blockDeviceMapping": {
      "items": [
        {
          "deviceName": "/dev/sda1",
          "ebs": {
            "deleteOnTermination": true
          }
        }
      ]
    },
    "description": "framecon stuff",
    "instanceId": "i-546b27df737a621a2",
    "name": "framecon AMI",
    "noReboot": true
  },
  "responseElements": null,
  "sourceIPAddress": "166.140.209.2",
  "userAgent": "Boto3/1.4.4 Python/2.7.12 Linux/4.13.0-31-generic Botocore/1.7.12",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::errorCode (panther rule field)neClient.DryRunOperation1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

CreateImageUsageReport

#
Service
ec2

Description

Creates a report that shows how your image is used across other Amazon Web Services accounts.

CreateInstanceConnectEndpoint

#
Service
ec2

Description

Creates an EC2 Instance Connect Endpoint.

CreateInstanceEventWindow

#
Service
ec2

Description

Creates an event window in which scheduled events for the associated Amazon EC2 instances can run.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f0063dcb-17f2-4e3c-9fdc-7c55e71944a9",
  "eventName": "CreateInstanceEventWindow",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:40:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "356cc375-5198-4c0d-80ca-8bc0d9bda072",
  "requestParameters": {
    "CreateInstanceEventWindowRequest": {
      "Name": "dwfix-ec2-d393e412-iew",
      "TagSpecification": {
        "ResourceType": "instance-event-window",
        "Tag": [
          {
            "Key": "Name",
            "Value": "dwfix-ec2-d393e412",
            "tag": 1
          },
          {
            "Key": "dwfix",
            "Value": "1",
            "tag": 2
          }
        ],
        "tag": 1
      },
      "TimeRange": {
        "EndHour": 6,
        "EndWeekDay": "sunday",
        "StartHour": 2,
        "StartWeekDay": "sunday",
        "tag": 1
      }
    }
  },
  "responseElements": {
    "CreateInstanceEventWindowResponse": {
      "instanceEventWindow": {
        "instanceEventWindowId": "iew-0812df4e4314df613",
        "name": "dwfix-ec2-d393e412-iew",
        "state": "creating",
        "tagSet": {
          "item": [
            {
              "key": "Name",
              "value": "dwfix-ec2-d393e412"
            },
            {
              "key": "dwfix",
              "value": "1"
            }
          ]
        },
        "timeRangeSet": {
          "item": {
            "endHour": 6,
            "endWeekDay": "sunday",
            "startHour": 2,
            "startWeekDay": "sunday"
          }
        }
      },
      "requestId": "356cc375-5198-4c0d-80ca-8bc0d9bda072",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

CreateInternetGateway

#
Service
ec2

Description

Creates an Internet gateway for use with a VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "e40431f7-07bc-4d9a-a5cb-07e28107babb",
  "eventName": "CreateInternetGateway",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "b23138bd-d869-4268-8c79-df643cafc60e",
  "requestParameters": {
    "tagSpecificationSet": {
      "items": [
        {
          "resourceType": "internet-gateway",
          "tags": [
            {
              "key": "StratusRedTeam",
              "value": "true"
            },
            {
              "key": "Name",
              "value": "stratus-red-team-ec2-steal-credentials-vpc"
            }
          ]
        }
      ]
    }
  },
  "responseElements": {
    "internetGateway": {
      "association": {},
      "attachmentSet": {},
      "internetGatewayId": "igw-02a84e4222d62e16b",
      "ownerId": "123837392027",
      "tagSet": {
        "items": [
          {
            "key": "StratusRedTeam",
            "value": "true"
          },
          {
            "key": "Name",
            "value": "stratus-red-team-ec2-steal-credentials-vpc"
          }
        ]
      }
    },
    "requestId": "b23138bd-d869-4268-8c79-df643cafc60e"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

Panther #

References #

CreateInterruptibleCapacityReservationAllocation

#
Service
ec2

Description

Creates an interruptible Capacity Reservation by specifying the number of unused instances you want to allocate from your source reservation.

CreateIpam

#
Service
ec2

Description

Create an IPAM.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "5bf80a39-8c10-402c-9b59-2aabbb1944b8",
  "eventName": "CreateIpam",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:40:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1ffa677c-4ffa-4db4-aa2b-2c85d472089d",
  "requestParameters": {
    "CreateIpamRequest": {
      "ClientToken": "a24c7535-db37-4724-8eb3-36a19933a582",
      "Description": "dwfix-ec2-d393e412 ipam",
      "OperatingRegion": {
        "RegionName": "us-west-1",
        "tag": 1
      },
      "TagSpecification": {
        "ResourceType": "ipam",
        "Tag": [
          {
            "Key": "Name",
            "Value": "dwfix-ec2-d393e412",
            "tag": 1
          },
          {
            "Key": "dwfix",
            "Value": "1",
            "tag": 2
          }
        ],
        "tag": 1
      }
    }
  },
  "responseElements": {
    "CreateIpamResponse": {
      "ipam": {
        "defaultResourceDiscoveryAssociationId": "ipam-res-disco-assoc-07136081da90123d9",
        "defaultResourceDiscoveryId": "ipam-res-disco-0ee5af4d14e72767e",
        "description": "dwfix-ec2-d393e412 ipam",
        "enablePrivateGua": false,
        "ipamArn": "arn:aws:ec2::123456789012:ipam/ipam-081be5e3bac006e10",
        "ipamId": "ipam-081be5e3bac006e10",
        "ipamRegion": "us-west-1",
        "meteredAccount": "ipam-owner",
        "operatingRegionSet": {
          "item": {
            "regionName": "us-west-1"
          }
        },
        "ownerId": "123456789012",
        "privateDefaultScopeId": "ipam-scope-08c25ba7a8986b987",
        "publicDefaultScopeId": "ipam-scope-0fecdb0cfd16681d6",
        "resourceDiscoveryAssociationCount": 1,
        "scopeCount": 2,
        "state": "create-in-progress",
        "tagSet": {
          "item": [
            {
              "key": "dwfix",
              "value": "1"
            },
            {
              "key": "Name",
              "value": "dwfix-ec2-d393e412"
            }
          ]
        },
        "tier": "advanced"
      },
      "requestId": "1ffa677c-4ffa-4db4-aa2b-2c85d472089d",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateIpamExternalResourceVerificationToken

#
Service
ec2

Description

Create a verification token.

CreateIpamPolicy

#
Service
ec2

Description

Creates an IPAM policy.

CreateIpamPool

#
Service
ec2

Description

Create an IP address pool for Amazon VPC IP Address Manager (IPAM).

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "9a35e468-25dc-46a5-8533-c8ac93e6cfe2",
  "eventName": "CreateIpamPool",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:47:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "33c10310-d282-4ccf-b7b7-e28ebbe348f6",
  "requestParameters": {
    "CreateIpamPoolRequest": {
      "AddressFamily": "ipv4",
      "ClientToken": "1b57fc37-a8be-404e-81a5-78bdf9617b30",
      "Description": "dwfix-ec2-d393e412 ipam pool",
      "IpamScopeId": "ipam-scope-08c25ba7a8986b987",
      "Locale": "us-west-1",
      "TagSpecification": {
        "ResourceType": "ipam-pool",
        "Tag": [
          {
            "Key": "Name",
            "Value": "dwfix-ec2-d393e412",
            "tag": 1
          },
          {
            "Key": "dwfix",
            "Value": "1",
            "tag": 2
          }
        ],
        "tag": 1
      }
    }
  },
  "responseElements": {
    "CreateIpamPoolResponse": {
      "ipamPool": {
        "addressFamily": "ipv4",
        "autoImport": false,
        "description": "dwfix-ec2-d393e412 ipam pool",
        "ipamArn": "arn:aws:ec2::123456789012:ipam/ipam-081be5e3bac006e10",
        "ipamPoolArn": "arn:aws:ec2::123456789012:ipam-pool/ipam-pool-0b5795c40ef5b6d99",
        "ipamPoolId": "ipam-pool-0b5795c40ef5b6d99",
        "ipamRegion": "us-west-1",
        "ipamScopeArn": "arn:aws:ec2::123456789012:ipam-scope/ipam-scope-08c25ba7a8986b987",
        "ipamScopeType": "private",
        "locale": "us-west-1",
        "ownerId": "123456789012",
        "poolDepth": 1,
        "state": "create-in-progress",
        "tagSet": {
          "item": [
            {
              "key": "dwfix",
              "value": "1"
            },
            {
              "key": "Name",
              "value": "dwfix-ec2-d393e412"
            }
          ]
        }
      },
      "requestId": "33c10310-d282-4ccf-b7b7-e28ebbe348f6",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateIpamPrefixListResolver

#
Service
ec2

Description

Creates an IPAM prefix list resolver.

CreateIpamPrefixListResolverTarget

#
Service
ec2

Description

Creates an IPAM prefix list resolver target.

CreateIpamResourceDiscovery

#
Service
ec2

Description

Creates an IPAM resource discovery.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.ResourceLimitExceeded",
  "errorMessage": "You've reached the limit for resource discoveries. You have created 1 resource discoveries, and you are limited to 1.",
  "eventCategory": "Management",
  "eventID": "00f11cf2-f2af-4294-ac05-bd2098214b8b",
  "eventName": "CreateIpamResourceDiscovery",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:48:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b09571e8-4a2d-480a-9961-9f7c8699265a",
  "requestParameters": {
    "CreateIpamResourceDiscoveryRequest": {
      "ClientToken": "865ec5a5-e33a-4b6d-bbe9-f74dc9b41eca",
      "Description": "dwfix-ec2-d393e412 ipam-rd",
      "OperatingRegion": {
        "RegionName": "us-west-1",
        "tag": 1
      },
      "TagSpecification": {
        "ResourceType": "ipam-resource-discovery",
        "Tag": [
          {
            "Key": "Name",
            "Value": "dwfix-ec2-d393e412",
            "tag": 1
          },
          {
            "Key": "dwfix",
            "Value": "1",
            "tag": 2
          }
        ],
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateIpamScope

#
Service
ec2

Description

Create an IPAM scope.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f7753d35-9267-4860-aa16-e792fd6bc7ca",
  "eventName": "CreateIpamScope",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:47:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5ef1f200-f2fb-4405-a61e-6302e766b484",
  "requestParameters": {
    "CreateIpamScopeRequest": {
      "ClientToken": "0ab45157-3186-46d0-afd2-1e2a754a50fb",
      "Description": "dwfix-ec2-d393e412 ipam scope",
      "IpamId": "ipam-081be5e3bac006e10",
      "TagSpecification": {
        "ResourceType": "ipam-scope",
        "Tag": [
          {
            "Key": "Name",
            "Value": "dwfix-ec2-d393e412",
            "tag": 1
          },
          {
            "Key": "dwfix",
            "Value": "1",
            "tag": 2
          }
        ],
        "tag": 1
      }
    }
  },
  "responseElements": {
    "CreateIpamScopeResponse": {
      "ipamScope": {
        "description": "dwfix-ec2-d393e412 ipam scope",
        "ipamArn": "arn:aws:ec2::123456789012:ipam/ipam-081be5e3bac006e10",
        "ipamRegion": "us-west-1",
        "ipamScopeArn": "arn:aws:ec2::123456789012:ipam-scope/ipam-scope-047dd4ad39a6ae5a6",
        "ipamScopeId": "ipam-scope-047dd4ad39a6ae5a6",
        "ipamScopeType": "private",
        "isDefault": false,
        "ownerId": "123456789012",
        "poolCount": 0,
        "state": "create-in-progress",
        "tagSet": {
          "item": [
            {
              "key": "dwfix",
              "value": "1"
            },
            {
              "key": "Name",
              "value": "dwfix-ec2-d393e412"
            }
          ]
        }
      },
      "requestId": "5ef1f200-f2fb-4405-a61e-6302e766b484",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateLaunchTemplate

#
Service
ec2

Description

Creates a launch template.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f1066d2a-8172-49dd-904a-b4d3050cbc6a",
  "eventName": "CreateLaunchTemplate",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:59:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "863e9eae-8d8d-405f-a6a7-e312043b9d6b",
  "requestParameters": {
    "CreateLaunchTemplateRequest": {
      "ClientToken": "4f9a8b07-d3eb-4d23-a1b9-0786357dc185",
      "LaunchTemplateData": {
        "ImageId": "ami-03993477bf043c1d1",
        "InstanceType": "t3.micro"
      },
      "LaunchTemplateName": "dwfix-lt"
    }
  },
  "responseElements": {
    "CreateLaunchTemplateResponse": {
      "launchTemplate": {
        "createTime": "2026-06-29T19:59:23.000Z",
        "createdBy": "arn:aws:iam::123456789012:user/sample-user",
        "defaultVersionNumber": 1,
        "latestVersionNumber": 1,
        "launchTemplateId": "lt-0e15e74d047fa83a3",
        "launchTemplateName": "dwfix-lt",
        "operator": {
          "managed": false
        }
      },
      "requestId": "863e9eae-8d8d-405f-a6a7-e312043b9d6b",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

CreateLaunchTemplateVersion

#
Service
ec2

Description

Creates a new version of a launch template.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "1004fdd3-503d-4248-bd65-27d346bb776c",
  "eventName": "CreateLaunchTemplateVersion",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:59:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cb1ba550-8485-42a2-ae90-00e114e99a80",
  "requestParameters": {
    "CreateLaunchTemplateVersionRequest": {
      "ClientToken": "a26975ae-f502-480f-8e7d-f22cb2af8df3",
      "LaunchTemplateData": {
        "ImageId": "ami-03993477bf043c1d1",
        "InstanceType": "t3.small"
      },
      "LaunchTemplateId": "lt-0e15e74d047fa83a3"
    }
  },
  "responseElements": {
    "CreateLaunchTemplateVersionResponse": {
      "launchTemplateVersion": {
        "createTime": "2026-06-29T19:59:23.000Z",
        "createdBy": "arn:aws:iam::123456789012:user/sample-user",
        "defaultVersion": false,
        "launchTemplateData": {
          "imageId": "ami-03993477bf043c1d1",
          "instanceType": "t3.small"
        },
        "launchTemplateId": "lt-0e15e74d047fa83a3",
        "launchTemplateName": "dwfix-lt",
        "operator": {
          "managed": false
        },
        "versionNumber": 2
      },
      "requestId": "cb1ba550-8485-42a2-ae90-00e114e99a80",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateLocalGatewayRoute

#
Service
ec2

Description

Creates a static route for the specified local gateway route table.

CreateLocalGatewayRouteTable

#
Service
ec2

Description

Creates a local gateway route table.

CreateLocalGatewayRouteTableVirtualInterfaceGroupAssociation

#
Service
ec2

Description

Creates a local gateway route table virtual interface group association.

CreateLocalGatewayRouteTableVpcAssociation

#
Service
ec2

Description

Associates the specified VPC with the specified local gateway route table.

CreateLocalGatewayVirtualInterface

#
Service
ec2

Description

Create a virtual interface for a local gateway.

CreateLocalGatewayVirtualInterfaceGroup

#
Service
ec2

Description

Create a local gateway virtual interface group.

CreateMacSystemIntegrityProtectionModificationTask

#
Service
ec2

Description

Creates a System Integrity Protection (SIP) modification task to configure the SIP settings for an x86 Mac instance or Apple silicon Mac instance.

CreateManagedPrefixList

#
Service
ec2

Description

Creates a managed prefix list.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f2e15dfc-25dd-46d2-b229-b8da2c2bbd80",
  "eventName": "CreateManagedPrefixList",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:40:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "927fa68a-ad07-4eb0-8bfe-2e78558c1310",
  "requestParameters": {
    "CreateManagedPrefixListRequest": {
      "AddressFamily": "IPv4",
      "ClientToken": "63f50d0c-fb85-4727-8be6-8a142b25aeaa",
      "MaxEntries": 10,
      "PrefixListName": "dwfix-ec2-d393e412-pl",
      "TagSpecification": {
        "ResourceType": "prefix-list",
        "Tag": [
          {
            "Key": "Name",
            "Value": "dwfix-ec2-d393e412",
            "tag": 1
          },
          {
            "Key": "dwfix",
            "Value": "1",
            "tag": 2
          }
        ],
        "tag": 1
      }
    }
  },
  "responseElements": {
    "CreateManagedPrefixListResponse": {
      "prefixList": {
        "addressFamily": "IPv4",
        "maxEntries": 10,
        "ownerId": "123456789012",
        "prefixListArn": "arn:aws:ec2:us-west-1:123456789012:prefix-list/pl-0019d1157c40d82a7",
        "prefixListId": "pl-0019d1157c40d82a7",
        "prefixListName": "dwfix-ec2-d393e412-pl",
        "state": "create-in-progress",
        "tagSet": {
          "item": [
            {
              "key": "dwfix",
              "value": "1"
            },
            {
              "key": "Name",
              "value": "dwfix-ec2-d393e412"
            }
          ]
        },
        "version": 1
      },
      "requestId": "927fa68a-ad07-4eb0-8bfe-2e78558c1310",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateNatGateway

#
Service
ec2

Description

Creates a NAT gateway in the specified subnet.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "dbb3b16e-549e-48bc-bfa6-9ca4c2845e43",
  "eventName": "CreateNatGateway",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "98cac787-9654-4d84-9fbc-d42f1023e2ef",
  "requestParameters": {
    "CreateNatGatewayRequest": {
      "AllocationId": "eipalloc-08a083beb7e83dbc0",
      "ClientToken": "86C58940-D407-4E02-A617-E40168CFDBE2",
      "ConnectivityType": "public",
      "SubnetId": "subnet-01ed430875cff578d",
      "TagSpecification": {
        "ResourceType": "natgateway",
        "Tag": [
          {
            "Key": "StratusRedTeam",
            "Value": true,
            "tag": 1
          },
          {
            "Key": "Name",
            "Value": "stratus-red-team-ec2-steal-credentials-vpc-us-east-1a",
            "tag": 2
          }
        ],
        "tag": 1
      }
    }
  },
  "responseElements": {
    "CreateNatGatewayResponse": {
      "clientToken": "86C58940-D407-4E02-A617-E40168CFDBE2",
      "natGateway": {
        "connectivityType": "public",
        "createTime": "2023-07-10T11:55:14.000Z",
        "natGatewayAddressSet": {
          "item": {
            "allocationId": "eipalloc-08a083beb7e83dbc0",
            "isPrimary": true,
            "status": "associating"
          }
        },
        "natGatewayId": "nat-03575abbac42080d9",
        "state": "pending",
        "subnetId": "subnet-01ed430875cff578d",
        "tagSet": {
          "item": [
            {
              "key": "StratusRedTeam",
              "value": true
            },
            {
              "key": "Name",
              "value": "stratus-red-team-ec2-steal-credentials-vpc-us-east-1a"
            }
          ]
        },
        "vpcId": "vpc-06fe1a64761a0f720"
      },
      "requestId": "98cac787-9654-4d84-9fbc-d42f1023e2ef",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

References #

CreateNetworkInsightsAccessScope

#
Service
ec2

Description

Creates a Network Access Scope.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "466a2f94-e5ce-40b5-a3dc-5547058d2996",
  "eventName": "CreateNetworkInsightsAccessScope",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:46:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "db54f42f-6ea7-4bbc-8d51-b4cb8ebcc69e",
  "requestParameters": {
    "CreateNetworkInsightsAccessScopeRequest": {
      "ClientToken": "d255bb82175f43959388c5b8c00843a1",
      "TagSpecification": {
        "ResourceType": "network-insights-access-scope",
        "Tag": [
          {
            "Key": "Name",
            "Value": "dwfix-ec2-d393e412",
            "tag": 1
          },
          {
            "Key": "dwfix",
            "Value": "1",
            "tag": 2
          }
        ],
        "tag": 1
      }
    }
  },
  "responseElements": {
    "CreateNetworkInsightsAccessScopeResponse": {
      "networkInsightsAccessScope": {
        "createdDate": "2026-06-29T22:46:01.733Z",
        "networkInsightsAccessScopeArn": "arn:aws:ec2:us-west-1:123456789012:network-insights-access-scope/nis-09c07334f0c179e68",
        "networkInsightsAccessScopeId": "nis-09c07334f0c179e68",
        "tagSet": {
          "item": [
            {
              "key": "dwfix",
              "value": "1"
            },
            {
              "key": "Name",
              "value": "dwfix-ec2-d393e412"
            }
          ]
        },
        "updatedDate": "2026-06-29T22:46:01.733Z"
      },
      "networkInsightsAccessScopeContent": {
        "networkInsightsAccessScopeId": "nis-09c07334f0c179e68"
      },
      "requestId": "db54f42f-6ea7-4bbc-8d51-b4cb8ebcc69e",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateNetworkInsightsPath

#
Service
ec2

Description

Creates a path to analyze for reachability.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "7776d5d7-09ca-4a15-9bd8-3a04760cc839",
  "eventName": "CreateNetworkInsightsPath",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:46:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "97fdb5aa-7f0f-4803-bcf9-26a397fb4608",
  "requestParameters": {
    "CreateNetworkInsightsPathRequest": {
      "ClientToken": "a6e2f3dc7cc94e47bb114cc18c6209a9",
      "Destination": "igw-03d64a9d751ff8ddf",
      "Protocol": "tcp",
      "Source": "i-0a4c8f9124bcc1a50",
      "TagSpecification": {
        "ResourceType": "network-insights-path",
        "Tag": [
          {
            "Key": "Name",
            "Value": "dwfix-ec2-d393e412",
            "tag": 1
          },
          {
            "Key": "dwfix",
            "Value": "1",
            "tag": 2
          }
        ],
        "tag": 1
      }
    }
  },
  "responseElements": {
    "CreateNetworkInsightsPathResponse": {
      "networkInsightsPath": {
        "createdDate": "2026-06-29T22:46:00.276Z",
        "destination": "igw-03d64a9d751ff8ddf",
        "destinationArn": "arn:aws:ec2:us-west-1:123456789012:internet-gateway/igw-03d64a9d751ff8ddf",
        "networkInsightsPathArn": "arn:aws:ec2:us-west-1:123456789012:network-insights-path/nip-01e67beb8a4227dca",
        "networkInsightsPathId": "nip-01e67beb8a4227dca",
        "protocol": "tcp",
        "source": "i-0a4c8f9124bcc1a50",
        "sourceArn": "arn:aws:ec2:us-west-1:123456789012:instance/i-0a4c8f9124bcc1a50",
        "tagSet": {
          "item": [
            {
              "key": "dwfix",
              "value": "1"
            },
            {
              "key": "Name",
              "value": "dwfix-ec2-d393e412"
            }
          ]
        }
      },
      "requestId": "97fdb5aa-7f0f-4803-bcf9-26a397fb4608",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateNetworkInterface

#
Service
ec2

Description

Creates a network interface in the specified subnet.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "16034e79-0235-4886-9566-19d4a4ca1d72",
  "eventName": "CreateNetworkInterface",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "18b3084b-7025-4894-aa0c-8a9e953e4038",
  "requestParameters": {
    "clientToken": "C265B64D-B8B2-4C8F-912B-A346F34FC63A",
    "groupSet": {},
    "privateIpAddressesSet": {
      "items": [
        {
          "primary": true,
          "privateIpAddress": "10.0.1.10"
        }
      ]
    },
    "subnetId": "subnet-0ed352584ab4aa265",
    "tagSpecificationSet": {
      "items": [
        {
          "resourceType": "network-interface",
          "tags": [
            {
              "key": "StratusRedTeam",
              "value": "true"
            }
          ]
        }
      ]
    }
  },
  "responseElements": {
    "networkInterface": {
      "availabilityZone": "us-east-1a",
      "groupSet": {
        "items": [
          {
            "groupId": "sg-0b233157065b7d5e2",
            "groupName": "default"
          }
        ]
      },
      "interfaceType": "interface",
      "ipv6AddressesSet": {},
      "macAddress": "12:c4:b6:95:a1:71",
      "networkInterfaceId": "eni-076fa9fb98a2500a7",
      "ownerId": "123837392027",
      "privateIpAddress": "10.0.1.10",
      "privateIpAddressesSet": {
        "item": [
          {
            "primary": true,
            "privateIpAddress": "10.0.1.10"
          }
        ]
      },
      "requesterId": "AIDATFQR7NSC5AU2ZV3IE",
      "requesterManaged": false,
      "sourceDestCheck": true,
      "status": "pending",
      "subnetId": "subnet-0ed352584ab4aa265",
      "tagSet": {
        "items": [
          {
            "key": "StratusRedTeam",
            "value": "true"
          }
        ]
      },
      "vpcId": "vpc-06fe1a64761a0f720"
    },
    "requestId": "18b3084b-7025-4894-aa0c-8a9e953e4038"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

CreateNetworkInterfacePermission

#
Service
ec2

Description

Grants an Amazon Web Services-authorized account permission to attach the specified network interface to an instance in their account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.OperationNotPermitted",
  "errorMessage": "Permissions given to AWS service principals are not currently supported.",
  "eventCategory": "Management",
  "eventID": "cc778ae5-8640-4612-a5e5-22c1199d9578",
  "eventName": "CreateNetworkInterfacePermission",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:45:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "bf0ff06a-5e66-4c34-a7c4-32e0d8419373",
  "requestParameters": {
    "CreateNetworkInterfacePermissionRequest": {
      "AwsService": "ec2.amazonaws.com",
      "NetworkInterfaceId": "eni-025f9aaa17cd9ff32",
      "Permission": "EIP-ASSOCIATE"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreatePlacementGroup

#
Service
ec2

Description

Creates a placement group that you launch cluster instances into.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "bdf8bedf-4132-4d90-a5b4-68505c7bd1b9",
  "eventName": "CreatePlacementGroup",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:40:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "836d68e1-c05b-458d-a56c-b46556b54a25",
  "requestParameters": {
    "groupName": "dwfix-ec2-d393e412-pg",
    "strategy": "spread",
    "tagSpecificationSet": {
      "items": [
        {
          "resourceType": "placement-group",
          "tags": [
            {
              "key": "Name",
              "value": "dwfix-ec2-d393e412"
            },
            {
              "key": "dwfix",
              "value": "1"
            }
          ]
        }
      ]
    }
  },
  "responseElements": {
    "_return": true,
    "placementGroup": {
      "groupArn": "arn:aws:ec2:us-west-1:123456789012:placement-group/dwfix-ec2-d393e412-pg",
      "groupId": "pg-090818db2c412fcc8",
      "groupName": "dwfix-ec2-d393e412-pg",
      "spreadLevel": "rack",
      "state": "available",
      "strategy": "spread",
      "tagSet": {
        "items": [
          {
            "key": "Name",
            "value": "dwfix-ec2-d393e412"
          },
          {
            "key": "dwfix",
            "value": "1"
          }
        ]
      }
    },
    "requestId": "836d68e1-c05b-458d-a56c-b46556b54a25"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreatePublicIpv4Pool

#
Service
ec2

Description

Creates a public IPv4 address pool.

CreateReplaceRootVolumeTask

#
Service
ec2

Description

Replaces the EBS-backed root volume for a running instance with a new volume that is restored to the original root volume's launch state, that is restored to a specific snapshot taken from the original root volume, or that is restored from.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.IncorrectInstanceState",
  "errorMessage": "Instance is not in the running state.",
  "eventCategory": "Management",
  "eventID": "866d7dec-28b2-4503-9cf3-b495b33e85c2",
  "eventName": "CreateReplaceRootVolumeTask",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:45:36Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "661f2327-39b6-4af1-8064-905a4a746ccc",
  "requestParameters": {
    "CreateReplaceRootVolumeTaskRequest": {
      "ClientToken": "4e73636f-6dbe-4e2b-8881-2df7650bc482",
      "DeleteReplacedRootVolume": false,
      "InstanceId": "i-0a4c8f9124bcc1a50",
      "SnapshotId": "snap-0ae577a47e091fcaa"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateReservedInstancesListing

#
Service
ec2

Description

Creates a listing for Amazon EC2 Reserved Instances to be sold in the Reserved Instance Marketplace.

CreateRestoreImageTask

#
Service
ec2

Description

Starts a task that restores an AMI from an Amazon S3 object that was previously created by using CreateStoreImageTask.

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::errorCode (panther rule field)neClient.DryRunOperation1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

CreateRouteServer

#
Service
ec2

Description

Creates a new route server to manage dynamic routing in a VPC.

CreateRouteServerEndpoint

#
Service
ec2

Description

Creates a new endpoint for a route server in a specified subnet.

CreateRouteServerPeer

#
Service
ec2

Description

Creates a new BGP peer for a specified route server endpoint.

CreateSecondaryNetwork

#
Service
ec2

Description

Creates a secondary network.

CreateSecondarySubnet

#
Service
ec2

Description

Creates a secondary subnet in a secondary network.

CreateSnapshot

#
Service
ec2

Description

Creates a snapshot of an Amazon EBS volume and stores it in Amazon S3.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "9eede385-5c6d-405e-9dda-fd10950e9069",
  "eventName": "CreateSnapshot",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:11:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "d0778782-df1d-4eb6-91da-edbefb7e7db1",
  "requestParameters": {
    "tagSpecificationSet": {
      "items": [
        {
          "resourceType": "snapshot",
          "tags": [
            {
              "key": "StratusRedTeam",
              "value": "true"
            }
          ]
        }
      ]
    },
    "volumeId": "vol-0fc2e34e74650e145"
  },
  "responseElements": {
    "encrypted": false,
    "ownerId": "123837392027",
    "requestId": "d0778782-df1d-4eb6-91da-edbefb7e7db1",
    "snapshotId": "snap-083d3b857c13988bc",
    "startTime": 1688991086923,
    "status": "pending",
    "tagSet": {
      "items": [
        {
          "key": "StratusRedTeam",
          "value": "true"
        }
      ]
    },
    "volumeId": "vol-0fc2e34e74650e145",
    "volumeSize": "1"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_36659dd6-3cf5-4369-ae72-21be4cb11547 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

CreateSnapshots

#
Service
ec2

Description

Creates crash-consistent snapshots of multiple EBS volumes attached to an Amazon EC2 instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "468d0921-004a-4b5e-863b-d6b41cf35476",
  "eventName": "CreateSnapshots",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:42:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "42ad60be-7fbd-4a37-8994-aaf739ed1f84",
  "requestParameters": {
    "CreateSnapshotsRequest": {
      "Description": "dwfix-ec2-d393e412 multi-snap",
      "InstanceSpecification": {
        "ExcludeBootVolume": false,
        "InstanceId": "i-0a4c8f9124bcc1a50"
      },
      "TagSpecification": {
        "ResourceType": "snapshot",
        "Tag": [
          {
            "Key": "Name",
            "Value": "dwfix-ec2-d393e412",
            "tag": 1
          },
          {
            "Key": "dwfix",
            "Value": "1",
            "tag": 2
          }
        ],
        "tag": 1
      }
    }
  },
  "responseElements": {
    "CreateSnapshotsResponse": {
      "requestId": "42ad60be-7fbd-4a37-8994-aaf739ed1f84",
      "snapshotSet": {
        "item": {
          "description": "dwfix-ec2-d393e412 multi-snap",
          "encrypted": false,
          "ownerId": "123456789012",
          "progress": "",
          "snapshotId": "snap-059f701cce7160c5e",
          "startTime": "2026-06-29T22:42:02.839Z",
          "state": "pending",
          "tagSet": {
            "item": [
              {
                "key": "dwfix",
                "value": "1"
              },
              {
                "key": "Name",
                "value": "dwfix-ec2-d393e412"
              }
            ]
          },
          "volumeId": "vol-08f7e4b919b04f996",
          "volumeSize": 8
        }
      },
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateSpotDatafeedSubscription

#
Service
ec2

Description

Creates a datafeed for Spot Instances, enabling you to view Spot Instance usage logs.

CreateSubnet

#
Service
ec2

Description

Creates a subnet in an existing VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "078ad2dc-a2bf-46ee-90dc-f524fb5fe1f1",
  "eventName": "CreateSubnet",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "8dd15b1c-a6bc-4c98-9299-a3554bac2203",
  "requestParameters": {
    "availabilityZone": "us-east-1a",
    "cidrBlock": "10.0.128.0/24",
    "tagSpecificationSet": {
      "items": [
        {
          "resourceType": "subnet",
          "tags": [
            {
              "key": "Name",
              "value": "stratus-red-team-ec2-steal-credentials-vpc-public-us-east-1a"
            },
            {
              "key": "StratusRedTeam",
              "value": "true"
            }
          ]
        }
      ]
    },
    "vpcId": "vpc-06fe1a64761a0f720"
  },
  "responseElements": {
    "requestId": "8dd15b1c-a6bc-4c98-9299-a3554bac2203",
    "subnet": {
      "assignIpv6AddressOnCreation": false,
      "availabilityZone": "us-east-1a",
      "availabilityZoneId": "use1-az2",
      "availableIpAddressCount": 251,
      "cidrBlock": "10.0.128.0/24",
      "defaultForAz": false,
      "enableDns64": false,
      "ipv6CidrBlockAssociationSet": {},
      "ipv6Native": false,
      "mapPublicIpOnLaunch": false,
      "ownerId": "123837392027",
      "privateDnsNameOptionsOnLaunch": {
        "enableResourceNameDnsAAAARecord": false,
        "enableResourceNameDnsARecord": false,
        "hostnameType": "ip-name"
      },
      "state": "available",
      "subnetArn": "arn:aws:ec2:us-east-1:123837392027:subnet/subnet-01ed430875cff578d",
      "subnetId": "subnet-01ed430875cff578d",
      "tagSet": {
        "items": [
          {
            "key": "Name",
            "value": "stratus-red-team-ec2-steal-credentials-vpc-public-us-east-1a"
          },
          {
            "key": "StratusRedTeam",
            "value": "true"
          }
        ]
      },
      "vpcId": "vpc-06fe1a64761a0f720"
    }
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

CreateSubnetCidrReservation

#
Service
ec2

Description

Creates a subnet CIDR reservation.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "c0e6f60b-664a-4d07-97a8-542b7dab1d5d",
  "eventName": "CreateSubnetCidrReservation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:48:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ebca3a22-d790-4d34-b973-8761c1c01e25",
  "requestParameters": {
    "CreateSubnetCidrReservationRequest": {
      "Cidr": "10.0.1.0/28",
      "Description": "dwfix test reservation",
      "ReservationType": "prefix",
      "SubnetId": "subnet-00c955600d8a2bf71"
    }
  },
  "responseElements": {
    "CreateSubnetCidrReservationResponse": {
      "requestId": "ebca3a22-d790-4d34-b973-8761c1c01e25",
      "subnetCidrReservation": {
        "cidr": "10.0.1.0/28",
        "description": "dwfix test reservation",
        "ownerId": "123456789012",
        "reservationType": "prefix",
        "subnetCidrReservationId": "scr-058adb7c0eca14d57",
        "subnetId": "subnet-00c955600d8a2bf71"
      },
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateTags

#
Service
ec2

Description

Adds or overwrites one or more tags for the specified EC2 resource or resources.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:58:38Z",
  "eventSource": "ec2.amazonaws.com",
  "eventName": "CreateTags",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#ec2.create-tags",
  "requestParameters": {
    "resourcesSet": {
      "items": [
        {
          "resourceId": "sg-0200d267c43de2fbc"
        }
      ]
    },
    "tagSet": {
      "items": [
        {
          "key": "dw-harness",
          "value": "aws_harness"
        }
      ]
    }
  },
  "responseElements": {
    "requestId": "61115b13-4583-4116-88f8-29cc9593ab69",
    "_return": true
  },
  "requestID": "61115b13-4583-4116-88f8-29cc9593ab69",
  "eventID": "8fe8df53-6ebe-4ead-a0fd-596cdb9232cb",
  "readOnly": false,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com"
  }
}

CreateTrafficMirrorFilter

#
Service
ec2

Description

Creates a Traffic Mirror filter.

Example CloudTrail Event #

{
  "awsRegion": "ap-southeast-2",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation. Encoded authorization failure message: QAyRWNFkfMIXJa_Z24XhmlxaYZfvxYqlVBS7f6lWOZIOhyRfSdy9oqmg-PRqb7hOeN3Wmg7L0SETVhj0qShMzpfbJNjvTwSLHyrzh8ma_L0nm1AExsRAVs5KC8aLabBpyO8aWLdSUgLZMTo5ckefoM5kAoaKDnYv758JTgBxQGbQacHC2xDEPfKRy5v9IZggKlhrR3oX7avehXY9ke3Rc0cIiscEM5arn3Gpk6yOserJnrI-DfP9lREj0zvEbK_mn4wLw93gzOVa3JJ-X2Dau2TATmRr3cBCoW3yTvJU_QuMaxloOa6h7HdDL2TXRQsgN5Y3LVVskKwXQGCk2C_ssnLALYalTg7IkLrZLS7hfW6lm7Fpd7FyIlU5LuZC_iiRkcKtz2eIcx6-LgLALH4xxY1nrgeMmgxaIBypSIO_ib1-WLImy4Bd-Bj8Q58ffnR1f1UNKrZNI3ekGii36rVT5d2HwglTKgSQ6KwruHULtep80BcjX2kKF3woTigha6GY_7GTQobvmmCWH-1aPIDuw3B2K9H506aQ",
  "eventID": "2997ff89-8331-4c0c-b3bf-780bd5d0decf",
  "eventName": "CreateTrafficMirrorFilter",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-04-10T14:58:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "9e2b8810-68ba-4998-b4e1-cfb9dfd3ea30",
  "requestParameters": {
    "CreateTrafficMirrorFilterRequest": {
      "ClientToken": "8d622c29-fadf-47f0-b71b-b0404d4c48ff"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "255.171.1.252",
  "userAgent": "aws-cli/1.18.31 Python/3.8.2 Linux/4.9.184-linuxkit botocore/1.15.31",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

CreateTrafficMirrorFilterRule

#
Service
ec2

Description

Creates a Traffic Mirror filter rule.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:58:56Z",
  "eventSource": "ec2.amazonaws.com",
  "eventName": "CreateTrafficMirrorFilterRule",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#ec2.create-traffic-mirror-filter-rule",
  "requestParameters": {
    "CreateTrafficMirrorFilterRuleRequest": {
      "RuleAction": "accept",
      "SourceCidrBlock": "198.51.100.0/24",
      "RuleNumber": 100,
      "DestinationCidrBlock": "203.0.113.0/24",
      "ClientToken": "a44f4b7e-ea82-4b9e-8c4d-e15c91f1cc93",
      "Protocol": 6,
      "TrafficDirection": "ingress",
      "TrafficMirrorFilterId": "tmf-0dab8854170a7a4ad"
    }
  },
  "responseElements": {
    "CreateTrafficMirrorFilterRuleResponse": {
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/",
      "requestId": "0522e94a-cb54-410e-b355-3e0bb19f14ab",
      "clientToken": "a44f4b7e-ea82-4b9e-8c4d-e15c91f1cc93",
      "trafficMirrorFilterRule": {
        "destinationCidrBlock": "203.0.113.0/24",
        "ruleAction": "accept",
        "protocol": 6,
        "ruleNumber": 100,
        "sourceCidrBlock": "198.51.100.0/24",
        "trafficDirection": "ingress",
        "trafficMirrorFilterId": "tmf-0dab8854170a7a4ad",
        "trafficMirrorFilterRuleId": "tmfr-00f1c5b47fd53fadf"
      }
    }
  },
  "requestID": "0522e94a-cb54-410e-b355-3e0bb19f14ab",
  "eventID": "46bd9e8a-bf11-4a87-93cb-7efb942e31b6",
  "readOnly": false,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

CreateTrafficMirrorTarget

#
Service
ec2

Description

Creates a target for your Traffic Mirror session.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation. User: arn:aws:iam::123456789012:user/TrailDiscover is not authorized to perform: ec2:CreateTrafficMirrorTarget on resource: arn:aws:ec2:us-east-1:192374575148:network-interface/* because no identity-based policy allows the ec2:CreateTrafficMirrorTarget action. Encoded authorization failure message: H7q_Ce16dv2QHxzQQzWtKzMHnAfDdtrbGBaK1JPNY7BDyRralS5VrS04LZPDVb00qAeL-9LICwyTGNPnw6WMLNLhI6xelM2dVEXvhM9cBriIgvBfJgffxMSUQbN3e-lXfdmm7407CsCQ_xBhbUT3Or1BcCESaOLKm7XSSl3-RrYsNXgjF8f4hTqTh8zfi8fviy6VOAtJbjV7Ol73ZxK7PGq30qZVaL4utsysXubvuIBv961D34obWDqElsnct4PF5LfiK-rZmmJBhWHFYpke9k8R2-w-WtgYOzw9VJAoO4OfnyDOeK4skZR8OiHAe-k60PRDMB9SUUU-l0l8GIz3BaXxzvU4QmEDrCU9om8vEo8h7pvKlhs9n5zXql1QsGL7PLclgKob5QD1MWmHwWe9sauKKhezc3Qe_naoQMO6tRqV4vQqkFLjkjdCmDxN5NVnYrZ8lUD2_YFb5gU5Ke7RGEqSi10RKB1gWZvuI0aBvxym26OBjHz6Oh2OuJ7rKUo4gpzFf-uaKbdnPHXzG6atD3W-BXvUNnDTffEjwEn_sg",
  "eventCategory": "Management",
  "eventID": "db312c37-74a0-46c7-a801-5e6da8c4d34d",
  "eventName": "CreateTrafficMirrorTarget",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2024-08-18T14:09:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.09",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "700e210b-b6ba-4968-8309-90f0ac13eef4",
  "requestParameters": {
    "CreateTrafficMirrorTargetRequest": {
      "ClientToken": "1b22a7ef-cced-4535-9ebc-cdd46913c976",
      "Description": "TrailDiscoverDescription",
      "NetworkInterfaceId": "TrailDiscoverNetworkInterfaceId",
      "NetworkLoadBalancerArn": "TrailDiscoverNetworkLoadBalancerArn"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "0.0.0.0",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "aws-cli/2.17.32 md/awscrt#0.21.2 ua/2.0 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.11.9 md/pyimpl#CPython exec-env/grimoire_fbb74a09-3b31-4160-bdc2-a680f206a0a8 cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#ec2.create-traffic-mirror-target",
  "userIdentity": {
    "accessKeyId": "AKIA****************",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/TrailDiscover",
    "principalId": "AROA****************:User",
    "type": "IAMUser",
    "userName": "TrailDiscover"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

CreateTransitGateway

#
Service
ec2

Description

Creates a transit gateway.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "9c89ee84-fb93-4cf0-aa29-83cc9e1ee8ac",
  "eventName": "CreateTransitGateway",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:40:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "028b6061-42ca-43e5-b7d0-a70271d7c7b5",
  "requestParameters": {
    "CreateTransitGatewayRequest": {
      "Description": "dwfix-ec2-d393e412 tgw",
      "Options": {
        "AutoAcceptSharedAttachments": "disable",
        "DefaultRouteTableAssociation": "disable",
        "DefaultRouteTablePropagation": "disable"
      },
      "TagSpecification": {
        "ResourceType": "transit-gateway",
        "Tag": [
          {
            "Key": "Name",
            "Value": "dwfix-ec2-d393e412",
            "tag": 1
          },
          {
            "Key": "dwfix",
            "Value": "1",
            "tag": 2
          }
        ],
        "tag": 1
      }
    }
  },
  "responseElements": {
    "CreateTransitGatewayResponse": {
      "requestId": "028b6061-42ca-43e5-b7d0-a70271d7c7b5",
      "transitGateway": {
        "creationTime": "2026-06-29T22:40:01.000Z",
        "description": "dwfix-ec2-d393e412 tgw",
        "options": {
          "amazonSideAsn": 64512,
          "autoAcceptSharedAttachments": "disable",
          "defaultRouteTableAssociation": "disable",
          "defaultRouteTablePropagation": "disable",
          "dnsSupport": "enable",
          "encryptionSupport": {
            "encryptionState": "disabled"
          },
          "multicastSupport": "disable",
          "securityGroupReferencingSupport": "disable",
          "vpnEcmpSupport": "enable"
        },
        "ownerId": "123456789012",
        "state": "pending",
        "tagSet": {
          "item": [
            {
              "key": "Name",
              "value": "dwfix-ec2-d393e412"
            },
            {
              "key": "dwfix",
              "value": "1"
            }
          ]
        },
        "transitGatewayArn": "arn:aws:ec2:us-west-1:123456789012:transit-gateway/tgw-0109d0ce00ed6848b",
        "transitGatewayId": "tgw-0109d0ce00ed6848b"
      },
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateTransitGatewayConnect

#
Service
ec2

Description

Creates a Connect attachment from a specified transit gateway attachment.

CreateTransitGatewayConnectPeer

#
Service
ec2

Description

Creates a Connect peer for a specified transit gateway Connect attachment between a transit gateway and an appliance.

CreateTransitGatewayMeteringPolicy

#
Service
ec2

Description

Creates a metering policy for a transit gateway to track and measure network traffic.

CreateTransitGatewayMeteringPolicyEntry

#
Service
ec2

Description

Creates an entry in a transit gateway metering policy to define traffic measurement rules.

CreateTransitGatewayMulticastDomain

#
Service
ec2

Description

Creates a multicast domain using the specified transit gateway.

CreateTransitGatewayPeeringAttachment

#
Service
ec2

Description

Requests a transit gateway peering attachment between the specified transit gateway (requester) and a peer transit gateway (accepter).

CreateTransitGatewayPolicyTable

#
Service
ec2

Description

Creates a transit gateway policy table.

CreateTransitGatewayPrefixListReference

#
Service
ec2

Description

Creates a reference (route) to a prefix list in a specified transit gateway route table.

CreateTransitGatewayRoute

#
Service
ec2

Description

Creates a static route for the specified transit gateway route table.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.IncorrectState",
  "errorMessage": "tgw-rtb-0f5c12c8b5c90a1a1 is in invalid state",
  "eventCategory": "Management",
  "eventID": "3859ff2f-dc45-4702-aeda-739c007f7822",
  "eventName": "CreateTransitGatewayRoute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:46:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c3311431-a523-4db1-acfc-c749c44ad8f6",
  "requestParameters": {
    "CreateTransitGatewayRouteRequest": {
      "Blackhole": true,
      "DestinationCidrBlock": "192.168.100.0/24",
      "TransitGatewayRouteTableId": "tgw-rtb-0f5c12c8b5c90a1a1"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateTransitGatewayRouteTable

#
Service
ec2

Description

Creates a route table for the specified transit gateway.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "ad0e524f-7e21-429f-b3c0-6fa9c80c8e81",
  "eventName": "CreateTransitGatewayRouteTable",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:46:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5fb6adc5-d398-4d5d-9325-3f91f58cd374",
  "requestParameters": {
    "CreateTransitGatewayRouteTableRequest": {
      "TagSpecifications": {
        "ResourceType": "transit-gateway-route-table",
        "Tag": [
          {
            "Key": "Name",
            "Value": "dwfix-ec2-d393e412",
            "tag": 1
          },
          {
            "Key": "dwfix",
            "Value": "1",
            "tag": 2
          }
        ],
        "tag": 1
      },
      "TransitGatewayId": "tgw-0109d0ce00ed6848b"
    }
  },
  "responseElements": {
    "CreateTransitGatewayRouteTableResponse": {
      "requestId": "5fb6adc5-d398-4d5d-9325-3f91f58cd374",
      "transitGatewayRouteTable": {
        "creationTime": "2026-06-29T22:46:11.000Z",
        "defaultAssociationRouteTable": false,
        "defaultPropagationRouteTable": false,
        "state": "pending",
        "tagSet": {
          "item": [
            {
              "key": "Name",
              "value": "dwfix-ec2-d393e412"
            },
            {
              "key": "dwfix",
              "value": "1"
            }
          ]
        },
        "transitGatewayId": "tgw-0109d0ce00ed6848b",
        "transitGatewayRouteTableId": "tgw-rtb-0f5c12c8b5c90a1a1"
      },
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateTransitGatewayRouteTableAnnouncement

#
Service
ec2

Description

Advertises a new transit gateway route table.

CreateTransitGatewayVpcAttachment

#
Service
ec2

Description

Attaches the specified VPC to the specified transit gateway.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "70bfbf53-83db-4d77-b13e-f9cdda3f170f",
  "eventName": "CreateTransitGatewayVpcAttachment",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:46:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "58921e3d-d665-49f5-b365-b3cee323a697",
  "requestParameters": {
    "CreateTransitGatewayVpcAttachmentRequest": {
      "SubnetIds": {
        "content": "subnet-00c955600d8a2bf71",
        "tag": 1
      },
      "TagSpecifications": {
        "ResourceType": "transit-gateway-attachment",
        "Tag": [
          {
            "Key": "Name",
            "Value": "dwfix-ec2-d393e412",
            "tag": 1
          },
          {
            "Key": "dwfix",
            "Value": "1",
            "tag": 2
          }
        ],
        "tag": 1
      },
      "TransitGatewayId": "tgw-0109d0ce00ed6848b",
      "VpcId": "vpc-00c0dad452596a616"
    }
  },
  "responseElements": {
    "CreateTransitGatewayVpcAttachmentResponse": {
      "requestId": "58921e3d-d665-49f5-b365-b3cee323a697",
      "transitGatewayVpcAttachment": {
        "creationTime": "2026-06-29T22:46:12.000Z",
        "options": {
          "applianceModeSupport": "disable",
          "dnsSupport": "enable",
          "ipv6Support": "disable",
          "securityGroupReferencingSupport": "enable"
        },
        "state": "pending",
        "subnetIds": {
          "item": "subnet-00c955600d8a2bf71"
        },
        "tagSet": {
          "item": [
            {
              "key": "Name",
              "value": "dwfix-ec2-d393e412"
            },
            {
              "key": "dwfix",
              "value": "1"
            }
          ]
        },
        "transitGatewayAttachmentId": "tgw-attach-08d8a09ccdcb3d355",
        "transitGatewayId": "tgw-0109d0ce00ed6848b",
        "vpcId": "vpc-00c0dad452596a616",
        "vpcOwnerId": "123456789012"
      },
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateVerifiedAccessEndpoint

#
Service
ec2

Description

An Amazon Web Services Verified Access endpoint is where you define your application along with an optional endpoint-level access policy.

CreateVerifiedAccessGroup

#
Service
ec2

Description

An Amazon Web Services Verified Access group is a collection of Amazon Web Services Verified Access endpoints who's associated applications have similar security requirements.

CreateVerifiedAccessInstance

#
Service
ec2

Description

An Amazon Web Services Verified Access instance is a regional entity that evaluates application requests and grants access only when your security requirements are met.

CreateVerifiedAccessTrustProvider

#
Service
ec2

Description

A trust provider is a third-party entity that creates, maintains, and manages identity information for users and devices.

CreateVolume

#
Service
ec2

Description

Creates an Amazon EBS volume that can be attached to an instance in the same Availability Zone.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "396f94bc-78ec-4b64-917d-aadc2260c81d",
  "eventName": "CreateVolume",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:10:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "5b2c0b96-bec1-4a37-b6d8-3a4ac6c979c2",
  "requestParameters": {
    "clientToken": "7C289842-4CE2-47D0-8706-FBCE5D907C5E",
    "size": "1",
    "tagSpecificationSet": {
      "items": [
        {
          "resourceType": "volume",
          "tags": [
            {
              "key": "StratusRedTeam",
              "value": "true"
            },
            {
              "key": "Name",
              "value": "stratus-red-team-share-ami-ami"
            }
          ]
        }
      ]
    },
    "zone": "us-east-1a"
  },
  "responseElements": {
    "createTime": 1688991025000,
    "encrypted": false,
    "iops": 100,
    "multiAttachEnabled": false,
    "requestId": "5b2c0b96-bec1-4a37-b6d8-3a4ac6c979c2",
    "size": "1",
    "status": "creating",
    "tagSet": {
      "items": [
        {
          "key": "StratusRedTeam",
          "value": "true"
        },
        {
          "key": "Name",
          "value": "stratus-red-team-share-ami-ami"
        }
      ]
    },
    "volumeId": "vol-0a2e548958718390d",
    "volumeType": "gp2",
    "zone": "us-east-1a"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_b47d6b97-21d3-4b01-8937-6f0c23cb2d4b HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

CreateVpc

#
Service
ec2

Description

Creates a VPC with the specified CIDR block.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "f5e4b2d3-a4a2-4a78-b81f-9036f12b623e",
  "eventName": "CreateVpc",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:08Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "227252b0-eb8a-4c29-810e-def37a9f3476",
  "requestParameters": {
    "amazonProvidedIpv6CidrBlock": false,
    "cidrBlock": "10.0.0.0/16",
    "instanceTenancy": "default",
    "tagSpecificationSet": {
      "items": [
        {
          "resourceType": "vpc",
          "tags": [
            {
              "key": "Name",
              "value": "stratus-red-team-ec2-steal-credentials-vpc"
            },
            {
              "key": "StratusRedTeam",
              "value": "true"
            }
          ]
        }
      ]
    }
  },
  "responseElements": {
    "requestId": "227252b0-eb8a-4c29-810e-def37a9f3476",
    "vpc": {
      "cidrBlock": "10.0.0.0/16",
      "cidrBlockAssociationSet": {
        "items": [
          {
            "associationId": "vpc-cidr-assoc-01a3c97bf2a2efa11",
            "cidrBlock": "10.0.0.0/16",
            "cidrBlockState": {
              "state": "associated"
            }
          }
        ]
      },
      "dhcpOptionsId": "dopt-0ef51062810f8ca7b",
      "instanceTenancy": "default",
      "ipv6CidrBlockAssociationSet": {},
      "isDefault": false,
      "ownerId": "123837392027",
      "state": "pending",
      "tagSet": {
        "items": [
          {
            "key": "Name",
            "value": "stratus-red-team-ec2-steal-credentials-vpc"
          },
          {
            "key": "StratusRedTeam",
            "value": "true"
          }
        ]
      },
      "vpcId": "vpc-06fe1a64761a0f720"
    }
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

CreateVpcBlockPublicAccessExclusion

#
Service
ec2

Description

Create a VPC Block Public Access (BPA) exclusion.

CreateVpcEncryptionControl

#
Service
ec2

Description

Creates a VPC Encryption Control configuration for a specified VPC.

CreateVpcEndpoint

#
Service
ec2

Description

Creates a VPC endpoint for a specified AWS service.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "574e7b17-54aa-4874-8164-91000cc1ccce",
  "eventName": "CreateVpcEndpoint",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:48:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4d8089f3-04a1-4492-aad0-d749c2eccb4f",
  "requestParameters": {
    "CreateVpcEndpointRequest": {
      "RouteTableId": {
        "content": "rtb-06b1ec38aa8ffb600",
        "tag": 1
      },
      "ServiceName": "com.amazonaws.us-west-1.s3",
      "TagSpecification": {
        "ResourceType": "vpc-endpoint",
        "Tag": [
          {
            "Key": "Name",
            "Value": "dwfix-ec2-d393e412",
            "tag": 1
          },
          {
            "Key": "dwfix",
            "Value": "1",
            "tag": 2
          }
        ],
        "tag": 1
      },
      "VpcEndpointType": "Gateway",
      "VpcId": "vpc-00c0dad452596a616"
    }
  },
  "responseElements": {
    "CreateVpcEndpointResponse": {
      "requestId": "4d8089f3-04a1-4492-aad0-d749c2eccb4f",
      "vpcEndpoint": {
        "creationTimestamp": "2026-06-29T22:48:47.000Z",
        "dnsEntrySet": "",
        "dnsOptions": {
          "dnsRecordIpType": "service-defined"
        },
        "groupSet": "",
        "ipAddressType": "ipv4",
        "networkInterfaceIdSet": "",
        "ownerId": "123456789012",
        "policyDocument": {
          "Version": "2008-10-17",
          "Statement": [
            {
              "Effect": "Allow",
              "Principal": "*",
              "Action": "*",
              "Resource": "*"
            }
          ]
        },
        "privateDnsEnabled": false,
        "requesterManaged": false,
        "routeTableIdSet": {
          "item": "rtb-06b1ec38aa8ffb600"
        },
        "serviceName": "com.amazonaws.us-west-1.s3",
        "state": "available",
        "subnetIdSet": "",
        "tagSet": {
          "item": [
            {
              "key": "Name",
              "value": "dwfix-ec2-d393e412"
            },
            {
              "key": "dwfix",
              "value": "1"
            }
          ]
        },
        "vpcEndpointId": "vpce-0699134642a5b2f4d",
        "vpcEndpointType": "Gateway",
        "vpcId": "vpc-00c0dad452596a616"
      },
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateVpcEndpointConnectionNotification

#
Service
ec2

Description

Creates a connection notification for a specified VPC endpoint or VPC endpoint service.

CreateVpcEndpointServiceConfiguration

#
Service
ec2

Description

Creates a VPC endpoint service to which service consumers (Amazon Web Services accounts, users, and IAM roles) can connect.

CreateVpcPeeringConnection

#
Service
ec2

Description

Requests a VPC peering connection between two VPCs: a requester VPC that you own and a peer VPC with which to create the connection.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "The request must contain the parameter vpcId",
  "eventID": "a6e13f34-7dee-405a-895b-6ae4e4967614",
  "eventName": "CreateVpcPeeringConnection",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2019-11-17T04:58:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "043e429d-72f8-4233-8379-acf891753a46",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "8.103.248.255",
  "userAgent": "aws-cli/1.14.44 Python/3.6.8 Linux/4.4.0-039049-Microsoft botocore/1.8.48",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

CreateVpnConcentrator

#
Service
ec2

Description

Creates a VPN concentrator that aggregates multiple VPN connections to a transit gateway.

CreateVpnConnection

#
Service
ec2

Description

Creates a VPN connection between an existing virtual private gateway and a VPN customer gateway.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpnGatewayID.NotFound",
  "errorMessage": "The vpnGateway ID 'vgw-03b7415aef1ba49a5' does not exist",
  "eventCategory": "Management",
  "eventID": "5668f6a8-8721-4a46-a08b-2999ed837aac",
  "eventName": "CreateVpnConnection",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:46:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9cad7367-33ed-4749-9558-66b664797612",
  "requestParameters": {
    "customerGatewayId": "cgw-04a9f55555b346fed",
    "options": {
      "staticRoutesOnly": true
    },
    "tagSpecificationSet": {
      "items": [
        {
          "resourceType": "vpn-connection",
          "tags": [
            {
              "key": "Name",
              "value": "dwfix-ec2-d393e412"
            },
            {
              "key": "dwfix",
              "value": "1"
            }
          ]
        }
      ]
    },
    "type": "ipsec.1",
    "vpnGatewayId": "vgw-03b7415aef1ba49a5"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

CreateVpnConnectionRoute

#
Service
ec2

Description

Creates a static route associated with a VPN connection between an existing virtual private gateway and a VPN customer gateway.

CreateVpnGateway

#
Service
ec2

Description

Creates a virtual private gateway.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "cda16e37-f10f-4930-9d3b-396c44cb3f23",
  "eventName": "CreateVpnGateway",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:46:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4e514fa0-925e-4a2c-aafd-58d271032829",
  "requestParameters": {
    "tagSpecificationSet": {
      "items": [
        {
          "resourceType": "vpn-gateway",
          "tags": [
            {
              "key": "Name",
              "value": "dwfix-ec2-d393e412"
            },
            {
              "key": "dwfix",
              "value": "1"
            }
          ]
        }
      ]
    },
    "type": "ipsec.1"
  },
  "responseElements": {
    "requestId": "4e514fa0-925e-4a2c-aafd-58d271032829",
    "vpnGateway": {
      "amazonSideAsn": 64512,
      "attachments": {},
      "state": "pending",
      "tagSet": {
        "items": [
          {
            "key": "Name",
            "value": "dwfix-ec2-d393e412"
          },
          {
            "key": "dwfix",
            "value": "1"
          }
        ]
      },
      "type": "ipsec.1",
      "vpnGatewayId": "vgw-03b7415aef1ba49a5"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteCapacityManagerDataExport

#
Service
ec2

Description

Deletes an existing Capacity Manager data export configuration.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidCapacityManagerDataExportId.Malformed",
  "errorMessage": "The capacity-manager-data-export ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "b72bd82c-1fce-4e9a-8844-43c210b82545",
  "eventName": "DeleteCapacityManagerDataExport",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c00a45f5-3ff9-485c-b54b-702789f071f0",
  "requestParameters": {
    "DeleteCapacityManagerDataExportRequest": {
      "CapacityManagerDataExportId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteCarrierGateway

#
Service
ec2

Description

Deletes a carrier gateway.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.UnsupportedOperation",
  "errorMessage": "The functionality you requested is not available in this region.",
  "eventCategory": "Management",
  "eventID": "2459b9aa-9944-4b72-a9be-f4e337421e95",
  "eventName": "DeleteCarrierGateway",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "09a136b5-460a-4593-b04b-3cf20f5958e1",
  "requestParameters": {
    "DeleteCarrierGatewayRequest": {
      "CarrierGatewayId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteClientVpnEndpoint

#
Service
ec2

Description

Deletes the specified Client VPN endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidClientVpnEndpointId.NotFound",
  "errorMessage": "The client-vpn-endpoint ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "5f80a40d-4cdf-4711-9a7c-7ce30ef450d8",
  "eventName": "DeleteClientVpnEndpoint",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "514c66dd-96f5-4549-9022-20b5053e905b",
  "requestParameters": {
    "DeleteClientVpnEndpointRequest": {
      "ClientVpnEndpointId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteClientVpnRoute

#
Service
ec2

Description

Deletes a route from a Client VPN endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidClientVpnEndpointId.NotFound",
  "errorMessage": "Endpoint dw-probe does not exist",
  "eventCategory": "Management",
  "eventID": "0d8df003-83e9-47f0-9651-fda3cbfb2c9e",
  "eventName": "DeleteClientVpnRoute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e6213a93-27bb-4a14-9437-f2b6df9b7298",
  "requestParameters": {
    "DeleteClientVpnRouteRequest": {
      "ClientVpnEndpointId": "dw-probe",
      "DestinationCidrBlock": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteCoipCidr

#
Service
ec2

Description

Deletes a range of customer-owned IP addresses.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpv4PoolCoipId.Malformed",
  "errorMessage": "The coip-pool ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "54e46b97-90ce-412f-aebd-318c50fd9f9c",
  "eventName": "DeleteCoipCidr",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "22b0b0a2-96ca-43fb-b5f6-efc142e260df",
  "requestParameters": {
    "DeleteCoipCidrRequest": {
      "Cidr": "dw-probe",
      "CoipPoolId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteCoipPool

#
Service
ec2

Description

Deletes a pool of customer-owned IP (CoIP) addresses.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpv4PoolCoipId.Malformed",
  "errorMessage": "The coip-pool ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "0fb92ec6-c726-4786-a6b4-71ed1476d155",
  "eventName": "DeleteCoipPool",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5b36d039-82de-442b-b2eb-2dd56350989c",
  "requestParameters": {
    "DeleteCoipPoolRequest": {
      "CoipPoolId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteCustomerGateway

#
Service
ec2

Description

Deletes the specified customer gateway.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidCustomerGatewayId.Malformed",
  "errorMessage": "Invalid id: \"dw-probe\" (expecting \"cgw-...\")",
  "eventCategory": "Management",
  "eventID": "2863b0e5-d8b7-4c08-9696-6c1fdb34a4b0",
  "eventName": "DeleteCustomerGateway",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "44cd7f85-6617-4bde-b3c6-a9aea98549dd",
  "requestParameters": {
    "customerGatewayId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DeleteDhcpOptions

#
Service
ec2

Description

Deletes the specified set of DHCP options.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidDhcpOptionsId.Malformed",
  "errorMessage": "The dhcp-options ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "fd8cbfae-bff3-4207-8b91-cffa6201e7ca",
  "eventName": "DeleteDhcpOptions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7db3e2fb-3227-4317-9e4a-ddcda80c5e1d",
  "requestParameters": {
    "dhcpOptionsId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteEgressOnlyInternetGateway

#
Service
ec2

Description

Deletes an egress-only internet gateway.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.MalformedGatewayID.NotFound",
  "errorMessage": "The eigw ID dw-probe is malformed",
  "eventCategory": "Management",
  "eventID": "b2de6e37-9e36-4a46-8025-7cb2c1a5b98e",
  "eventName": "DeleteEgressOnlyInternetGateway",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e92e29c1-b278-4d87-99a1-d85e7984f161",
  "requestParameters": {
    "DeleteEgressOnlyInternetGatewayRequest": {
      "EgressOnlyInternetGatewayId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteFleets

#
Service
ec2

Description

Deletes the specified EC2 Fleet request.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidFleetId.Malformed",
  "errorMessage": "The fleet ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "b4fe54a1-d648-4d9b-8396-3ae191efdd64",
  "eventName": "DeleteFleets",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3ad67e84-b206-4f0b-9aed-1e13616d55d1",
  "requestParameters": {
    "DeleteFleetsRequest": {
      "FleetId": {
        "content": "dw-probe",
        "tag": 1
      },
      "TerminateInstances": false
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteFpgaImage

#
Service
ec2

Description

Deletes the specified Amazon FPGA Image (AFI).

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.UnsupportedOperation",
  "errorMessage": "The functionality you requested is not available in this region.",
  "eventCategory": "Management",
  "eventID": "5d0c6d09-512f-4068-8fe4-90bad617f33d",
  "eventName": "DeleteFpgaImage",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ca935361-a773-40c5-9b78-f635b8c3d320",
  "requestParameters": {
    "DeleteFpgaImageRequest": {
      "FpgaImageId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteImageUsageReport

#
Service
ec2

Description

Deletes the specified image usage report.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidImageUsageReportId.Malformed",
  "errorMessage": "The image-usage-report ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "a3d87ad8-d275-4c51-ba41-3dcebeff1b2b",
  "eventName": "DeleteImageUsageReport",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7c228951-cccc-4eee-9a27-32dca1562d9f",
  "requestParameters": {
    "DeleteImageUsageReportRequest": {
      "ReportId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteInstanceConnectEndpoint

#
Service
ec2

Description

Deletes the specified EC2 Instance Connect Endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidInstanceConnectEndpointId.Malformed",
  "errorMessage": "The instance-connect-endpoint ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "6d9c73b2-25d8-4823-9ed9-d312c00bdb9d",
  "eventName": "DeleteInstanceConnectEndpoint",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "64a02afd-280b-4196-a566-f35bbdeb30d7",
  "requestParameters": {
    "DeleteInstanceConnectEndpointRequest": {
      "InstanceConnectEndpointId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteInstanceEventWindow

#
Service
ec2

Description

Deletes the specified event window.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "1 validation error detected: Value 'dw-probe' at 'eventWindowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^iew-[\\w]+$",
  "eventCategory": "Management",
  "eventID": "63c4df52-df3c-4629-8351-252c6180cf67",
  "eventName": "DeleteInstanceEventWindow",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e2444d4a-a7d8-492a-8b1d-9cd746937028",
  "requestParameters": {
    "DeleteInstanceEventWindowRequest": {
      "InstanceEventWindowId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DeleteInternetGateway

#
Service
ec2

Description

Deletes the specified Internet gateway.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "930bcbfc-fe56-4d77-a1c5-c5c6e75812ca",
  "eventName": "DeleteInternetGateway",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:08:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "86886406-e4ff-4536-8880-6c7f49edfd0c",
  "requestParameters": {
    "internetGatewayId": "igw-040b2274c4a167722"
  },
  "responseElements": {
    "_return": true,
    "requestId": "86886406-e4ff-4536-8880-6c7f49edfd0c"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/4.67.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.261 (go1.19.8; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

DeleteIpam

#
Service
ec2

Description

Delete an IPAM.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamId.Malformed",
  "errorMessage": "The specified IPAM Id is not valid. Specify an IPAM Id in the form ipam-xxxxxxxxxxxxxxxxx.",
  "eventCategory": "Management",
  "eventID": "9d9d454c-d6ea-45b6-8f99-1f4ff09d3ce4",
  "eventName": "DeleteIpam",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "611feb20-c634-4265-ac08-49b5ecaef01b",
  "requestParameters": {
    "DeleteIpamRequest": {
      "IpamId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteIpamExternalResourceVerificationToken

#
Service
ec2

Description

Delete a verification token.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamExternalResourceVerificationTokenId.Malformed",
  "errorMessage": "The ipam-external-resource-verification-token ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "8f9494ff-ca98-42e1-8e59-25e618a31114",
  "eventName": "DeleteIpamExternalResourceVerificationToken",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5b4f87e4-760c-4a59-af5c-85a27d9041f6",
  "requestParameters": {
    "DeleteIpamExternalResourceVerificationTokenRequest": {
      "IpamExternalResourceVerificationTokenId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteIpamPolicy

#
Service
ec2

Description

Deletes an IPAM policy.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamPolicyId.Malformed",
  "errorMessage": "The ipam-policy ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "7b356c57-52b8-442b-bf45-896209b7bd21",
  "eventName": "DeleteIpamPolicy",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3ad01d2c-4d9d-437f-aab3-7988dafefceb",
  "requestParameters": {
    "DeleteIpamPolicyRequest": {
      "IpamPolicyId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteIpamPool

#
Service
ec2

Description

Delete an IPAM pool.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamPoolId.Malformed",
  "errorMessage": "The ipam-pool ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "925d96f5-96b4-4dc4-9a53-fe6355730d21",
  "eventName": "DeleteIpamPool",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "787de90d-0f6f-4ef2-bb45-c82d9500058e",
  "requestParameters": {
    "DeleteIpamPoolRequest": {
      "IpamPoolId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteIpamPrefixListResolver

#
Service
ec2

Description

Deletes an IPAM prefix list resolver.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamPrefixListResolverId.Malformed",
  "errorMessage": "The ipam-prefix-list-resolver ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "59c77a51-463f-4d10-bd81-73042645780a",
  "eventName": "DeleteIpamPrefixListResolver",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "79378da3-07a9-444d-9ddf-74534a1302d2",
  "requestParameters": {
    "DeleteIpamPrefixListResolverRequest": {
      "IpamPrefixListResolverId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteIpamPrefixListResolverTarget

#
Service
ec2

Description

Deletes an IPAM prefix list resolver target.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamPrefixListResolverTargetId.Malformed",
  "errorMessage": "The ipam-prefix-list-resolver-target ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "5c34ae54-461c-415e-a05f-554433b911ec",
  "eventName": "DeleteIpamPrefixListResolverTarget",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "04ea60f8-83ea-461a-93ad-fae509a3d105",
  "requestParameters": {
    "DeleteIpamPrefixListResolverTargetRequest": {
      "IpamPrefixListResolverTargetId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteIpamResourceDiscovery

#
Service
ec2

Description

Deletes an IPAM resource discovery.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamResourceDiscoveryId.Malformed",
  "errorMessage": "The specified IPAM resource discovery ID is not valid. Specify an IPAM resource discovery ID in the form ipam-res-disco-xxxxxxxxxxxxxxxxx.",
  "eventCategory": "Management",
  "eventID": "6d2d987f-5de4-4b12-bd34-beeda2995775",
  "eventName": "DeleteIpamResourceDiscovery",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "55407571-0713-4ed4-b1db-4cd6999a5773",
  "requestParameters": {
    "DeleteIpamResourceDiscoveryRequest": {
      "IpamResourceDiscoveryId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteIpamScope

#
Service
ec2

Description

Delete the scope for an IPAM.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamScopeId.Malformed",
  "errorMessage": "The specified IPAM scope ID is not valid. Specify an IPAM scope ID in the form ipam-scope-xxxxxxxxxxxxxxxxx.",
  "eventCategory": "Management",
  "eventID": "531535e9-3ffd-4209-a900-52023d376fa9",
  "eventName": "DeleteIpamScope",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "58d5a287-67e4-4998-bd12-cf0ca294ad19",
  "requestParameters": {
    "DeleteIpamScopeRequest": {
      "IpamScopeId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteKeyPair

#
Service
ec2

Description

Deletes the specified key pair, by removing the public key from Amazon EC2.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "The request must contain the parameter KeyName",
  "eventCategory": "Management",
  "eventID": "64e3fc8c-4519-4103-ad3f-ab98285ecd49",
  "eventName": "DeleteKeyPair",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:45:16Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6f0f7652-2876-41ed-b5d0-87f4322a4682",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteLaunchTemplate

#
Service
ec2

Description

Deletes a launch template.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "Either a launch template ID or a launch template name must be specified in the request.",
  "eventID": "4f0e0cab-3638-41e3-a5a3-011e3111c79c",
  "eventName": "DeleteLaunchTemplate",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2019-11-17T04:59:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "3dfb7cf8-e214-4630-927d-0228cfb24ffd",
  "requestParameters": {
    "DeleteLaunchTemplateRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "8.103.248.255",
  "userAgent": "aws-cli/1.14.44 Python/3.6.8 Linux/4.4.0-039049-Microsoft botocore/1.8.48",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DeleteLaunchTemplateVersions

#
Service
ec2

Description

Deletes one or more versions of a launch template.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "Either a launch template ID or a launch template name must be specified in the request.",
  "eventCategory": "Management",
  "eventID": "3d0e6e47-fadd-4ef0-8d96-716fa6cb4bc1",
  "eventName": "DeleteLaunchTemplateVersions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2366b28a-8555-43e6-8448-bdbcb13bb25c",
  "requestParameters": {
    "DeleteLaunchTemplateVersionsRequest": {
      "LaunchTemplateVersion": {
        "content": "dw-probe",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteLocalGatewayRoute

#
Service
ec2

Description

Deletes the specified route from the specified local gateway route table.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidLocalGatewayRouteTableID.Malformed",
  "errorMessage": "The local-gateway-route-table ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "fad30896-21c9-4818-b366-28a85d51ea94",
  "eventName": "DeleteLocalGatewayRoute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "751a9dc5-de81-426c-a270-3a79cfe96ea3",
  "requestParameters": {
    "DeleteLocalGatewayRouteRequest": {
      "LocalGatewayRouteTableId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteLocalGatewayRouteTable

#
Service
ec2

Description

Deletes a local gateway route table.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidLocalGatewayRouteTableID.Malformed",
  "errorMessage": "The local-gateway-route-table ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "dd6976b0-c895-4fd6-95fb-a8bb7debe09b",
  "eventName": "DeleteLocalGatewayRouteTable",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e7f0da3a-4490-4dd0-b34c-a78feaf49e40",
  "requestParameters": {
    "DeleteLocalGatewayRouteTableRequest": {
      "LocalGatewayRouteTableId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteLocalGatewayRouteTableVirtualInterfaceGroupAssociation

#
Service
ec2

Description

Deletes a local gateway route table virtual interface group association.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidLocalGatewayRouteTableVirtualInterfaceGroupAssociationID.Malformed",
  "errorMessage": "The local-gateway-route-table-virtual-interface-group-association ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "43342a0a-1275-4f82-ae68-a15760881d1e",
  "eventName": "DeleteLocalGatewayRouteTableVirtualInterfaceGroupAssociation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c861d047-49d9-4c6d-9e85-c88c34f033c2",
  "requestParameters": {
    "DeleteLocalGatewayRouteTableVirtualInterfaceGroupAssociationRequest": {
      "LocalGatewayRouteTableVirtualInterfaceGroupAssociationId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteLocalGatewayRouteTableVpcAssociation

#
Service
ec2

Description

Deletes the specified association between a VPC and local gateway route table.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidLocalGatewayRouteTableVpcAssociationID.Malformed",
  "errorMessage": "The local-gateway-route-table-vpc-association ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "186557a1-372a-45e6-92db-6a59ccdbfdf3",
  "eventName": "DeleteLocalGatewayRouteTableVpcAssociation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b0d4fce5-3187-461b-a815-64c2eae1893f",
  "requestParameters": {
    "DeleteLocalGatewayRouteTableVpcAssociationRequest": {
      "LocalGatewayRouteTableVpcAssociationId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteLocalGatewayVirtualInterface

#
Service
ec2

Description

Deletes the specified local gateway virtual interface.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidLocalGatewayVirtualInterfaceID.Malformed",
  "errorMessage": "The local-gateway-virtual-interface ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "32e2793f-4aea-4a82-8e59-e152a1ea68f1",
  "eventName": "DeleteLocalGatewayVirtualInterface",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "32c6bd77-0025-4cbe-a141-6e871c8cba6e",
  "requestParameters": {
    "DeleteLocalGatewayVirtualInterfaceRequest": {
      "LocalGatewayVirtualInterfaceId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteLocalGatewayVirtualInterfaceGroup

#
Service
ec2

Description

Delete the specified local gateway interface group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidLocalGatewayVirtualInterfaceGroupID.Malformed",
  "errorMessage": "The local-gateway-virtual-interface-group ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "daa85093-a804-4682-b123-75d3c4c01afc",
  "eventName": "DeleteLocalGatewayVirtualInterfaceGroup",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "eaf53754-93d0-47f4-841b-1027258ad17c",
  "requestParameters": {
    "DeleteLocalGatewayVirtualInterfaceGroupRequest": {
      "LocalGatewayVirtualInterfaceGroupId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteManagedPrefixList

#
Service
ec2

Description

Deletes the specified managed prefix list.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidPrefixListId.Malformed",
  "errorMessage": "The prefix-list ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "d2b999a4-5107-440d-9d22-490d78a6e7ef",
  "eventName": "DeleteManagedPrefixList",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6c3074e1-b572-4b43-8c38-7ec85f8c2919",
  "requestParameters": {
    "DeleteManagedPrefixListRequest": {
      "PrefixListId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteNatGateway

#
Service
ec2

Description

Deletes the specified NAT gateway.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "de095443-8389-4aa2-9bcb-d3295a255169",
  "eventName": "DeleteNatGateway",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:08:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "de006d2f-9fc1-49b9-814f-b5914c38881b",
  "requestParameters": {
    "DeleteNatGatewayRequest": {
      "NatGatewayId": "nat-0dd264ee104155137"
    }
  },
  "responseElements": {
    "DeleteNatGatewayResponse": {
      "natGatewayId": "nat-0dd264ee104155137",
      "requestId": "de006d2f-9fc1-49b9-814f-b5914c38881b",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DeleteNetworkInsightsAccessScope

#
Service
ec2

Description

Deletes the specified Network Access Scope.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "dw-probe is not a valid NetworkInsightsAccessScopeId.",
  "eventCategory": "Management",
  "eventID": "08ccf09b-38f8-4295-a071-f1de6a1e8f41",
  "eventName": "DeleteNetworkInsightsAccessScope",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:29Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0aee0f8c-a599-407d-9ebc-a995d9094a04",
  "requestParameters": {
    "DeleteNetworkInsightsAccessScopeRequest": {
      "NetworkInsightsAccessScopeId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteNetworkInsightsAccessScopeAnalysis

#
Service
ec2

Description

Deletes the specified Network Access Scope analysis.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "dw-probe is not a valid NetworkInsightsAccessScopeAnalysisId.",
  "eventCategory": "Management",
  "eventID": "f0e01e0f-145f-431e-a0f0-1c8a0870b623",
  "eventName": "DeleteNetworkInsightsAccessScopeAnalysis",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cc0db49e-6d8e-41a1-9565-da55b7f86eeb",
  "requestParameters": {
    "DeleteNetworkInsightsAccessScopeAnalysisRequest": {
      "NetworkInsightsAccessScopeAnalysisId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteNetworkInsightsAnalysis

#
Service
ec2

Description

Deletes the specified network insights analysis.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "dw-probe is not a valid NetworkInsightsAnalysisId.",
  "eventCategory": "Management",
  "eventID": "555ab816-e1d1-4443-8a37-55b3ee158795",
  "eventName": "DeleteNetworkInsightsAnalysis",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ed8be186-4505-4c9a-9e09-25abadd877dd",
  "requestParameters": {
    "DeleteNetworkInsightsAnalysisRequest": {
      "NetworkInsightsAnalysisId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteNetworkInsightsPath

#
Service
ec2

Description

Deletes the specified path.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "dw-probe is not a valid NetworkInsightsPathId.",
  "eventCategory": "Management",
  "eventID": "93228956-4400-4213-8a87-ff53bc91f210",
  "eventName": "DeleteNetworkInsightsPath",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c9940bbf-8a46-47d4-8d51-e27f2e1eac7f",
  "requestParameters": {
    "DeleteNetworkInsightsPathRequest": {
      "NetworkInsightsPathId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteNetworkInterface

#
Service
ec2

Description

Deletes the specified network interface.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "33a9aebf-b70c-4de6-beaa-2b108fa358ce",
  "eventName": "DeleteNetworkInterface",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:12:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "9cffc258-0812-4313-a70f-b2bb26d43c3e",
  "requestParameters": {
    "networkInterfaceId": "eni-06b7a305fe9519d03"
  },
  "responseElements": {
    "_return": true,
    "requestId": "9cffc258-0812-4313-a70f-b2bb26d43c3e"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DeleteNetworkInterfacePermission

#
Service
ec2

Description

Deletes a permission for a network interface.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidPermissionID.Malformed",
  "errorMessage": "The ENI permission ID dw-probe is malformed",
  "eventCategory": "Management",
  "eventID": "24d8f18c-0e01-49f6-b405-c40e8aee6118",
  "eventName": "DeleteNetworkInterfacePermission",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "75a2a1dc-80a1-43e0-88bf-3a710389019c",
  "requestParameters": {
    "DeleteNetworkInterfacePermissionRequest": {
      "NetworkInterfacePermissionId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeletePlacementGroup

#
Service
ec2

Description

Deletes the specified placement group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidPlacementGroup.Unknown",
  "errorMessage": "The placement group 'dw-probe' is unknown.",
  "eventCategory": "Management",
  "eventID": "1b484ef3-d06a-4dfa-86e2-4533e1fd93e6",
  "eventName": "DeletePlacementGroup",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "585e4389-e902-44e6-a917-056fb36169be",
  "requestParameters": {
    "groupName": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeletePublicIpv4Pool

#
Service
ec2

Description

Delete a public IPv4 pool.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidPublicIpv4PoolID.Malformed",
  "errorMessage": "The pool ID 'dw-probe' is invalid.",
  "eventCategory": "Management",
  "eventID": "34b1d0eb-31ad-4ed2-9b77-b82d98d1003c",
  "eventName": "DeletePublicIpv4Pool",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c5deb2b6-70d2-4644-bc1c-fe0869babab6",
  "requestParameters": {
    "DeletePublicIpv4PoolRequest": {
      "PoolId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteQueuedReservedInstances

#
Service
ec2

Description

Deletes the queued purchases for the specified Reserved Instances.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidReservedInstancesID.NotFound",
  "errorMessage": "The reserved-instances ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "86983f06-77a7-482d-a9e9-09e0c9ad8d0d",
  "eventName": "DeleteQueuedReservedInstances",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2703cb41-d917-4cdd-9066-ece143a0a919",
  "requestParameters": {
    "DeleteQueuedReservedInstancesRequest": {
      "ReservedInstancesId": {
        "content": "dw-probe",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteRouteServer

#
Service
ec2

Description

Deletes the specified route server.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRouteServerId.Malformed",
  "errorMessage": "The route-server ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "edbe2bf8-7c66-469c-b0f8-494f0655e4d0",
  "eventName": "DeleteRouteServer",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9ad41cdd-a94d-4ca9-8c55-e83a3d4e3dfa",
  "requestParameters": {
    "DeleteRouteServerRequest": {
      "RouteServerId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteRouteServerEndpoint

#
Service
ec2

Description

Deletes the specified route server endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRouteServerEndpointId.Malformed",
  "errorMessage": "The route-server-endpoint ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "79b33898-3aa9-46ba-a383-5b7ec528a1c5",
  "eventName": "DeleteRouteServerEndpoint",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d5d45c18-8b27-4456-805f-0fab13076e15",
  "requestParameters": {
    "DeleteRouteServerEndpointRequest": {
      "RouteServerEndpointId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteRouteServerPeer

#
Service
ec2

Description

Deletes the specified BGP peer from a route server.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRouteServerPeerId.Malformed",
  "errorMessage": "The route-server-peer ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "99ac6e5e-3074-4a65-9355-75a7ccc64c4c",
  "eventName": "DeleteRouteServerPeer",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d280966c-6f0b-4af2-8fc5-c8480f88fa63",
  "requestParameters": {
    "DeleteRouteServerPeerRequest": {
      "RouteServerPeerId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteSecondaryNetwork

#
Service
ec2

Description

Deletes a secondary network.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidSecondaryNetworkId.Malformed",
  "errorMessage": "The secondary-network ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "64feeeea-9a90-47f4-8c1a-9b1fcebea15e",
  "eventName": "DeleteSecondaryNetwork",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "52af086d-30e0-4491-ac8f-57ac28a9f0cd",
  "requestParameters": {
    "DeleteSecondaryNetworkRequest": {
      "ClientToken": "397f09dd-78d3-4684-a40d-352ff870d2e9",
      "SecondaryNetworkId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteSecondarySubnet

#
Service
ec2

Description

Deletes a secondary subnet.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidAction",
  "errorMessage": "The action DeleteSecondarySubnet is not valid for this web service.",
  "eventCategory": "Management",
  "eventID": "b38c62bd-ba81-41d4-a68a-ffe2d40d12f9",
  "eventName": "DeleteSecondarySubnet",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9fc5460c-5668-476f-ad4a-1e64fd600fe0",
  "requestParameters": {
    "DeleteSecondarySubnetRequest": {
      "ClientToken": "ac401a70-c282-42b1-be2f-0c844d176e77",
      "SecondarySubnetId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteSecurityGroup

#
Service
ec2

Description

Deletes a security group.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:58:40Z",
  "eventSource": "ec2.amazonaws.com",
  "eventName": "DeleteSecurityGroup",
  "awsRegion": "us-west-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#ec2.delete-security-group",
  "requestParameters": {
    "groupId": "sg-0200d267c43de2fbc"
  },
  "responseElements": {
    "requestId": "1f00956a-134f-4cd1-b95c-522e7512c3b6",
    "_return": true,
    "groupId": "sg-0200d267c43de2fbc"
  },
  "requestID": "1f00956a-134f-4cd1-b95c-522e7512c3b6",
  "eventID": "db1b4c66-7939-42db-958b-4de58e2d7f62",
  "readOnly": false,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DeleteSnapshot

#
Service
ec2

Description

Deletes the specified snapshot.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "af96f3f5-5b2d-40dd-886e-4db2d999130b",
  "eventName": "DeleteSnapshot",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:12:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "adf10ecf-38a9-4e9d-9039-881ec40c20b9",
  "requestParameters": {
    "force": false,
    "snapshotId": "snap-083d3b857c13988bc"
  },
  "responseElements": {
    "_return": true,
    "requestId": "adf10ecf-38a9-4e9d-9039-881ec40c20b9"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DeleteSpotDatafeedSubscription

#
Service
ec2

Description

Deletes the datafeed for Spot Instances.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "fe861022-74c7-447f-98a7-43cb3779be1e",
  "eventName": "DeleteSpotDatafeedSubscription",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2019-11-17T04:59:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "9a5d89be-58f7-4feb-8cd7-aef7fb82bff9",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "8.103.248.255",
  "userAgent": "aws-cli/1.14.44 Python/3.6.8 Linux/4.4.0-039049-Microsoft botocore/1.8.48",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DeleteSubnet

#
Service
ec2

Description

Deletes the specified subnet.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "b0fb6697-fa27-429c-b90c-dbd7d0381d49",
  "eventName": "DeleteSubnet",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:08:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "bfa021b8-68ee-44c6-b2c4-3ec501445680",
  "requestParameters": {
    "subnetId": "subnet-096553f59d783f082"
  },
  "responseElements": {
    "_return": true,
    "requestId": "bfa021b8-68ee-44c6-b2c4-3ec501445680"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/4.67.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.261 (go1.19.8; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DeleteSubnetCidrReservation

#
Service
ec2

Description

Deletes a subnet CIDR reservation.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidSubnetCidrReservationID.Malformed",
  "errorMessage": "The subnet-cidr-reservation ID dw-probe is malformed",
  "eventCategory": "Management",
  "eventID": "427c3b67-d7b4-43b7-9117-16a146139602",
  "eventName": "DeleteSubnetCidrReservation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2535cb40-2147-440b-a958-b83cbdd38daa",
  "requestParameters": {
    "DeleteSubnetCidrReservationRequest": {
      "SubnetCidrReservationId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTags

#
Service
ec2

Description

Deletes the specified set of tags from the specified set of resources.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidID",
  "errorMessage": "The ID 'dw-probe' is not valid",
  "eventCategory": "Management",
  "eventID": "3ca0f3c1-8eb2-4d93-ab69-81e45e70da08",
  "eventName": "DeleteTags",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4d41d9e1-f015-4118-8f8c-3f32465a6827",
  "requestParameters": {
    "resourcesSet": {
      "items": [
        {
          "resourceId": "dw-probe"
        }
      ]
    },
    "tagSet": {}
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTrafficMirrorFilter

#
Service
ec2

Description

Deletes the specified Traffic Mirror filter.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "Invalid ID: dw-probe. Filter ID must be 20 characters!",
  "eventCategory": "Management",
  "eventID": "8e3b7df5-bf68-4fa0-8190-b19f303d65a9",
  "eventName": "DeleteTrafficMirrorFilter",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:33Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "23880102-faf6-4c1c-8847-409b8e764395",
  "requestParameters": {
    "DeleteTrafficMirrorFilterRequest": {
      "TrafficMirrorFilterId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DeleteTrafficMirrorFilterRule

#
Service
ec2

Description

Deletes the specified Traffic Mirror rule.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "Invalid ID: dw-probe. Filter rule ID must be 21 characters!",
  "eventCategory": "Management",
  "eventID": "40741a94-0bf6-4b5e-bbfe-00e97dce3228",
  "eventName": "DeleteTrafficMirrorFilterRule",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:33Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2e034ded-8646-493d-97dd-7d1b63d057a3",
  "requestParameters": {
    "DeleteTrafficMirrorFilterRuleRequest": {
      "TrafficMirrorFilterRuleId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DeleteTrafficMirrorSession

#
Service
ec2

Description

Deletes the specified Traffic Mirror session.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "Invalid ID: dw-probe. Session ID must be 20 characters!",
  "eventCategory": "Management",
  "eventID": "f61deef9-0b24-4e6c-b107-8b5d8be8effc",
  "eventName": "DeleteTrafficMirrorSession",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:33Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7645a1c5-203e-4993-abe4-4a0af06310bb",
  "requestParameters": {
    "DeleteTrafficMirrorSessionRequest": {
      "TrafficMirrorSessionId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DeleteTrafficMirrorTarget

#
Service
ec2

Description

Deletes the specified Traffic Mirror target.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "Invalid ID: dw-probe. Target ID must be 20 characters!",
  "eventCategory": "Management",
  "eventID": "48b116ab-7f43-4f5f-bf59-017e9179e82c",
  "eventName": "DeleteTrafficMirrorTarget",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:33Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ea75e663-fc31-483e-a45f-81c9b70589ef",
  "requestParameters": {
    "DeleteTrafficMirrorTargetRequest": {
      "TrafficMirrorTargetId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DeleteTransitGateway

#
Service
ec2

Description

Deletes the specified transit gateway.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayID.Malformed",
  "errorMessage": "Invalid Transit Gateway id dw-probe.",
  "eventCategory": "Management",
  "eventID": "dc2f74ba-d5bc-4be6-b0f7-a1bc42101efc",
  "eventName": "DeleteTransitGateway",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:33Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0053ccfc-879c-499a-94e1-d8aba73c8919",
  "requestParameters": {
    "DeleteTransitGatewayRequest": {
      "TransitGatewayId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTransitGatewayClientVpnAttachment

#
Service
ec2

Description

Deletes a Transit Gateway attachment for a Client VPN endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayAttachmentID.Malformed",
  "errorMessage": "The transit-gateway-attachment ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "94a39324-4fcd-4356-8a53-115a87587b64",
  "eventName": "DeleteTransitGatewayClientVpnAttachment",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ecfa63c3-4c9f-42a0-9f4d-c2908d6042ce",
  "requestParameters": {
    "DeleteTransitGatewayClientVpnAttachmentRequest": {
      "TransitGatewayAttachmentId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTransitGatewayConnect

#
Service
ec2

Description

Deletes the specified Connect attachment.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayAttachmentID.Malformed",
  "errorMessage": "The transit-gateway-attachment ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "22486e16-cd09-45c8-8c10-87a0adac8b76",
  "eventName": "DeleteTransitGatewayConnect",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e3c319ea-d2d6-4e6a-b3e1-48fa91e6ceda",
  "requestParameters": {
    "DeleteTransitGatewayConnectRequest": {
      "TransitGatewayAttachmentId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTransitGatewayConnectPeer

#
Service
ec2

Description

Deletes the specified Connect peer.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayConnectPeerID.Malformed",
  "errorMessage": "The transit-gateway-connect-peer ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "907451da-e802-4fda-93aa-8e82f916440a",
  "eventName": "DeleteTransitGatewayConnectPeer",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "136c48e5-1275-458c-8308-2d9d289f35bd",
  "requestParameters": {
    "DeleteTransitGatewayConnectPeerRequest": {
      "TransitGatewayConnectPeerId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTransitGatewayMeteringPolicy

#
Service
ec2

Description

Deletes a transit gateway metering policy.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayMeteringPolicyIdMalformedException",
  "errorMessage": "The transit-gateway-metering-policy ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "94c7c88e-7e7f-443e-aabc-bae84036fcfe",
  "eventName": "DeleteTransitGatewayMeteringPolicy",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8bbbb7e2-f543-41cb-a562-d9723a6658fb",
  "requestParameters": {
    "DeleteTransitGatewayMeteringPolicyRequest": {
      "TransitGatewayMeteringPolicyId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTransitGatewayMeteringPolicyEntry

#
Service
ec2

Description

Deletes an entry from a transit gateway metering policy.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayMeteringPolicyIdMalformedException",
  "errorMessage": "The transit-gateway-metering-policy ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "cff66025-161f-41a2-96fc-055e121c34d7",
  "eventName": "DeleteTransitGatewayMeteringPolicyEntry",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c579a310-0268-4f2e-a80c-0deb9d67e768",
  "requestParameters": {
    "DeleteTransitGatewayMeteringPolicyEntryRequest": {
      "PolicyRuleNumber": 1,
      "TransitGatewayMeteringPolicyId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTransitGatewayMulticastDomain

#
Service
ec2

Description

Deletes the specified transit gateway multicast domain.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayMulticastDomainId.Malformed",
  "errorMessage": "Invalid Transit Gateway Multicast Domain id dw-probe.",
  "eventCategory": "Management",
  "eventID": "197a74e7-b130-4fce-8216-2c927c5377a6",
  "eventName": "DeleteTransitGatewayMulticastDomain",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "38b1cd73-580f-4467-bc00-d08ab07f9578",
  "requestParameters": {
    "DeleteTransitGatewayMulticastDomainRequest": {
      "TransitGatewayMulticastDomainId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTransitGatewayPeeringAttachment

#
Service
ec2

Description

Deletes a transit gateway peering attachment.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayAttachmentID.Malformed",
  "errorMessage": "Invalid Transit Gateway Attachment id.",
  "eventCategory": "Management",
  "eventID": "04c983ef-5bce-466f-be6e-374f11603289",
  "eventName": "DeleteTransitGatewayPeeringAttachment",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9a9f9ed8-3e68-4e14-af00-7f022fd0e260",
  "requestParameters": {
    "DeleteTransitGatewayPeeringAttachmentRequest": {
      "TransitGatewayAttachmentId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTransitGatewayPolicyTable

#
Service
ec2

Description

Deletes the specified transit gateway policy table.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayPolicyTableId.Malformed",
  "errorMessage": "The transit-gateway-policy-table ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "060ea080-d981-4e37-a68d-23b9617d5819",
  "eventName": "DeleteTransitGatewayPolicyTable",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f8ae87e5-8d17-4b49-a1e5-87dd3a80a1df",
  "requestParameters": {
    "DeleteTransitGatewayPolicyTableRequest": {
      "TransitGatewayPolicyTableId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTransitGatewayPrefixListReference

#
Service
ec2

Description

Deletes a reference (route) to a prefix list in a specified transit gateway route table.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRouteTableId.Malformed",
  "errorMessage": "Invalid Transit Gateway Route Table id dw-probe.",
  "eventCategory": "Management",
  "eventID": "42ea587b-7147-43e4-bedd-66d2d23611f3",
  "eventName": "DeleteTransitGatewayPrefixListReference",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6f38fd73-2738-464a-8314-de63e2048e1f",
  "requestParameters": {
    "DeleteTransitGatewayPrefixListReferenceRequest": {
      "PrefixListId": "dw-probe",
      "TransitGatewayRouteTableId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTransitGatewayRoute

#
Service
ec2

Description

Deletes the specified route from the specified transit gateway route table.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRouteTableId.Malformed",
  "errorMessage": "Invalid Transit Gateway Route Table id dw-probe.",
  "eventCategory": "Management",
  "eventID": "4aaf110d-9205-428a-ada5-fc8e157bd0ce",
  "eventName": "DeleteTransitGatewayRoute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "512315d0-daf9-4fc3-9d75-adf99b4c3333",
  "requestParameters": {
    "DeleteTransitGatewayRouteRequest": {
      "DestinationCidrBlock": "dw-probe",
      "TransitGatewayRouteTableId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTransitGatewayRouteTable

#
Service
ec2

Description

Deletes the specified transit gateway route table.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRouteTableId.Malformed",
  "errorMessage": "Invalid Transit Gateway Route Table id dw-probe.",
  "eventCategory": "Management",
  "eventID": "2e999e6d-602f-4d14-a10e-41d60475d05d",
  "eventName": "DeleteTransitGatewayRouteTable",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:36Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8985af50-b499-41a3-a42e-be8d8cc2f419",
  "requestParameters": {
    "DeleteTransitGatewayRouteTableRequest": {
      "TransitGatewayRouteTableId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTransitGatewayRouteTableAnnouncement

#
Service
ec2

Description

Advertises to the transit gateway that a transit gateway route table is deleted.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayRouteTableAnnouncementId.Malformed",
  "errorMessage": "The transit-gateway-route-table-announcement ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "de24f261-7719-467a-8703-15782b8f4d4b",
  "eventName": "DeleteTransitGatewayRouteTableAnnouncement",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:36Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f3437b93-9690-4821-a03e-bf497293251b",
  "requestParameters": {
    "DeleteTransitGatewayRouteTableAnnouncementRequest": {
      "TransitGatewayRouteTableAnnouncementId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteTransitGatewayVpcAttachment

#
Service
ec2

Description

Deletes the specified VPC attachment.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayAttachmentID.Malformed",
  "errorMessage": "Invalid Transit Gateway Attachment id.",
  "eventCategory": "Management",
  "eventID": "08658ced-a22e-438e-b569-72089cfa043e",
  "eventName": "DeleteTransitGatewayVpcAttachment",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:36Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "77f3a9b8-5355-485d-9ba9-a577053ecfea",
  "requestParameters": {
    "DeleteTransitGatewayVpcAttachmentRequest": {
      "TransitGatewayAttachmentId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteVerifiedAccessEndpoint

#
Service
ec2

Description

Delete an Amazon Web Services Verified Access endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVerifiedAccessEndpointId.NotFound",
  "errorMessage": "VerifiedAccessEndpoint dw-probe does not exist",
  "eventCategory": "Management",
  "eventID": "c4597cea-39e7-45d6-b079-2f04cff0c189",
  "eventName": "DeleteVerifiedAccessEndpoint",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:36Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e9f11be9-fc05-43e7-9229-4ff9200d1746",
  "requestParameters": {
    "DeleteVerifiedAccessEndpointRequest": {
      "ClientToken": "107104d6-426d-401a-adb5-188304ea70d5",
      "VerifiedAccessEndpointId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteVerifiedAccessGroup

#
Service
ec2

Description

Delete an Amazon Web Services Verified Access group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVerifiedAccessGroupId.NotFound",
  "errorMessage": "VerifiedAccessGroup dw-probe does not exist",
  "eventCategory": "Management",
  "eventID": "a5fd6e52-9d9f-46c1-a04c-d6a6a95fb139",
  "eventName": "DeleteVerifiedAccessGroup",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:37Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "bad9b328-9850-4d3f-ac47-e9f8253be124",
  "requestParameters": {
    "DeleteVerifiedAccessGroupRequest": {
      "ClientToken": "84d9ce7c-6880-43d3-932a-4efad3d0d312",
      "VerifiedAccessGroupId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteVerifiedAccessInstance

#
Service
ec2

Description

Delete an Amazon Web Services Verified Access instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVerifiedAccessInstanceId.NotFound",
  "errorMessage": "VerifiedAccessInstance dw-probe does not exist",
  "eventCategory": "Management",
  "eventID": "9f4f6e07-faaf-47a6-b3de-8611cb24468e",
  "eventName": "DeleteVerifiedAccessInstance",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:37Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "716cfede-d6ea-4539-b94f-6cfe88ecdf61",
  "requestParameters": {
    "DeleteVerifiedAccessInstanceRequest": {
      "ClientToken": "12220941-5065-4220-8106-c526254d51cb",
      "VerifiedAccessInstanceId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteVerifiedAccessTrustProvider

#
Service
ec2

Description

Delete an Amazon Web Services Verified Access trust provider.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVerifiedAccessTrustProviderId.NotFound",
  "errorMessage": "VerifiedAccessTrustProvider dw-probe does not exist",
  "eventCategory": "Management",
  "eventID": "3407bc39-35b0-4cc8-8a73-371a97129dda",
  "eventName": "DeleteVerifiedAccessTrustProvider",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:37Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "969071b9-8c3e-48c6-b5ae-6ac1fa7cb774",
  "requestParameters": {
    "DeleteVerifiedAccessTrustProviderRequest": {
      "ClientToken": "87e193cb-b995-412c-9f9f-5e03fffb75a4",
      "VerifiedAccessTrustProviderId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteVolume

#
Service
ec2

Description

Deletes the specified Amazon EBS volume.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "77a5e160-ad9e-419b-a329-2f8406054631",
  "eventName": "DeleteVolume",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:12:04Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "2d8fd360-079d-4c5f-8aa1-e612af8bece0",
  "requestParameters": {
    "reportVolumeFailure": false,
    "volumeId": "vol-0fc2e34e74650e145"
  },
  "responseElements": {
    "_return": true,
    "requestId": "2d8fd360-079d-4c5f-8aa1-e612af8bece0"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DeleteVpc

#
Service
ec2

Description

Deletes the specified VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "c9c907af-3402-4ce0-a887-53d0f5ba4be3",
  "eventName": "DeleteVpc",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:08:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "115a20b3-6b36-4449-a7f4-93b24f269081",
  "requestParameters": {
    "vpcId": "vpc-0255d384b4b458b46"
  },
  "responseElements": {
    "_return": true,
    "requestId": "115a20b3-6b36-4449-a7f4-93b24f269081"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

DeleteVpcBlockPublicAccessExclusion

#
Service
ec2

Description

Delete a VPC Block Public Access (BPA) exclusion.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.VpcBlockPublicAccessExclusionId.Malformed",
  "errorMessage": "The vpc-block-public-access-exclusion ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "7eb43045-0811-42f2-a648-e52a79a32c49",
  "eventName": "DeleteVpcBlockPublicAccessExclusion",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "beaec851-c31d-419c-8032-f35696933107",
  "requestParameters": {
    "DeleteVpcBlockPublicAccessExclusionRequest": {
      "ExclusionId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteVpcEncryptionControl

#
Service
ec2

Description

Deletes a VPC Encryption Control configuration.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpcEncryptionControlId.Malformed",
  "errorMessage": "The vpc-encryption-control ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "195aad69-893f-4905-9807-56cb7f2d6fb3",
  "eventName": "DeleteVpcEncryptionControl",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9c0dc833-c95f-4d92-84c0-d427899a21a6",
  "requestParameters": {
    "DeleteVpcEncryptionControlRequest": {
      "VpcEncryptionControlId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteVpcEndpointConnectionNotifications

#
Service
ec2

Description

Deletes the specified VPC endpoint connection notifications.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameter",
  "errorMessage": "Invalid Id: 'dw-probe' (expecting 'vpce-nfn-...; the Id may only contain lowercase alphanumeric characters and two dashes')",
  "eventCategory": "Management",
  "eventID": "f2c810ed-a65f-41b1-b9f1-b500fd4d9d96",
  "eventName": "DeleteVpcEndpointConnectionNotifications",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "abc80740-a161-456e-8f83-6d5c29755945",
  "requestParameters": {
    "DeleteVpcEndpointConnectionNotificationsRequest": {
      "ConnectionNotificationId": {
        "content": "dw-probe",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteVpcEndpoints

#
Service
ec2

Description

Deletes one or more specified VPC endpoints.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpcEndpointId.Malformed",
  "errorMessage": "Invalid Id: 'dw-probe' (expecting 'vpce-...; the Id may only contain lowercase alphanumeric characters and a single dash')",
  "eventCategory": "Management",
  "eventID": "18a0debd-07d3-49f7-b034-1a7515f04c4f",
  "eventName": "DeleteVpcEndpoints",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cec0aaa4-7d3f-4c10-b81f-15f74b6590de",
  "requestParameters": {
    "DeleteVpcEndpointsRequest": {
      "VpcEndpointId": {
        "content": "dw-probe",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteVpcEndpointServiceConfigurations

#
Service
ec2

Description

Deletes the specified VPC endpoint service configurations.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpcEndpointServiceId.Malformed",
  "errorMessage": "Invalid Id: 'dw-probe' (expecting 'vpce-svc-...; the Id may only contain lowercase alphanumeric characters and two dashes')",
  "eventCategory": "Management",
  "eventID": "6de5ad97-6f94-41b1-9671-f8b8ac5de97d",
  "eventName": "DeleteVpcEndpointServiceConfigurations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f015b967-75e8-4797-b944-73066a3f1ca8",
  "requestParameters": {
    "DeleteVpcEndpointServiceConfigurationsRequest": {
      "ServiceId": {
        "content": "dw-probe",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteVpcPeeringConnection

#
Service
ec2

Description

Deletes a VPC peering connection.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpcPeeringConnectionId.Malformed",
  "errorMessage": "The vpc-peering-connection ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "c651ce03-5566-4758-8c8a-248b508c68be",
  "eventName": "DeleteVpcPeeringConnection",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:39Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "bd1b9ec6-3daa-405a-bbdd-2dd78c21f4dd",
  "requestParameters": {
    "vpcPeeringConnectionId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteVpnConcentrator

#
Service
ec2

Description

Deletes the specified VPN concentrator.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpnConcentratorID.Malformed",
  "errorMessage": "The vpn-concentrator ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "090c7e6c-ed17-4738-9238-f0694e8f7c5e",
  "eventName": "DeleteVpnConcentrator",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:39Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2e1b56d7-2935-42fc-b991-93ec7cc30549",
  "requestParameters": {
    "DeleteVpnConcentratorRequest": {
      "VpnConcentratorId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteVpnConnection

#
Service
ec2

Description

Deletes the specified VPN connection.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpnConnectionID.NotFound",
  "errorMessage": "The vpnConnection ID 'dw-probe' does not exist",
  "eventCategory": "Management",
  "eventID": "fed21ef8-044a-422e-9d0a-59c9080dbc50",
  "eventName": "DeleteVpnConnection",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:39Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1369ab37-9721-4fc3-a788-4634aeec62d7",
  "requestParameters": {
    "vpnConnectionId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteVpnConnectionRoute

#
Service
ec2

Description

Deletes the specified static route associated with a VPN connection between an existing virtual private gateway and a VPN customer gateway.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpnConnectionID.NotFound",
  "errorMessage": "The vpnConnection ID 'dw-probe' does not exist",
  "eventCategory": "Management",
  "eventID": "fb2c99c1-b058-4fa2-889f-afd9a8c3b1f8",
  "eventName": "DeleteVpnConnectionRoute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:39Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5b67480a-dc77-4c87-85a9-03c37569aaef",
  "requestParameters": {
    "destinationCidrBlock": "dw-probe",
    "vpnConnectionId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteVpnGateway

#
Service
ec2

Description

Deletes the specified virtual private gateway.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpnGatewayID.NotFound",
  "errorMessage": "The vpnGateway ID 'dw-probe' does not exist",
  "eventCategory": "Management",
  "eventID": "511d7419-eea3-4de7-ba91-29a0fe47092e",
  "eventName": "DeleteVpnGateway",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:39Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9449e37a-9507-47f1-aa93-90ea80e74800",
  "requestParameters": {
    "vpnGatewayId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeprovisionByoipCidr

#
Service
ec2

Description

Releases the specified address range that you provisioned for use with your Amazon Web Services resources through bring your own IP addresses (BYOIP) and deletes the corresponding address pool.

DeprovisionIpamByoasn

#
Service
ec2

Description

Deprovisions your Autonomous System Number (ASN) from your Amazon Web Services account.

DeprovisionIpamPoolCidr

#
Service
ec2

Description

Deprovision a CIDR provisioned from an IPAM pool.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "1241faf1-e638-479d-bfe8-04c02cf068d6",
  "eventName": "DeprovisionIpamPoolCidr",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:48:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8b0542a1-420b-48a4-9283-4d5a90b9a9c7",
  "requestParameters": {
    "DeprovisionIpamPoolCidrRequest": {
      "Cidr": "10.99.0.0/16",
      "IpamPoolId": "ipam-pool-0b5795c40ef5b6d99"
    }
  },
  "responseElements": {
    "DeprovisionIpamPoolCidrResponse": {
      "ipamPoolCidr": {
        "cidr": "10.99.0.0/16",
        "ipamPoolCidrId": "ipam-pool-cidr-00a9fa47cce7f4a0a9bdbda8809e6cc1f",
        "netmaskLength": 16,
        "state": "pending-deprovision"
      },
      "requestId": "8b0542a1-420b-48a4-9283-4d5a90b9a9c7",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeprovisionPublicIpv4PoolCidr

#
Service
ec2

Description

Deprovision a CIDR from a public IPv4 pool.

DeregisterImage

#
Service
ec2

Description

Deregisters the specified AMI.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "01789781-6054-4dd1-93a6-e9d36c5bbb69",
  "eventName": "DeregisterImage",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:12:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "eb9db9ef-5e03-4e05-a8a8-59000b7881cb",
  "requestParameters": {
    "imageId": "ami-0aa1d83d0b0985c86"
  },
  "responseElements": {
    "_return": true,
    "requestId": "eb9db9ef-5e03-4e05-a8a8-59000b7881cb"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DeregisterInstanceEventNotificationAttributes

#
Service
ec2

Description

Deregisters tag keys to prevent tags that have the specified tag keys from being included in scheduled event notifications for resources in the Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "The request must include the InstanceTagAttribute parameter. Add the required parameter and retry the request.",
  "eventCategory": "Management",
  "eventID": "8e3ec28d-5187-4251-a435-bb60525d097e",
  "eventName": "DeregisterInstanceEventNotificationAttributes",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:40Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a438e282-7575-4e9a-ad50-3b79dadd382b",
  "requestParameters": {
    "DeregisterInstanceEventNotificationAttributesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DeregisterTransitGatewayMulticastGroupMembers

#
Service
ec2

Description

Deregisters the specified members (network interfaces) from the transit gateway multicast group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "Missing required parameter in request: TransitGatewayMulticastDomainId.",
  "eventCategory": "Management",
  "eventID": "939f08ff-0139-469a-a588-c25405f25073",
  "eventName": "DeregisterTransitGatewayMulticastGroupMembers",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:45:16Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7f2b25c9-0e18-4fc7-bdca-88ff849bc3f6",
  "requestParameters": {
    "DeregisterTransitGatewayMulticastGroupMembersRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeregisterTransitGatewayMulticastGroupSources

#
Service
ec2

Description

Deregisters the specified sources (network interfaces) from the transit gateway multicast group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "Missing required parameter in request: TransitGatewayMulticastDomainId.",
  "eventCategory": "Management",
  "eventID": "819b7bce-d739-490f-b957-ea97559ca265",
  "eventName": "DeregisterTransitGatewayMulticastGroupSources",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:45:16Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "69bd8d33-a7c4-4f20-ac82-9a0aea3b849c",
  "requestParameters": {
    "DeregisterTransitGatewayMulticastGroupSourcesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeAccountAttributes

#
Service
ec2

Description

Describes the specified attribute of your AWS account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "fa6ec09a-d1fc-445c-a77c-c237c87d8339",
  "eventName": "DescribeAccountAttributes",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:58:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "5e3170a8-0e1e-4c01-9637-306863f3f2a7",
  "requestParameters": {
    "accountAttributeNameSet": {},
    "filterSet": {}
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "stratus-red-team_631bdcf7-5789-4c2b-9607-f5637f3270cb",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeAddresses

#
Service
ec2

Description

Describes one or more of your Elastic IP addresses.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "3a8cae4e-43f8-4452-bf1c-860615660cf4",
  "eventName": "DescribeAddresses",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:08Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "bea051d8-3690-4b3c-8cbf-b47b645c04f3",
  "requestParameters": {
    "allocationIdsSet": {
      "items": [
        {
          "allocationId": "eipalloc-08a083beb7e83dbc0"
        }
      ]
    },
    "filterSet": {},
    "publicIpsSet": {}
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeAddressesAttribute

#
Service
ec2

Description

Describes the attributes of the specified Elastic IP addresses.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "9dedbd8b-b72b-4790-9193-ca493a98dcf7",
  "eventName": "DescribeAddressesAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:27:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "02800d8a-5455-4be4-9092-32a3c07813d9",
  "requestParameters": {
    "DescribeAddressesAttributeRequest": {
      "Attribute": "domain-name",
      "MaxResults": 100
    }
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCVDQK5XKV",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeAddressTransfers

#
Service
ec2

Description

Describes an Elastic IP address transfer.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "fd858f23-2611-4ef2-a23f-b06426ac2693",
  "eventName": "DescribeAddressTransfers",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:27:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "7cf0a6bf-6a70-4089-ab68-29c08ce745fc",
  "requestParameters": {
    "DescribeAddressTransfersRequest": {
      "MaxResults": 10
    }
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCVDQK5XKV",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeAggregateIdFormat

#
Service
ec2

Description

Describes the longer ID format settings for all resource types in a specific Region.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "92878b5f-ad59-4a26-a0aa-fd27de054c2e",
  "eventName": "DescribeAggregateIdFormat",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-10-17T20:10:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "2a841885-f382-435c-86f9-e752146e6e8",
  "requestParameters": {
    "DescribeAggregateIdFormatRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeAvailabilityZones

#
Service
ec2

Description

Describes one or more of the Availability Zones that are available to you.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "a55bb769-64c1-4fe8-bd12-102ab1d0d2bb",
  "eventName": "DescribeAvailabilityZones",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "5f8fd9a4-79dc-416a-80c4-8f9efac1bde0",
  "requestParameters": {
    "availabilityZoneIdSet": {},
    "availabilityZoneSet": {},
    "filterSet": {
      "items": [
        {
          "name": "state",
          "valueSet": {
            "items": [
              {
                "value": "available"
              }
            ]
          }
        }
      ]
    }
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeAwsNetworkPerformanceMetricSubscriptions

#
Service
ec2

Description

Describes the current Infrastructure Performance metric subscriptions.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f7257b28-7c20-4f4c-8205-a386d8cf6c73",
  "eventName": "DescribeAwsNetworkPerformanceMetricSubscriptions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "08e84dcc-31a4-4e10-a9a9-8fb73e163fb6",
  "requestParameters": {
    "DescribeAwsNetworkPerformanceMetricSubscriptionsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeBundleTasks

#
Service
ec2

Description

Describes one or more of your bundling tasks.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "f0abd03b-f5e3-4003-8146-3d7c321f5b59",
  "eventName": "DescribeBundleTasks",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-03-01T07:24:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "035337-3fb7-46b2-ba5e-3b39baa59687",
  "requestParameters": {
    "bundlesSet": {}
  },
  "responseElements": null,
  "sourceIPAddress": "6.84.9.35",
  "userAgent": "aws-cli/1.2.9 Python/3.4.3 Linux/4.4.0-53-generic",
  "userIdentity": {
    "accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeByoipCidrs

#
Service
ec2

Description

Describes the IP address ranges that were provisioned for use with Amazon Web Services resources through through bring your own IP addresses (BYOIP).

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.DryRunOperation",
  "errorMessage": "Request would have succeeded, but DryRun flag is set.",
  "eventID": "39a24e38-a31e-43e1-a522-478201fa6",
  "eventName": "DescribeByoipCidrs",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-05-19T17:44:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "db6e8fd3-32cf-41fc-8245-ef205a7d0d4a",
  "requestParameters": {
    "DescribeByoipCidrsRequest": {
      "MaxResults": 1
    }
  },
  "responseElements": null,
  "sourceIPAddress": "255.251.4.254",
  "userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeCapacityBlockExtensionHistory

#
Service
ec2

Description

Describes the events for the specified Capacity Block extension during the specified time.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "0ee1219a-47e4-4f1f-a4cf-fb620e246517",
  "eventName": "DescribeCapacityBlockExtensionHistory",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "b29db676-8344-45f1-853b-ec7d4dd00a9b",
  "requestParameters": {
    "DescribeCapacityBlockExtensionHistoryRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeCapacityBlockExtensionOfferings

#
Service
ec2

Description

Describes Capacity Block extension offerings available for purchase in the Amazon Web Services Region that you're currently using.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidCapacityReservationId.Malformed",
  "errorMessage": "The capacity-reservation ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "9ceb6fbe-5ed0-4786-b3c4-11891cb6bc9a",
  "eventName": "DescribeCapacityBlockExtensionOfferings",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c53dbaa7-7c92-452d-ba84-8a24560974a9",
  "requestParameters": {
    "DescribeCapacityBlockExtensionOfferingsRequest": {
      "CapacityBlockExtensionDurationHours": 1,
      "CapacityReservationId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeCapacityBlockOfferings

#
Service
ec2

Description

Describes Capacity Block offerings available for purchase in the Amazon Web Services Region that you're currently using.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "The request must include the InstanceType parameter. Add the required parameter and retry the request.",
  "eventCategory": "Management",
  "eventID": "99fe1265-8c41-4c39-9315-096867bfb67b",
  "eventName": "DescribeCapacityBlockOfferings",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "61773443-d54d-415f-8d62-4b7dbfc539fc",
  "requestParameters": {
    "DescribeCapacityBlockOfferingsRequest": {
      "CapacityDurationHours": 1
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeCapacityBlocks

#
Service
ec2

Description

Describes details about Capacity Blocks in the Amazon Web Services Region that you're currently using.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.Unsupported",
  "errorMessage": "The operation DescribeCapacityBlocks is not supported.",
  "eventCategory": "Management",
  "eventID": "13cf9949-af6f-4b8d-8cde-23a04f22438b",
  "eventName": "DescribeCapacityBlocks",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "86acd2b2-19ea-4445-a002-a5964ced7271",
  "requestParameters": {
    "DescribeCapacityBlocksRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeCapacityBlockStatus

#
Service
ec2

Description

Describes the availability of capacity for the specified Capacity blocks, or all of your Capacity Blocks.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.Unsupported",
  "errorMessage": "The operation DescribeCapacityBlockStatus is not supported.",
  "eventCategory": "Management",
  "eventID": "ca59511d-f713-4185-80ee-0a33bc020187",
  "eventName": "DescribeCapacityBlockStatus",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "bdfb345f-b450-4e24-9409-31e05bbaabbc",
  "requestParameters": {
    "DescribeCapacityBlockStatusRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeCapacityManagerDataExports

#
Service
ec2

Description

Describes one or more Capacity Manager data export configurations.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "22e09d11-2716-41e0-89b2-9a36487e3ff0",
  "eventName": "DescribeCapacityManagerDataExports",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "53752a75-6fec-446d-8877-981f3ebe7653",
  "requestParameters": {
    "DescribeCapacityManagerDataExportsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeCapacityReservationBillingRequests

#
Service
ec2

Description

Describes a request to assign the billing of the unused capacity of a Capacity Reservation.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f2887cb5-eaa2-4f99-9bef-b724fcf4a21a",
  "eventName": "DescribeCapacityReservationBillingRequests",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "a9e387d5-87f3-4a62-ac55-48013f04438f",
  "requestParameters": {
    "DescribeCapacityReservationBillingRequestsRequest": {
      "Role": "odcr-owner"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeCapacityReservationCancellationQuotes

#
Service
ec2

Description

Describes one or more Capacity Reservation cancellation quotes.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "ef5879b4-4f8e-406c-a078-90b09e141279",
  "eventName": "DescribeCapacityReservationCancellationQuotes",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "588faaa6-992b-4e47-be29-08d881f7ef39",
  "requestParameters": {
    "DescribeCapacityReservationCancellationQuotesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeCapacityReservationFleets

#
Service
ec2

Description

Describes one or more Capacity Reservation Fleets.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "b514a664-f43a-41ab-9431-22d528300397",
  "eventName": "DescribeCapacityReservationFleets",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "406112d9-8a6f-4b23-ad0f-f8f22ac5e1c3",
  "requestParameters": {
    "DescribeCapacityReservationFleetsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeCapacityReservations

#
Service
ec2

Description

Describes one or more of your Capacity Reservations.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "79522-0961-4d43-bd95-4d839d78daf9",
  "eventName": "DescribeCapacityReservations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2019-07-25T09:40:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "953b4d3e-0b8b-423e-81cd-586198dce38f",
  "requestParameters": {
    "DescribeCapacityReservationsRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeCapacityReservationTopology

#
Service
ec2

Description

Describes a tree-based hierarchy that represents the physical host placement of your pending or active Capacity Reservations within an Availability Zone or Local Zone.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "6b904996-7769-41ca-a8e7-408487deb813",
  "eventName": "DescribeCapacityReservationTopology",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "bff2d54b-e722-47e6-a095-13f6e75a3561",
  "requestParameters": {
    "DescribeCapacityReservationTopologyRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeClassicLinkInstances

#
Service
ec2

Description

Describes one or more of your linked EC2-Classic instances.

Example CloudTrail Event #

{
  "awsRegion": "eu-west-1",
  "eventID": "60c87c94-8933-4e86-ae8c-afac72dc31d9",
  "eventName": "DescribeClassicLinkInstances",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-02-28T17:46:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "1c2b760b-654e-4441-89ec-5fa5c09eb810",
  "requestParameters": {
    "filterSet": {},
    "instancesSet": {}
  },
  "responseElements": null,
  "sourceIPAddress": "254.135.184.250",
  "userAgent": "aws-cli/1.11.35 Python/2.7.12 Darwin/16.4.0 botocore/1.4.92",
  "userIdentity": {
    "accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeClientVpnAuthorizationRules

#
Service
ec2

Description

Describes the authorization rules for a specified Client VPN endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.DryRunOperation",
  "errorMessage": "Request would have succeeded, but DryRun flag is set.",
  "eventID": "9dcfea34-b052-4abd-aa8f-296048fa2fb3",
  "eventName": "DescribeClientVpnAuthorizationRules",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-05-19T17:44:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "5422b05e-0074-4e6f-aa8e-165a3630b7d4",
  "requestParameters": {
    "DescribeClientVpnAuthorizationRulesRequest": {
      "ClientVpnEndpointId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "255.251.4.254",
  "userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeClientVpnConnections

#
Service
ec2

Description

Describes active client connections and connections that have been terminated within the last 60 minutes for the specified Client VPN endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.DryRunOperation",
  "errorMessage": "Request would have succeeded, but DryRun flag is set.",
  "eventID": "327892-7b88-44c3-8cfd-f4cfde7ecc98",
  "eventName": "DescribeClientVpnConnections",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-05-19T17:44:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "c486cf9f-955e-44b8-b8ba-e246802bb093",
  "requestParameters": {
    "DescribeClientVpnConnectionsRequest": {
      "ClientVpnEndpointId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "255.251.4.254",
  "userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeClientVpnEndpoints

#
Service
ec2

Description

Describes one or more Client VPN endpoints in the account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "3846ce81-1a49-44f7-869e-55d27d2b44ee",
  "eventName": "DescribeClientVpnEndpoints",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2019-07-25T09:40:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "72af6199-07ae-46ac-b2f9-c2e01543b7e",
  "requestParameters": {
    "DescribeClientVpnEndpointsRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeClientVpnTargetNetworks

#
Service
ec2

Description

Describes the target networks associated with the specified Client VPN endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.DryRunOperation",
  "errorMessage": "Request would have succeeded, but DryRun flag is set.",
  "eventID": "c4ca512e-adb8-4280-af9f-e2ea68aa34c0",
  "eventName": "DescribeClientVpnTargetNetworks",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-05-19T17:44:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "286ed344-df7e-405c-befd-cf54af47a6b4",
  "requestParameters": {
    "DescribeClientVpnTargetNetworksRequest": {
      "ClientVpnEndpointId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "255.251.4.254",
  "userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeCoipPools

#
Service
ec2

Description

Describes the specified customer-owned address pools or all of your customer-owned address pools.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "9553e556-22e0-4eed-bd8d-6fdfa08be86e",
  "eventName": "DescribeCoipPools",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-06-10T05:33:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "a443bdd8-072e-48bb-9ed2-7859fd54baaf",
  "requestParameters": {
    "DescribeCoipPoolsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeConversionTasks

#
Service
ec2

Description

Describes one or more of your conversion tasks.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "4903dd5d-37f9-419f-8b19-74c172425ccf9",
  "eventName": "DescribeConversionTasks",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-03-01T07:24:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "b833f6e1-cf38-4d57-a2f6-01e9b49f0745",
  "requestParameters": {
    "conversionTaskIdSet": {}
  },
  "responseElements": null,
  "sourceIPAddress": "6.84.9.35",
  "userAgent": "aws-cli/1.2.9 Python/3.4.3 Linux/4.4.0-53-generic",
  "userIdentity": {
    "accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeCustomerGateways

#
Service
ec2

Description

Describes one or more of your VPN customer gateways.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "98c26f33-85cf-418f-92b0-cac6110464f8",
  "eventName": "DescribeCustomerGateways",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:13:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "29a87e28-7b61-4d55-82e6-73cb7d16b257",
  "requestParameters": {
    "customerGatewaySet": {},
    "filterSet": {}
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCSUD2OWV6",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:13:16Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeDeclarativePoliciesReports

#
Service
ec2

Description

Describes the metadata of an account status report, including the status of the report.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "9c4a101a-3779-4ad1-9a7f-56ec634a5d2d",
  "eventName": "DescribeDeclarativePoliciesReports",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "a71fa7cc-45cd-4bad-8867-6372902b4737",
  "requestParameters": {
    "DescribeDeclarativePoliciesReportsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeEgressOnlyInternetGateways

#
Service
ec2

Description

Describes your egress-only internet gateways.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "6a69e15e-511f-4845-8b88-bd4b598331ef",
  "eventName": "DescribeEgressOnlyInternetGateways",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:13:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "6818af6a-6d67-4538-82ef-8aa25863c779",
  "requestParameters": {
    "DescribeEgressOnlyInternetGatewaysRequest": {
      "MaxResults": 255
    }
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCSUD2OWV6",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:13:16Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeElasticGpus

#
Service
ec2

Description

Amazon Elastic Graphics reached end of life on January 8, 2024.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "14aee4e1-22c2-4dda-b9a7-b12c268d005e",
  "eventName": "DescribeElasticGpus",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-10-17T20:10:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "3e6410d9-ca0b-416a-88c6-83fa9398b8d8",
  "requestParameters": {
    "DescribeElasticGpusRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeExportImageTasks

#
Service
ec2

Description

Describes the specified export image tasks or all of your export image tasks.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "f598ba0f-3226-4c32-8454-6b69fc210174a",
  "eventName": "DescribeExportImageTasks",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-06-10T05:33:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "5ae57b81-d645-4486-9499-84fd11210",
  "requestParameters": {
    "DescribeExportImageTasksRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeExportTasks

#
Service
ec2

Description

Describes one or more of your export tasks.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "fcb548b7-5afe-4db6-a954-6f59cbf6d488",
  "eventName": "DescribeExportTasks",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-02-27T19:35:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "7d908292-ea81-4a09-bdad-60fb36c7ab9e",
  "requestParameters": {
    "exportTaskIdSet": {}
  },
  "responseElements": null,
  "sourceIPAddress": "5.165.77.250",
  "userAgent": "aws-cli/1.5.2 Python/2.7.8 Linux/4.9.0-1-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeFastLaunchImages

#
Service
ec2

Description

Describe details for Windows AMIs that are configured for Windows fast launch.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "ce6752e1-cd18-4199-8ec1-d7fd84f7f341",
  "eventName": "DescribeFastLaunchImages",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "34a481ac-55ad-443b-b3b7-d87f89e1d119",
  "requestParameters": {
    "DescribeFastLaunchImagesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeFastSnapshotRestores

#
Service
ec2

Description

Describes the state of fast snapshot restores for your snapshots.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "3500dc4f-4bb6-4da5-93fd-023a4ca86d83",
  "eventName": "DescribeFastSnapshotRestores",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-02-21T09:23:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "3a2546f6-f459-44fe-ad64-b7e7888db954",
  "requestParameters": {
    "DescribeFastSnapshotRestoresRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "240.5.57.4",
  "userAgent": "aws-cli/2.0.0 Python/3.8.1 Darwin/19.3.0 botocore/2.0.0dev4",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeFleetHistory

#
Service
ec2

Description

Describes the events for the specified EC2 Fleet during the specified time.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.DryRunOperation",
  "errorMessage": "Request would have succeeded, but DryRun flag is set.",
  "eventID": "06c9d340-32f5-4f5f-b1dd-1f7554e23150",
  "eventName": "DescribeFleetHistory",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-11-10T12:01:36Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "06d588293-0edc-4287-a1d4-a667b3241c5d",
  "requestParameters": {
    "DescribeFleetHistoryRequest": {
      "FleetId": "dummy_data",
      "StartTime": "2015-01-01T00:00:00Z"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "43.254.0.31",
  "userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeFleetInstances

#
Service
ec2

Description

Describes the running instances for the specified EC2 Fleet.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.DryRunOperation",
  "errorMessage": "Request would have succeeded, but DryRun flag is set.",
  "eventID": "b401b390-fbce-44f3-b695-ee05eae8340f",
  "eventName": "DescribeFleetInstances",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-11-10T12:01:36Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "aa8454c3-b1ec-46b5-a0c9-ea1692e694c8",
  "requestParameters": {
    "DescribeFleetInstancesRequest": {
      "FleetId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "43.254.0.31",
  "userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeFleets

#
Service
ec2

Description

Describes the specified EC2 Fleet or all of your EC2 Fleets.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "dd373de5-8f18-4898-a1e6-e75bad8e13a2",
  "eventName": "DescribeFleets",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-08-06T19:50:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "49def88c-348e-448d-b8d5-2bdf68431c9",
  "requestParameters": {
    "DescribeFleetsRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "139.235.254.142",
  "userAgent": "aws-cli/1.15.71 Python/2.7.15 Linux/4.17.10-1-ARCH botocore/1.10.70",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeFlowLogs

#
Service
ec2

Description

Describes one or more flow logs.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "65b25319-3e2c-42ed-9fa3-382717bac4ab",
  "eventName": "DescribeFlowLogs",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:02:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "5cf34e84-b96d-4e60-8f9a-2dc874da3bea",
  "requestParameters": {
    "DescribeFlowLogsRequest": {
      "FlowLogId": {
        "content": "fl-064ed3a785e4a37ef",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_20f9795b-aa02-4c8e-bad6-bd338ec09f59 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeFpgaImageAttribute

#
Service
ec2

Description

Describes the specified attribute of the specified Amazon FPGA Image (AFI).

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.DryRunOperation",
  "errorMessage": "Request would have succeeded, but DryRun flag is set.",
  "eventID": "5245f94c-2237-4056-9f84-e3b7a7fa8274",
  "eventName": "DescribeFpgaImageAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-11-10T12:01:37Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "818326d8b-6e4c-41a0-83f1-03d002a9a6d0",
  "requestParameters": {
    "DescribeFpgaImageAttributeRequest": {
      "Attribute": "dummy_data",
      "FpgaImageId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "43.254.0.31",
  "userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeFpgaImages

#
Service
ec2

Description

Describes the Amazon FPGA Images (AFIs) available to you.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "2453e8fe-36fa-489a-b29d-113bbc1cd696",
  "eventName": "DescribeFpgaImages",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-10-17T20:10:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "1bb167c0-88da-42b6-a9d0-2093deccad61",
  "requestParameters": {
    "DescribeFpgaImagesRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeHostReservationOfferings

#
Service
ec2

Description

Describes the Dedicated Host Reservations that are available to purchase.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "a16177f4-c88e-45eb-bf18-fbea502d1f52",
  "eventName": "DescribeHostReservationOfferings",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-11-10T12:01:37Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "19db836a-b08e-4cf1-b618-9ece516493",
  "requestParameters": {
    "DescribeHostReservationOfferingsRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "43.254.0.31",
  "userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeHostReservations

#
Service
ec2

Description

Describes Dedicated Host Reservations which are associated with Dedicated Hosts in your account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "4183d95a-ee1f-42db-b9f5-f129bfcee95e",
  "eventName": "DescribeHostReservations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-03-11T18:16:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "f11b42df-cf78-4f88-ac33-185dac60cbea",
  "requestParameters": {
    "DescribeHostReservationsRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "34.7.241.251",
  "userAgent": "aws-cli/1.10.67 Python/2.7.10 Darwin/16.4.0 botocore/1.4.93",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeHosts

#
Service
ec2

Description

Describes one or more of your Dedicated hosts.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "267926fc-8510-493d-8c33-91a780c7225e",
  "eventName": "DescribeHosts",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:27:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "ca8ead57-9da9-4b3a-ac03-6931b4be37fd",
  "requestParameters": {
    "DescribeHostsRequest": {
      "MaxResults": 500
    }
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCVDQK5XKV",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeIamInstanceProfileAssociations

#
Service
ec2

Description

Describes your IAM instance profile associations.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "162c4abf-b247-4276-beb5-cb457514b0b6",
  "eventName": "DescribeIamInstanceProfileAssociations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-12-13T23:52:34Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "09d9bd8f-0f41-4a2d-b805-446583db9042",
  "requestParameters": {
    "DescribeIamInstanceProfileAssociationsRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "121.206.185.1",
  "userAgent": "aws-cli/1.11.190 Python/3.6.3 Darwin/16.7.0 botocore/1.7.48",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeIdentityIdFormat

#
Service
ec2

Description

Describes the ID format settings for resources for the specified IAM user, IAM role, or root user.

Example CloudTrail Event #

{
  "awsRegion": "eu-west-1",
  "errorCode": "Client.InvalidTargetArn.Unknown",
  "errorMessage": "Invalid TargetArn: missing parameter",
  "eventID": "9ce28d14-9443-413c-8017-c375e53e0c7b",
  "eventName": "DescribeIdentityIdFormat",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-07-15T12:21:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "88bb488d-5cfc-4dd0-9a7d-a71aa70fa8ff",
  "requestParameters": {
    "DescribeIdentityIdFormatRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "173.114.134.8",
  "userAgent": "AWSPowerShell/74.36.54.6 .NET_Runtime/4.0 .NET_Framework/4.0 OS/Microsoft_Windows_NT_10.0.814599.0 WindowsPowerShell/5.0 ClientSync",
  "userIdentity": {
    "accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeIdFormat

#
Service
ec2

Description

Describes the ID format settings for your resources on a per-region basis, for example, to view which resource types are enabled for longer IDs.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "a972063bf-a9ae-47b8-a270-0fc91fde6ff7",
  "eventName": "DescribeIdFormat",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-02-12T20:45:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "047083a-1fc0-4891-8796-3a6c92a8ac42",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "255.253.125.115",
  "userAgent": "console.ec2.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "ASIAIB6AB67SP5RKU9Z4",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:root",
    "principalId": "811596193553",
    "sessionContext": {
      "attributes": {
        "creationDate": "2017-02-12T19:57:05Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "Root"
  }
}

References #

DescribeImageAttribute

#
Service
ec2

Description

Describes the specified attribute of the specified AMI.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "Client.InvalidAMIID.Malformed",
  "errorMessage": "Invalid id: \"snap-83d15d668fb2941db\" (expecting \"ami-...\")",
  "eventID": "6e4bae95-48b7-47fc-aa36-f23e54469ed",
  "eventName": "DescribeImageAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-05-17T14:29:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "01a1749e-3ac0-41b5-b973-da0c3082f44a",
  "requestParameters": {
    "attributeType": "launchPermission",
    "imageId": "snap-83d15d668fb2941db"
  },
  "responseElements": null,
  "sourceIPAddress": "252.250.127.237",
  "userAgent": "AWSPowerShell/251.194.70.74 .NET_Runtime/4.0 .NET_Framework/4.0 OS/Microsoft_Windows_NT_10.0.17369.0 WindowsPowerShell/5.0 ClientSync",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeImageReferences

#
Service
ec2

Description

Describes your Amazon Web Services resources that are referencing the specified images.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidAMIID.Malformed",
  "errorMessage": "One or more ImageIds isn't valid. Verify that each ImageId is in the correct format and try again.",
  "eventCategory": "Management",
  "eventID": "3d0fb1cc-e628-4b10-be92-5df5a1700bb9",
  "eventName": "DescribeImageReferences",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "1aa78771-5677-4c96-8d97-ff439aeecb75",
  "requestParameters": {
    "DescribeImageReferencesRequest": {
      "ImageId": {
        "content": "dw-probe",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeImageUsageReportEntries

#
Service
ec2

Description

Describes the entries in image usage reports, showing how your images are used across other Amazon Web Services accounts.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "a4f24aaf-fd9b-47a8-8e74-3de4c98322a4",
  "eventName": "DescribeImageUsageReportEntries",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "78c3c02e-fdc1-4d3b-a6b8-20c4036c0f59",
  "requestParameters": {
    "DescribeImageUsageReportEntriesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeImageUsageReports

#
Service
ec2

Description

Describes the configuration and status of image usage reports, filtered by report IDs or image IDs.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "fc0f5802-8115-40d0-b56c-8fb7b61ac6be",
  "eventName": "DescribeImageUsageReports",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "cf8bf414-e162-48f6-80b2-ea1481c23ff1",
  "requestParameters": {
    "DescribeImageUsageReportsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeImportImageTasks

#
Service
ec2

Description

Displays details about an import virtual machine or import snapshot tasks that are already created.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "dfd02eb3-ce0f-415d-911d-11b111f3e0d6",
  "eventName": "DescribeImportImageTasks",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2019-03-31T22:08:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "c7e284806-135d-464f-9b5a-4bcee5db2f6a",
  "requestParameters": {
    "maxResults": 0
  },
  "responseElements": null,
  "sourceIPAddress": "ec2-frontend-api.amazonaws.com",
  "userAgent": "ec2-frontend-api.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "ASIAE8B2KJPFIJXCU8Z8",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "invokedBy": "ec2-frontend-api.amazonaws.com",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "sessionContext": {
      "attributes": {
        "creationDate": "2019-03-31T22:08:55Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeImportSnapshotTasks

#
Service
ec2

Description

Displays details about an import snapshot tasks that is already created.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "6a39a1b4-57e9-417b-8fd2-2b364811f9b",
  "eventName": "DescribeImportSnapshotTasks",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2019-03-31T22:08:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "6c613cb9-12ff-43f7-a5fa-4d7a5d5e4fdc",
  "requestParameters": {
    "maxResults": 0
  },
  "responseElements": null,
  "sourceIPAddress": "ec2-frontend-api.amazonaws.com",
  "userAgent": "ec2-frontend-api.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "ASIAE8B2KJPFIJXCU8Z8",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "invokedBy": "ec2-frontend-api.amazonaws.com",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "sessionContext": {
      "attributes": {
        "creationDate": "2019-03-31T22:08:55Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeInstanceConnectEndpoints

#
Service
ec2

Description

Describes the specified EC2 Instance Connect Endpoints or all EC2 Instance Connect Endpoints.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "95c63342-02af-4f04-9b28-ef11a3c1f777",
  "eventName": "DescribeInstanceConnectEndpoints",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "dea730d2-2e6a-46b7-bfd9-9d9a90653520",
  "requestParameters": {
    "DescribeInstanceConnectEndpointsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeInstanceCreditSpecifications

#
Service
ec2

Description

Describes the credit option for CPU usage of the specified burstable performance instances.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "7af60355-a727-4b2a-bec1-81ff36c9616f",
  "eventName": "DescribeInstanceCreditSpecifications",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "d0fd33cb-ee3e-4fd3-a50f-b49b61ddf92e",
  "requestParameters": {
    "DescribeInstanceCreditSpecificationsRequest": {
      "InstanceId": {
        "content": "i-0dbc91f429e48eeed",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeInstanceEventNotificationAttributes

#
Service
ec2

Description

Describes the tag keys that are registered to appear in scheduled event notifications for resources in the current Region.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "555632f1-9398-49d9-983d-5e8f808c9944",
  "eventName": "DescribeInstanceEventNotificationAttributes",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-06-10T05:33:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "61768a9-f452-43d2-a5c1-6f72afc5cb49",
  "requestParameters": {
    "DescribeInstanceEventNotificationAttributesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeInstanceEventWindows

#
Service
ec2

Description

Describes the specified event windows or all event windows.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "cf83f0b5-72aa-43d9-bfac-bbebea2846f8",
  "eventName": "DescribeInstanceEventWindows",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "041894a3-2e21-4a53-9ee0-6712d6bf557f",
  "requestParameters": {
    "DescribeInstanceEventWindowsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeInstanceImageMetadata

#
Service
ec2

Description

Describes the AMI that was used to launch an instance, even if the AMI is deprecated, deregistered, made private (no longer public or shared with your account), or not allowed.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "c9b7176d-88d2-4f26-8d5c-a3b8343fb494",
  "eventName": "DescribeInstanceImageMetadata",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "df909cb7-1465-4545-a1ab-7cb7d7ded2c5",
  "requestParameters": {
    "DescribeInstanceImageMetadataRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeInstanceSqlHaHistoryStates

#
Service
ec2

Description

Describes the historical SQL Server High Availability states for Amazon EC2 instances that are enabled for Amazon EC2 High Availability for SQL Server monitoring.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "7aec14f3-bcd5-45ba-b074-2a49c636b890",
  "eventName": "DescribeInstanceSqlHaHistoryStates",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "9bb233da-66d3-4c7b-88ae-76564fb3600f",
  "requestParameters": {
    "DescribeInstanceSqlHaHistoryStatesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeInstanceSqlHaStates

#
Service
ec2

Description

Describes the SQL Server High Availability states for Amazon EC2 instances that are enabled for Amazon EC2 High Availability for SQL Server monitoring.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "26fec21d-86d7-4a4f-9e37-074ffef8bb90",
  "eventName": "DescribeInstanceSqlHaStates",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "cd0b83be-6645-4076-8c6d-396f21382ae2",
  "requestParameters": {
    "DescribeInstanceSqlHaStatesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeInstanceStatus

#
Service
ec2

Description

Describes the status of one or more instances, including any scheduled events.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "0cdb9fc4-c1e9-4260-ac1b-ac14e0840711",
  "eventName": "DescribeInstanceStatus",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:27:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "6a06b21b-0fae-4259-8ad8-574db29ac93f",
  "requestParameters": {
    "filterSet": {},
    "includeAllInstances": false,
    "instancesSet": {},
    "maxResults": 1000
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCVDQK5XKV",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeInstanceTopology

#
Service
ec2

Description

Describes a tree-based hierarchy that represents the physical host placement of your EC2 instances within an Availability Zone or Local Zone.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "b9bd82ff-7f71-42c1-a503-2fb156602247",
  "eventName": "DescribeInstanceTopology",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "1d920ce7-ff3c-4cb9-9ec8-0336889b6550",
  "requestParameters": {
    "DescribeInstanceTopologyRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeInstanceTypeOfferings

#
Service
ec2

Description

Lists the instance types that are offered for the specified location.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "4a2c4a02-06b1-4588-b5d2-4fa638fc4ef4",
  "eventName": "DescribeInstanceTypeOfferings",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-06-10T05:33:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "e45b1bb9-bd11-4847-838d-0df164fb4af3",
  "requestParameters": {
    "DescribeInstanceTypeOfferingsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeInstanceTypes

#
Service
ec2

Description

Describes the specified instance types.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "5e17e922-0865-4b9c-9336-ef69d9d9c26a",
  "eventName": "DescribeInstanceTypes",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-07-07T15:53:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "8f3f93fa-9ad3-4642-85c8-9f83a30dc688",
  "requestParameters": {
    "DescribeInstanceTypesRequest": {
      "MaxResults": 100,
      "NextToken": "AAIAATpzTWe8z_qcoCCUkmj1wtgqXR5BJ5Ti94_a3MAjkKF8HZX9iGjRHll2G5_WE29BpU6hdR2D4JhZHlmBis56ItbXiBYBLs-07p4xSwLCXDLVuXRzO6l4FKLWvNBXq5Ovi-1hcpovbmDe7zyQsw6kHL0uoJM_BDUc8u0="
    }
  },
  "responseElements": null,
  "sourceIPAddress": "167.98.108.182",
  "userAgent": "EC2ConsoleFrontend, aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.122-66.218.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI37YFF5PNWP",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/sean",
    "principalId": "AIDA3TLZJI375TCG5FSRI",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:56:28Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "sean"
  }
}

References #

DescribeInternetGateways

#
Service
ec2

Description

Describes one or more of your Internet gateways.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "7b306a05-b01e-4f83-ba04-55f0416c887e",
  "eventName": "DescribeInternetGateways",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:13:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "6587233b-552f-4e60-9cb7-6b4b85617ead",
  "requestParameters": {
    "filterSet": {},
    "internetGatewayIdSet": {},
    "maxResults": 1000
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCSUD2OWV6",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:13:16Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeIpamByoasn

#
Service
ec2

Description

Describes your Autonomous System Numbers (ASNs), their provisioning statuses, and the BYOIP CIDRs with which they are associated.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "79359508-075d-4fb7-baaa-3260a1d7f89a",
  "eventName": "DescribeIpamByoasn",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "b3490651-0cc1-4a91-b251-22e4ade3458a",
  "requestParameters": {
    "DescribeIpamByoasnRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeIpamExternalResourceVerificationTokens

#
Service
ec2

Description

Describe verification tokens.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "e130a008-4ffa-40ea-884c-457ad0b676c4",
  "eventName": "DescribeIpamExternalResourceVerificationTokens",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "8074d889-87d3-4f95-b453-7cf9ce0eb77f",
  "requestParameters": {
    "DescribeIpamExternalResourceVerificationTokensRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeIpamPolicies

#
Service
ec2

Description

Describes one or more IPAM policies.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "830eb3e4-9d87-4707-9250-2c0a7ea528c4",
  "eventName": "DescribeIpamPolicies",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "f279e8fc-a342-4ea8-928d-072c2d0d6748",
  "requestParameters": {
    "DescribeIpamPoliciesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeIpamPoolAllocations

#
Service
ec2

Description

Describes IPAM pool allocations.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "7d65a0d5-4dc6-49e5-bc69-18dad44e4d81",
  "eventName": "DescribeIpamPoolAllocations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "e93f394b-eda2-4803-b271-b3cb9f6b0e36",
  "requestParameters": {
    "DescribeIpamPoolAllocationsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeIpamPools

#
Service
ec2

Description

Get information about your IPAM pools.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "a92e63cf-fc9c-4d20-b026-cf66f7806ef9",
  "eventName": "DescribeIpamPools",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "5f58d047-eea1-40be-a5e1-9daf49a12bba",
  "requestParameters": {
    "DescribeIpamPoolsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeIpamPrefixListResolvers

#
Service
ec2

Description

Describes one or more IPAM prefix list resolvers.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "478e93ff-a10a-46c0-8c13-25bbaa14f5a5",
  "eventName": "DescribeIpamPrefixListResolvers",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "bf3ca8a4-83da-49de-b9ec-1abd686696f9",
  "requestParameters": {
    "DescribeIpamPrefixListResolversRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeIpamPrefixListResolverTargets

#
Service
ec2

Description

Describes one or more IPAM prefix list resolver Targets.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "aa803630-4cf8-499c-9347-b742c1abf141",
  "eventName": "DescribeIpamPrefixListResolverTargets",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "575b3c91-65ed-4979-bbbb-7ac073cd73d4",
  "requestParameters": {
    "DescribeIpamPrefixListResolverTargetsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeIpamResourceDiscoveries

#
Service
ec2

Description

Describes IPAM resource discoveries.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "dcb4a5a3-c730-424e-9c67-0f67b489743b",
  "eventName": "DescribeIpamResourceDiscoveries",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "a8c3dc5a-cae8-4051-b890-870aaf5b948b",
  "requestParameters": {
    "DescribeIpamResourceDiscoveriesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeIpamResourceDiscoveryAssociations

#
Service
ec2

Description

Describes resource discovery association with an Amazon VPC IPAM.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "58020c4b-0810-48f3-abf4-05595ea6470b",
  "eventName": "DescribeIpamResourceDiscoveryAssociations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "7dddd133-fc68-4be1-a35e-f1c39af2a65f",
  "requestParameters": {
    "DescribeIpamResourceDiscoveryAssociationsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeIpams

#
Service
ec2

Description

Get information about your IPAM pools.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "0c0314e4-1297-45b2-b391-2fb456a1dfe9",
  "eventName": "DescribeIpams",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "5b140852-9ee1-4e50-9f3d-22c5c5ebbb1d",
  "requestParameters": {
    "DescribeIpamsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeIpamScopes

#
Service
ec2

Description

Get information about your IPAM scopes.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "7b433525-08fb-458d-8f10-4fd02400731f",
  "eventName": "DescribeIpamScopes",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "eaec0423-9965-4559-b738-11df8f9e118c",
  "requestParameters": {
    "DescribeIpamScopesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeIpv6Pools

#
Service
ec2

Description

Describes your IPv6 address pools.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "2a44f0f2-2e2a-4798-bab4-b67e866030db6",
  "eventName": "DescribeIpv6Pools",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-06-10T05:33:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "14777b7-343f-4b33-8201-c8a5e6e1bb81",
  "requestParameters": {
    "DescribeIpv6PoolsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeKeyPairs

#
Service
ec2

Description

Describes one or more of your key pairs.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "630674b4-e51d-4763-9f4d-9f5de2cb208f",
  "eventName": "DescribeKeyPairs",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:27:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "1f88696d-5c9e-4420-a649-e37b6e067cb9",
  "requestParameters": {
    "filterSet": {},
    "includePublicKey": false,
    "keyPairIdSet": {},
    "keySet": {}
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCVDQK5XKV",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeLaunchTemplates

#
Service
ec2

Description

Describes one or more launch templates.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "1ca249de-b9db-4596-bb50-3e69955cb99b",
  "eventName": "DescribeLaunchTemplates",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:27:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "18f89994-83cd-4cf6-83e0-b4c7dcc73987",
  "requestParameters": {
    "DescribeLaunchTemplatesRequest": {
      "MaxResults": 1
    }
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCVDQK5XKV",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeLaunchTemplateVersions

#
Service
ec2

Description

Describes one or more versions of a specified launch template.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "8deb3cde-6b2f-4313-95dc-f491f3bcff3b",
  "eventName": "DescribeLaunchTemplateVersions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-07-07T13:25:33Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "bc967c75-879a-4c90-a1b2-7c22f973be95",
  "requestParameters": {
    "DescribeLaunchTemplateVersionsRequest": {
      "LaunchTemplateId": "lt-0c29f947cb42c3e34",
      "LaunchTemplateVersion": {
        "content": 1,
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "eks-nodegroup.amazonaws.com",
  "userAgent": "eks-nodegroup.amazonaws.com",
  "userIdentity": {
    "accountId": "797507667711",
    "arn": "arn:aws:sts::797507667711:assumed-role/AWSServiceRoleForAmazonEKSNodegroup/EKS",
    "invokedBy": "eks-nodegroup.amazonaws.com",
    "principalId": "AROA3TLZJI37WARU2V5OV:EKS",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T13:25:33Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "797507667711",
        "arn": "arn:aws:iam::797507667711:role/aws-service-role/eks-nodegroup.amazonaws.com/AWSServiceRoleForAmazonEKSNodegroup",
        "principalId": "AROA3TLZJI37WARU2V5OV",
        "type": "Role",
        "userName": "AWSServiceRoleForAmazonEKSNodegroup"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

References #

DescribeLocalGatewayRouteTables

#
Service
ec2

Description

Describes one or more local gateway route tables.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "a6baa8eb-cce8-4c83-893c-bd13fd47238b",
  "eventName": "DescribeLocalGatewayRouteTables",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-06-10T05:33:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "1f2678f1-0668-49a3-817d-f8ea1aaffe5c",
  "requestParameters": {
    "DescribeLocalGatewayRouteTablesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociations

#
Service
ec2

Description

Describes the associations between virtual interface groups and local gateway route tables.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "1beeaddf-6860-4c14-ba8d-64e531e76131",
  "eventName": "DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-06-10T05:33:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "7812e8f5-dbbf-458d-b4b1-154ab141902e",
  "requestParameters": {
    "DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociationsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeLocalGatewayRouteTableVpcAssociations

#
Service
ec2

Description

Describes the specified associations between VPCs and local gateway route tables.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "33f6314d-8e08-4774-9070-89e605efe229",
  "eventName": "DescribeLocalGatewayRouteTableVpcAssociations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-06-10T05:33:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "433b6c25-441d-4746-9ed0-6bd241ffb295",
  "requestParameters": {
    "DescribeLocalGatewayRouteTableVpcAssociationsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeLocalGateways

#
Service
ec2

Description

Describes one or more local gateways.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "e3b4a7ad-8c8c-4a8a-8152-72f398560d99",
  "eventName": "DescribeLocalGateways",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-06-10T05:33:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "61ac20e5-7907-40a4-8289-284ca9669ab5",
  "requestParameters": {
    "DescribeLocalGatewaysRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeLocalGatewayVirtualInterfaceGroups

#
Service
ec2

Description

Describes the specified local gateway virtual interface groups.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "ca31e918-a341-4c23-b2e1-38d4a321b2e2",
  "eventName": "DescribeLocalGatewayVirtualInterfaceGroups",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-06-10T05:33:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "9761cfd0-3c92-43cb-ac10-c1099d0337d5",
  "requestParameters": {
    "DescribeLocalGatewayVirtualInterfaceGroupsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeLocalGatewayVirtualInterfaces

#
Service
ec2

Description

Describes the specified local gateway virtual interfaces.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "65eacfbb-4907-4f51-a57b-58814c94585f",
  "eventName": "DescribeLocalGatewayVirtualInterfaces",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-06-10T05:33:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "e54468-d2ad-48b7-a11f-f465933706d4",
  "requestParameters": {
    "DescribeLocalGatewayVirtualInterfacesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeLockedSnapshots

#
Service
ec2

Description

Describes the lock status for a snapshot.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "0a09c547-cc37-48cc-97a0-cee9267b6137",
  "eventName": "DescribeLockedSnapshots",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "1947e8cb-907b-4e97-a25e-24a77d32a8bc",
  "requestParameters": {
    "DescribeLockedSnapshotsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeMacHosts

#
Service
ec2

Description

Describes the specified EC2 Mac Dedicated Host or all of your EC2 Mac Dedicated Hosts.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.UnsupportedOperation",
  "errorMessage": "The functionality you requested is not available in this region.",
  "eventCategory": "Management",
  "eventID": "4613947f-af0f-4fb7-b585-890887406e87",
  "eventName": "DescribeMacHosts",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "1fa7ac9f-4615-4ede-afb6-767ed3ace67c",
  "requestParameters": {
    "DescribeMacHostsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeMacModificationTasks

#
Service
ec2

Description

Describes a System Integrity Protection (SIP) modification task or volume ownership delegation task for an Amazon EC2 Mac instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.UnsupportedOperation",
  "errorMessage": "The functionality you requested is not available in this region.",
  "eventCategory": "Management",
  "eventID": "449e73f9-01e9-461b-a135-c524e2a78364",
  "eventName": "DescribeMacModificationTasks",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "ccd9bc9a-7fc4-4a71-bc13-4fd4f50b3c93",
  "requestParameters": {
    "DescribeMacModificationTasksRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeManagedPrefixLists

#
Service
ec2

Description

Describes your managed prefix lists and any Amazon Web Services-managed prefix lists.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "acba087b-740d-40db-9033-3205f831f5c9",
  "eventName": "DescribeManagedPrefixLists",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-07-07T18:47:11Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "b8c893e2-7e4c-4ffd-baa0-36b7774c56f8",
  "requestParameters": {
    "DescribeManagedPrefixListsRequest": {
      "MaxResults": 100
    }
  },
  "responseElements": null,
  "sourceIPAddress": "213.205.197.211",
  "userAgent": "console.ec2.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI376AFGRVSZ",
    "accountId": "797507667711",
    "arn": "arn:aws:iam::797507667711:user/bruce",
    "principalId": "AIDA3TLZJI372XH6M2Q25",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T11:45:11Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bruce"
  }
}

References #

DescribeMovingAddresses

#
Service
ec2

Description

Describes your Elastic IP addresses that are being moved to the EC2-VPC platform, or that are being restored to the EC2-Classic platform.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "689cbcaa-1e21-4cab-b7fb-5151726c747e",
  "eventName": "DescribeMovingAddresses",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-09-11T17:35:40Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "87a2bea9-fabd-4080-bd28-a2f10043c09a",
  "requestParameters": {
    "DescribeMovingAddressesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "60.219.252.71",
  "userAgent": "Boto3/1.14.28 Python/3.8.5 Linux/5.7.0-kali1-amd64 Botocore/1.17.28",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeNatGateways

#
Service
ec2

Description

Describes one or more of the your NAT gateways.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "1b729f93-cc5b-4654-9e51-b48edb9c6f51",
  "eventName": "DescribeNatGateways",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "219910a0-cfb2-4fb8-adc0-c0a3d00d9cf2",
  "requestParameters": {
    "DescribeNatGatewaysRequest": {
      "NatGatewayId": {
        "content": "nat-03575abbac42080d9",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeNetworkAcls

#
Service
ec2

Description

Describes one or more of your network ACLs.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "fecbf813-f665-4af7-b373-8e30480930ee",
  "eventName": "DescribeNetworkAcls",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:14:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "be259a68-d2ee-4bd0-b166-bbdf20108a36",
  "requestParameters": {
    "filterSet": {},
    "maxResults": 1000,
    "networkAclIdSet": {}
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCSUD2OWV6",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:13:16Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeNetworkInsightsAccessScopeAnalyses

#
Service
ec2

Description

Describes the specified Network Access Scope analyses.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "6c2e391f-ca9b-49ed-a2bc-c95e80e57df9",
  "eventName": "DescribeNetworkInsightsAccessScopeAnalyses",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "50705cfc-17ba-4d09-8726-9893e4d87dbd",
  "requestParameters": {
    "DescribeNetworkInsightsAccessScopeAnalysesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeNetworkInsightsAccessScopes

#
Service
ec2

Description

Describes the specified Network Access Scopes.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "cce08680-9486-470e-bccd-e31bf928c69f",
  "eventName": "DescribeNetworkInsightsAccessScopes",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "5c869992-b76a-44ad-83a7-017b3bfab20d",
  "requestParameters": {
    "DescribeNetworkInsightsAccessScopesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeNetworkInsightsAnalyses

#
Service
ec2

Description

Describes one or more of your network insights analyses.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "7922b6a5-d5d5-4b1e-b6dc-fb2d85cfe4f3",
  "eventName": "DescribeNetworkInsightsAnalyses",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "83256056-fa1b-44af-8a93-65a5657c39fd",
  "requestParameters": {
    "DescribeNetworkInsightsAnalysesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeNetworkInsightsPaths

#
Service
ec2

Description

Describes one or more of your paths.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "8ae607e6-321e-4f0d-86d6-c47cc45c9e9f",
  "eventName": "DescribeNetworkInsightsPaths",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "9a98d372-b390-4fc1-a137-d26ba370e9b3",
  "requestParameters": {
    "DescribeNetworkInsightsPathsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeNetworkInterfaceAttribute

#
Service
ec2

Description

Describes a network interface attribute.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "3735a088-29a1-480a-ab4f-c907d6ef3584",
  "eventName": "DescribeNetworkInterfaceAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-06-27T13:27:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "ac9e730c-7908-4571-a6e4-b8c513acc37a",
  "requestParameters": {
    "networkInterfaceId": "eni-f6ffd558"
  },
  "responseElements": null,
  "sourceIPAddress": "127.3.73.208",
  "userAgent": "aws-cli/1.18.46 Python/3.7.7 Linux/5.4.0-kali4-amd64 botocore/1.15.46",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeNetworkInterfacePermissions

#
Service
ec2

Description

Describes the permissions for your network interfaces.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "1420d649-a3d0-4860-a1d2-7aad696f3357",
  "eventName": "DescribeNetworkInterfacePermissions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-12-13T23:56:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "14caf7d1-8a04-4b5f-b18c-3fbddf30bc11",
  "requestParameters": {
    "DescribeNetworkInterfacePermissionsRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "121.206.185.1",
  "userAgent": "aws-cli/1.11.190 Python/3.6.3 Darwin/16.7.0 botocore/1.7.48",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeNetworkInterfaces

#
Service
ec2

Description

Describes one or more of your network interfaces.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "15775da8-b851-45e4-8ad9-a8729eac01ec",
  "eventName": "DescribeNetworkInterfaces",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "3521c52e-583a-4b89-ba44-6dc67a0bb80e",
  "requestParameters": {
    "filterSet": {},
    "networkInterfaceIdSet": {
      "items": [
        {
          "networkInterfaceId": "eni-076fa9fb98a2500a7"
        }
      ]
    }
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeOutpostLags

#
Service
ec2

Description

Describes the Outposts link aggregation groups (LAGs).

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "18dd7526-1d44-4eba-9c65-a069745acf66",
  "eventName": "DescribeOutpostLags",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "8e3c9421-5a2e-495f-9e31-a97e9204ad07",
  "requestParameters": {
    "DescribeOutpostLagsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribePlacementGroups

#
Service
ec2

Description

Describes one or more of your placement groups.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "80038760-4964-464f-9423-22dbfb4edfa6",
  "eventName": "DescribePlacementGroups",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:27:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "d41a70fd-4a0c-474b-a9e9-2b01ee1b005b",
  "requestParameters": {
    "filterSet": {},
    "placementGroupIdSet": {},
    "placementGroupSet": {}
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCVDQK5XKV",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribePrefixLists

#
Service
ec2

Description

Describes available AWS services in a prefix list format, which includes the prefix list name and prefix list ID of the service and the IP address range for the service.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "4b8e2f20-666d-4258-befc-51b2b126e842",
  "eventName": "DescribePrefixLists",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-10-17T20:10:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "124b9b01-fbac-4438-9400-33c968071bd9",
  "requestParameters": {
    "DescribePrefixListsRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribePrincipalIdFormat

#
Service
ec2

Description

Describes the ID format settings for the root user and all IAM roles and IAM users that have explicitly specified a longer ID (17-character ID) preference.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "9aaa2bb0-878f-4f20-ab41-6fa5fde6817b",
  "eventName": "DescribePrincipalIdFormat",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-10-17T20:10:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "eb1f7a70-62a5-4b1f-982d-06361a1960ca",
  "requestParameters": {
    "DescribePrincipalIdFormatRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "9.245.1.85",
  "userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribePublicIpv4Pools

#
Service
ec2

Description

Describes the specified IPv4 address pools.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "e09b4cc2-2456-4a2a-805b-63107e770b70",
  "eventName": "DescribePublicIpv4Pools",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2019-07-25T09:40:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "87fb127d-ce6f-415c-aa4f-af58953ba8f9",
  "requestParameters": {
    "DescribePublicIpv4PoolsRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeReplaceRootVolumeTasks

#
Service
ec2

Description

Describes a root volume replacement task.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f819b1c9-41fd-4b15-904c-98d35eb74c47",
  "eventName": "DescribeReplaceRootVolumeTasks",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "dad4dce4-6c96-46cc-80b1-7c86dffe81e3",
  "requestParameters": {
    "DescribeReplaceRootVolumeTasksRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeReservedInstances

#
Service
ec2

Description

Describes one or more of the Reserved Instances that you purchased.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventID": "833d54df-d375-428f-9c2c-076b2ae2c20e",
  "eventName": "DescribeReservedInstances",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-02-27T23:16:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "e2722f71-4e84-4610-8b5d-2c19d66415e4",
  "requestParameters": {
    "filterSet": {},
    "reservedInstancesSet": {}
  },
  "responseElements": null,
  "sourceIPAddress": "3.239.132.95",
  "userAgent": "aws-cli/1.7.36 Python/2.7.11 Linux/4.4.0-34-generic",
  "userIdentity": {
    "accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeReservedInstancesListings

#
Service
ec2

Description

Describes your account's Reserved Instance listings in the Reserved Instance Marketplace.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "Client.OptInRequired",
  "errorMessage": "AccountId '811596193553', You are not authorized to use the requested product. Please complete the seller registration https://portal.aws.amazon.com/ec2/ri/seller_registration?action=businessInfo.",
  "eventID": "ad74dbcc-1ba2-489f-b635-2fc3cd94c374",
  "eventName": "DescribeReservedInstancesListings",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-03-01T07:30:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "c203cf73-179d-4eaf-9133-fdad25889b4",
  "requestParameters": {
    "filterSet": {},
    "reservedInstancesListingSet": {},
    "reservedInstancesSet": {}
  },
  "responseElements": null,
  "sourceIPAddress": "6.84.9.35",
  "userAgent": "aws-cli/1.2.9 Python/3.4.3 Linux/4.4.0-53-generic",
  "userIdentity": {
    "accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeReservedInstancesModifications

#
Service
ec2

Description

Describes the modifications made to your Reserved Instances.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "f8cefc04-de21-4cca-bc64-05aac20aed8d",
  "eventName": "DescribeReservedInstancesModifications",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-03-01T07:30:33Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "f2532c97-b8e9-49aa-842c-1e792c0b9d6a",
  "requestParameters": {
    "filterSet": {},
    "reservedInstancesModificationSet": {}
  },
  "responseElements": null,
  "sourceIPAddress": "6.84.9.35",
  "userAgent": "aws-cli/1.2.9 Python/3.4.3 Linux/4.4.0-53-generic",
  "userIdentity": {
    "accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeReservedInstancesOfferings

#
Service
ec2

Description

Describes Reserved Instance offerings that are available for purchase.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "1f941e87-d46e-4239-8523-f2c5d256fe09",
  "eventName": "DescribeReservedInstancesOfferings",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-03-01T07:30:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "68de79c7-f45a-45c0-8c9f-4ff191b04928",
  "requestParameters": {
    "nextToken": "IjCP06V0WY8QLSt/Hnn+QQzdGaYMkM+fcKgqVzakS/ic5wjjK7zrQ6ornnyMlWah",
    "reservedInstancesOfferingsSet": {}
  },
  "responseElements": null,
  "sourceIPAddress": "6.84.9.35",
  "userAgent": "aws-cli/1.2.9 Python/3.4.3 Linux/4.4.0-53-generic",
  "userIdentity": {
    "accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeRouteServerEndpoints

#
Service
ec2

Description

Describes one or more route server endpoints.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "a940280e-593c-4234-9cc7-352dd5600661",
  "eventName": "DescribeRouteServerEndpoints",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "94043644-144a-4c30-a0ce-2c6989453c4b",
  "requestParameters": {
    "DescribeRouteServerEndpointsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeRouteServerPeers

#
Service
ec2

Description

Describes one or more route server peers.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "a1f5ba94-4a11-4fe4-b9c5-0a4100833eb4",
  "eventName": "DescribeRouteServerPeers",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "7c488206-f5be-4961-aede-ab8a58db0ab4",
  "requestParameters": {
    "DescribeRouteServerPeersRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeRouteServers

#
Service
ec2

Description

Describes one or more route servers.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "79b6224b-0791-4191-821c-83405d43a0d7",
  "eventName": "DescribeRouteServers",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "914c29f8-3710-41a9-bb2c-40ffd11c5c38",
  "requestParameters": {
    "DescribeRouteServersRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeRouteTables

#
Service
ec2

Description

Describes one or more of your route tables.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "bf0dace9-5898-4ff9-a2f8-b55014751093",
  "eventName": "DescribeRouteTables",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:13:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "a665966b-48eb-45d6-a80b-c948bd347cd6",
  "requestParameters": {
    "filterSet": {},
    "maxResults": 100,
    "routeTableIdSet": {}
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCSUD2OWV6",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:13:16Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeScheduledInstanceAvailability

#
Service
ec2

Description

Finds available schedules that meet the specified criteria.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.DryRunOperation",
  "errorMessage": "Request would have succeeded, but DryRun flag is set.",
  "eventID": "3edcb6fc-07de-42a4-99c3-b27f3b3ff63a",
  "eventName": "DescribeScheduledInstanceAvailability",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-11-10T12:01:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "e886c6ff-fe03-4228-992f-c506f376526e",
  "requestParameters": {
    "DescribeScheduledInstanceAvailabilityRequest": {
      "FirstSlotStartTimeRange": {
        "EarliestTime": "2015-01-01T00:00:00Z",
        "LatestTime": "2015-01-01T00:00:00Z"
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "43.254.0.31",
  "userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeScheduledInstances

#
Service
ec2

Description

Describes one or more of your Scheduled Instances.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "8c590598-b6c1-48fb-90d2-ca04ae3dd1fa",
  "eventName": "DescribeScheduledInstances",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-03-11T18:20:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "df7f285d-5ab2-40b3-8690-5acfeba2c859",
  "requestParameters": {
    "DescribeScheduledInstancesRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "34.7.241.251",
  "userAgent": "aws-cli/1.10.67 Python/2.7.10 Darwin/16.4.0 botocore/1.4.93",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeSecondaryInterfaces

#
Service
ec2

Description

Describes one or more of your secondary interfaces.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidAction",
  "errorMessage": "The action DescribeSecondaryInterfaces is not valid for this web service.",
  "eventCategory": "Management",
  "eventID": "6bfd0c8c-e6e5-490f-931b-e005c61ad14f",
  "eventName": "DescribeSecondaryInterfaces",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "13e2c0bc-f9d0-42cc-bb5a-f5e1a487628e",
  "requestParameters": {
    "DescribeSecondaryInterfacesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeSecondaryNetworks

#
Service
ec2

Description

Describes one or more secondary networks.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.UnsupportedOperation",
  "errorMessage": "The functionality you requested is not supported in this region.",
  "eventCategory": "Management",
  "eventID": "dcba4404-8763-4e97-b172-c76c1a826a81",
  "eventName": "DescribeSecondaryNetworks",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "52172d0c-a733-4759-b8c9-fe93d4c825f7",
  "requestParameters": {
    "DescribeSecondaryNetworksRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeSecondarySubnets

#
Service
ec2

Description

Describes one or more of your secondary subnets.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidAction",
  "errorMessage": "The action DescribeSecondarySubnets is not valid for this web service.",
  "eventCategory": "Management",
  "eventID": "6399c973-6f64-4038-a4ff-34ea07e0ec05",
  "eventName": "DescribeSecondarySubnets",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "3ac0be6f-08d2-421c-99b2-b405bdb37bf5",
  "requestParameters": {
    "DescribeSecondarySubnetsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeSecurityGroupReferences

#
Service
ec2

Description

[EC2-VPC only] Describes the VPCs on the other side of a VPC peering connection that are referencing the security groups you've specified in this request.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.DryRunOperation",
  "errorMessage": "Request would have succeeded, but DryRun flag is set.",
  "eventID": "a5aa3d88-ef8d-4f6e-87f0-4ec8cf839bc3",
  "eventName": "DescribeSecurityGroupReferences",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-11-10T12:01:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "ced04b70-8a90-439e-8462-b93a49005d",
  "requestParameters": {
    "DescribeSecurityGroupReferencesRequest": {
      "GroupId": {
        "content": "test",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "43.254.0.31",
  "userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

DescribeSecurityGroupRules

#
Service
ec2

Description

Describes one or more of your security group rules.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "3d97c37f-4f59-41a3-a689-968685ec41d9",
  "eventName": "DescribeSecurityGroupRules",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "e54bc96c-6d91-4d9e-b743-2c4470ed01b7",
  "requestParameters": {
    "DescribeSecurityGroupRulesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DescribeSecurityGroupVpcAssociations

#
Service
ec2

Description

Describes security group VPC associations made with AssociateSecurityGroupVpc.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "dda1ac61-ea4d-45d7-8907-339be0f1746a",
  "eventName": "DescribeSecurityGroupVpcAssociations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "611274df-555f-4c31-b64b-59af41044eea",
  "requestParameters": {
    "DescribeSecurityGroupVpcAssociationsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeServiceLinkVirtualInterfaces

#
Service
ec2

Description

Describes the Outpost service link virtual interfaces.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "706e0fe7-f554-43bb-bcce-affffa9fa249",
  "eventName": "DescribeServiceLinkVirtualInterfaces",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "b3452fb6-981a-4ce0-bd96-8f280ceefc9f",
  "requestParameters": {
    "DescribeServiceLinkVirtualInterfacesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeSnapshots

#
Service
ec2

Description

Describes one or more of the Amazon EBS snapshots available to you.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "dfccbba6-f976-4731-a29c-bae01d706ced",
  "eventName": "DescribeSnapshots",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:27:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "9df6a97a-6bf0-40ed-8427-925702f08b0d",
  "requestParameters": {
    "filterSet": {},
    "maxResults": 1000,
    "ownersSet": {
      "items": [
        {
          "owner": "123837392027"
        }
      ]
    },
    "sharedUsersSet": {},
    "snapshotSet": {}
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCVDQK5XKV",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeSpotDatafeedSubscription

#
Service
ec2

Description

Describes the datafeed for Spot Instances.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "Client.InvalidSpotDatafeed.NotFound",
  "errorMessage": "Spot datafeed subscription does not exist.",
  "eventID": "8d7dafc7-d1b5-469b-898d-cc0571a421a6",
  "eventName": "DescribeSpotDatafeedSubscription",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-03-01T07:31:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "48075eb-82bc-4c71-b4cf-8f2386dbadf7",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "6.84.9.35",
  "userAgent": "aws-cli/1.2.9 Python/3.4.3 Linux/4.4.0-53-generic",
  "userIdentity": {
    "accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeSpotFleetInstances

#
Service
ec2

Description

Describes the running instances for the specified Spot fleet.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.DryRunOperation",
  "errorMessage": "Request would have succeeded, but DryRun flag is set.",
  "eventID": "cf1670cb-256f-44be-8d75-eb885ad46067",
  "eventName": "DescribeSpotFleetInstances",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-11-10T12:01:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "7d2d652b-d6ba-4a98-ad12-a4944c53be6d",
  "requestParameters": {
    "DescribeSpotFleetInstancesRequest": {
      "SpotFleetRequestId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "43.254.0.31",
  "userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeSpotFleetRequestHistory

#
Service
ec2

Description

Describes the events for the specified Spot fleet request during the specified time.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.DryRunOperation",
  "errorMessage": "Request would have succeeded, but DryRun flag is set.",
  "eventID": "ad726e81-bde1-44aa-9dd3-68d563142b7e4",
  "eventName": "DescribeSpotFleetRequestHistory",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-11-10T12:01:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "6ebd2862-cd18-4cd6-9185-2f995330cc67",
  "requestParameters": {
    "DescribeSpotFleetRequestHistoryRequest": {
      "SpotFleetRequestId": "dummy_data",
      "StartTime": "2015-01-01T00:00:00Z"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "43.254.0.31",
  "userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeSpotFleetRequests

#
Service
ec2

Description

Describes your Spot fleet requests.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "6bb9baae-bc9f-4062-8e63-2f1c7c112ff6",
  "eventName": "DescribeSpotFleetRequests",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-03-11T18:20:36Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "c95544-3971-4c2b-b96d-4c2f1ef602e4",
  "requestParameters": {
    "DescribeSpotFleetRequestsRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "34.7.241.251",
  "userAgent": "aws-cli/1.10.67 Python/2.7.10 Darwin/16.4.0 botocore/1.4.93",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeSpotInstanceRequests

#
Service
ec2

Description

Describes the Spot Instance requests that belong to your account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "c4a2d388-0301-41f6-b3f1-2407dc4de14f",
  "eventName": "DescribeSpotInstanceRequests",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-02-27T23:16:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "83e073d4-e4d1-4c56-9dcc-b5ebed718c83",
  "requestParameters": {
    "filterSet": {},
    "spotInstanceRequestIdSet": {}
  },
  "responseElements": null,
  "sourceIPAddress": "3.239.132.95",
  "userAgent": "aws-cli/1.7.36 Python/2.7.11 Linux/4.4.0-34-generic",
  "userIdentity": {
    "accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeSpotPriceHistory

#
Service
ec2

Description

Describes the Spot Price history.

Example CloudTrail Event #

{
  "awsRegion": "ap-south-1",
  "eventID": "9c09edb7-8bfb-41dd-9dc1-40385ec60da7",
  "eventName": "DescribeSpotPriceHistory",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-03-04T17:18:39Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "207a103f-f5f2-46d3-adf6-437b80469",
  "requestParameters": {
    "endTime": 1489904317865,
    "instanceTypeSet": {
      "items": [
        {
          "instanceType": "g2.8xlarge"
        }
      ]
    },
    "productDescriptionSet": {},
    "startTime": 1488647917865
  },
  "responseElements": null,
  "sourceIPAddress": "5.165.77.250",
  "userAgent": "Boto3/1.4.2 Python/2.7.13 Linux/4.9.0-1-amd64 Botocore/1.5.19",
  "userIdentity": {
    "accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeStaleSecurityGroups

#
Service
ec2

Description

[EC2-VPC only] Describes the stale security group rules for security groups in a specified VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.DryRunOperation",
  "errorMessage": "Request would have succeeded, but DryRun flag is set.",
  "eventID": "c6a2bbb6-2866-49a1-a316-9c9717fbddf1",
  "eventName": "DescribeStaleSecurityGroups",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-11-10T12:01:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "5cf3008c-1e7b-45bc-84af-cb5cba404d3c",
  "requestParameters": {
    "DescribeStaleSecurityGroupsRequest": {
      "VpcId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "43.254.0.31",
  "userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeStoreImageTasks

#
Service
ec2

Description

Describes the progress of the AMI store tasks.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "4d42f521-da83-46a2-ad70-c80ddeacc518",
  "eventName": "DescribeStoreImageTasks",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "3f858caa-b998-4fc5-b129-158f4937e9a4",
  "requestParameters": {
    "DescribeStoreImageTasksRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeSubnets

#
Service
ec2

Description

Describes one or more of your subnets.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "74284e7a-7abf-43dc-b1d1-a0d8633ba00c",
  "eventName": "DescribeSubnets",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:13:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "10766182-9558-4144-a9be-9e43a28920b8",
  "requestParameters": {
    "filterSet": {},
    "maxResults": 1000,
    "subnetSet": {}
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCSUD2OWV6",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:13:16Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

DescribeTags

#
Service
ec2

Description

Describes one or more of the tags for your EC2 resources.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "7fa60441-c5fc-4f5d-b7fb-1d1d26606de6",
  "eventName": "DescribeTags",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:27:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "58e24e74-57a3-4be0-85d7-f18c1fb208ff",
  "requestParameters": {
    "filterSet": {
      "items": [
        {
          "name": "resource-type",
          "valueSet": {
            "items": [
              {
                "value": "elastic-ip"
              }
            ]
          }
        }
      ]
    },
    "maxResults": 500
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCVDQK5XKV",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeTrafficMirrorFilterRules

#
Service
ec2

Description

Describe traffic mirror filters that determine the traffic that is mirrored.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "4a8a0993-02ce-469f-821e-1ca8260b250a",
  "eventName": "DescribeTrafficMirrorFilterRules",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "a58acd13-c60a-421e-b91d-e7ccba9f0ba8",
  "requestParameters": {
    "DescribeTrafficMirrorFilterRulesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeTrafficMirrorFilters

#
Service
ec2

Description

Describes one or more Traffic Mirror filters.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "42328f8-2029-4681-8202-33c1e743044aa",
  "eventName": "DescribeTrafficMirrorFilters",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-06-10T05:33:39Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "a77829e5-badf-4cf6-a520-8a6e0d9f0bd5",
  "requestParameters": {
    "DescribeTrafficMirrorFiltersRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeTrafficMirrorSessions

#
Service
ec2

Description

Describes one or more Traffic Mirror sessions.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "9ba4e09f-faf1-4b38-ad2d-e0fd048b6ba4",
  "eventName": "DescribeTrafficMirrorSessions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-06-10T05:33:39Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "a09ad992-b307-4c54-b307-ffb503d1737c",
  "requestParameters": {
    "DescribeTrafficMirrorSessionsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeTrafficMirrorTargets

#
Service
ec2

Description

Information about one or more Traffic Mirror targets.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "93fd3651-219a-4c92-b80f-a29341ecb450",
  "eventName": "DescribeTrafficMirrorTargets",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-06-10T05:33:39Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "3de33695-7068-4daa-be3e-279a60dc2379",
  "requestParameters": {
    "DescribeTrafficMirrorTargetsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeTransitGatewayAttachments

#
Service
ec2

Description

Describes one or more attachments between resources and transit gateways.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "cf917116-bed7-4ffc-bf38-c36a7102f54e",
  "eventName": "DescribeTransitGatewayAttachments",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2019-07-25T09:40:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "feda68a8-d617-4932-9b57-7e1158f80d08",
  "requestParameters": {
    "DescribeTransitGatewayAttachmentsRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeTransitGatewayConnectPeers

#
Service
ec2

Description

Describes one or more Connect peers.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "5cc38a7b-7a7e-4bbc-a3de-4b7a8cd4beb1",
  "eventName": "DescribeTransitGatewayConnectPeers",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "ef91d15e-f311-4794-91ae-ebe9dfc5c90d",
  "requestParameters": {
    "DescribeTransitGatewayConnectPeersRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeTransitGatewayConnects

#
Service
ec2

Description

Describes one or more Connect attachments.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "5894ec98-d98a-4c8c-90c3-3b4f3546ec1d",
  "eventName": "DescribeTransitGatewayConnects",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "125b066d-5aa4-411a-955d-fcd9f48cefc0",
  "requestParameters": {
    "DescribeTransitGatewayConnectsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeTransitGatewayMeteringPolicies

#
Service
ec2

Description

Describes one or more transit gateway metering policies.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "ee76950b-82c9-4313-9fcf-0bc02bcf756a",
  "eventName": "DescribeTransitGatewayMeteringPolicies",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "a76477fc-222f-44bb-907d-d089fb1c8c08",
  "requestParameters": {
    "DescribeTransitGatewayMeteringPoliciesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeTransitGatewayPeeringAttachments

#
Service
ec2

Description

Describes your transit gateway peering attachments.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "50ab3be2-33ce-4bd5-85ea-79f375766cca",
  "eventName": "DescribeTransitGatewayPeeringAttachments",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-06-10T05:33:39Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "436993f-0376-4257-95a8-d9b0baf4e6b5",
  "requestParameters": {
    "DescribeTransitGatewayPeeringAttachmentsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "251.105.254.1",
  "userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeTransitGatewayPolicyTables

#
Service
ec2

Description

Describes one or more transit gateway route policy tables.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "c9838453-845f-49ec-9578-4dd739c4fffb",
  "eventName": "DescribeTransitGatewayPolicyTables",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "87599c49-9fa5-48f7-bf65-06b858940b8c",
  "requestParameters": {
    "DescribeTransitGatewayPolicyTablesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeTransitGatewayRouteTableAnnouncements

#
Service
ec2

Description

Describes one or more transit gateway route table advertisements.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "4b49efab-0654-4c1d-97bf-ceb36fae253d",
  "eventName": "DescribeTransitGatewayRouteTableAnnouncements",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "2a0f1ec9-b5a6-4df1-8319-4747a589f52b",
  "requestParameters": {
    "DescribeTransitGatewayRouteTableAnnouncementsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeTransitGatewayRouteTables

#
Service
ec2

Description

Describes one or more transit gateway route tables.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "c3ecd4b2-ab6b-4bb9-bbfc-11bde9c51492",
  "eventName": "DescribeTransitGatewayRouteTables",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2019-07-25T09:40:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "861f1341-9c9a-4e8e-8428-d168a3129dda",
  "requestParameters": {
    "DescribeTransitGatewayRouteTablesRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeTransitGateways

#
Service
ec2

Description

Describes one or more transit gateways.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "9b9b5bfa-7240-4300-ab85-52f65e004558",
  "eventName": "DescribeTransitGateways",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2019-07-25T09:40:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "1c3c773e-1993-4ff0-9a23-9757bdf0f106",
  "requestParameters": {
    "DescribeTransitGatewaysRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeTransitGatewayVpcAttachments

#
Service
ec2

Description

Describes one or more VPC attachments.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "fb6136e6-0f08-44dd-8556-e353e114847e0",
  "eventName": "DescribeTransitGatewayVpcAttachments",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2019-07-25T09:40:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "dad960f8-e300-444c-86bb-82b92f5c9162",
  "requestParameters": {
    "DescribeTransitGatewayVpcAttachmentsRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "248.251.245.4",
  "userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeTrunkInterfaceAssociations

#
Service
ec2

Description

Describes one or more network interface trunk associations.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.OperationNotPermitted",
  "errorMessage": "User 123456789012 is not permitted to perform this operation",
  "eventCategory": "Management",
  "eventID": "1d50d5e9-2ea6-4d8e-b908-e74029bb3656",
  "eventName": "DescribeTrunkInterfaceAssociations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "bcddf5b1-6f91-45d3-a88e-c81494b62be5",
  "requestParameters": {
    "DescribeTrunkInterfaceAssociationsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeVerifiedAccessEndpoints

#
Service
ec2

Description

Describes the specified Amazon Web Services Verified Access endpoints.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "a1ded684-ccce-435c-94ea-c0f2511700b4",
  "eventName": "DescribeVerifiedAccessEndpoints",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "442d4b76-4ef4-43d2-9878-652649c3d0bd",
  "requestParameters": {
    "DescribeVerifiedAccessEndpointsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeVerifiedAccessGroups

#
Service
ec2

Description

Describes the specified Verified Access groups.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "1f54ad6f-9eb4-4094-89aa-3cc78f5b0b7d",
  "eventName": "DescribeVerifiedAccessGroups",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "d856fec2-f246-4101-a50d-dca66898d8bd",
  "requestParameters": {
    "DescribeVerifiedAccessGroupsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeVerifiedAccessInstanceLoggingConfigurations

#
Service
ec2

Description

Describes the specified Amazon Web Services Verified Access instances.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "736c4f3a-8b31-4951-b1ba-cf0fcbe398a5",
  "eventName": "DescribeVerifiedAccessInstanceLoggingConfigurations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "3c6f620d-ea25-483a-b667-ae24fdcef9ee",
  "requestParameters": {
    "DescribeVerifiedAccessInstanceLoggingConfigurationsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeVerifiedAccessInstances

#
Service
ec2

Description

Describes the specified Amazon Web Services Verified Access instances.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "21cbec31-9bb8-4537-b5b9-a666d8e6922d",
  "eventName": "DescribeVerifiedAccessInstances",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "4aedb801-7e6a-4766-815e-06b058ddc95f",
  "requestParameters": {
    "DescribeVerifiedAccessInstancesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeVerifiedAccessTrustProviders

#
Service
ec2

Description

Describes the specified Amazon Web Services Verified Access trust providers.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "35e7855a-9ca6-41a2-a7ae-4fade59286b4",
  "eventName": "DescribeVerifiedAccessTrustProviders",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "9972d591-ca81-44ed-9f44-c709c406b3f6",
  "requestParameters": {
    "DescribeVerifiedAccessTrustProvidersRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeVolumeAttribute

#
Service
ec2

Description

Describes the specified attribute of the specified volume.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "eventID": "9c3dcdf0-edb2-4f24-9d04-3652af634102",
  "eventName": "DescribeVolumeAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2017-02-12T22:59:33Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "149ba3d3-342d-4561-a5ac-92ea33ba017b",
  "requestParameters": {
    "volumeId": "vol-8e100f305b7a6fef3"
  },
  "responseElements": null,
  "sourceIPAddress": "255.253.125.115",
  "userAgent": "console.ec2.amazonaws.com",
  "userIdentity": {
    "accessKeyId": "ASIAIB6AB67SP5RKU9Z4",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:root",
    "principalId": "811596193553",
    "sessionContext": {
      "attributes": {
        "creationDate": "2017-02-12T19:57:05Z",
        "mfaAuthenticated": "false"
      }
    },
    "type": "Root"
  }
}

References #

DescribeVolumeStatus

#
Service
ec2

Description

Describes the status of the specified volumes.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "8242ec66-3f5d-4032-be35-6cdbc6fc58d7",
  "eventName": "DescribeVolumeStatus",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:27:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "79b5840a-5a54-45ed-912e-c4eea46c2a67",
  "requestParameters": {
    "filterSet": {},
    "maxResults": 1000,
    "volumeSet": {}
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCVDQK5XKV",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeVpcAttribute

#
Service
ec2

Description

Describes the specified attribute of the specified VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "f7731d05-e80f-424b-8f67-732cbb8ea29f",
  "eventName": "DescribeVpcAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "76fb511b-ee07-4b05-8a5e-93c4274912bc",
  "requestParameters": {
    "vpcId": "vpc-06fe1a64761a0f720"
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeVpcBlockPublicAccessExclusions

#
Service
ec2

Description

Describe VPC Block Public Access (BPA) exclusions.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "One of the following parameters must be provided: ExclusionIds, MaxResults",
  "eventCategory": "Management",
  "eventID": "ccb6346e-6268-4d12-983b-2b2176d69b21",
  "eventName": "DescribeVpcBlockPublicAccessExclusions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "763b28d1-45b9-4cfe-a6a4-92dc154396b1",
  "requestParameters": {
    "DescribeVpcBlockPublicAccessExclusionsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeVpcBlockPublicAccessOptions

#
Service
ec2

Description

Describe VPC Block Public Access (BPA) options.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "7b391d58-7c1b-4147-b07b-c5a911e6e0ef",
  "eventName": "DescribeVpcBlockPublicAccessOptions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "58a1ddf9-b093-44c6-969c-31bfbb351f23",
  "requestParameters": {
    "DescribeVpcBlockPublicAccessOptionsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeVpcClassicLink

#
Service
ec2

DescribeVpcClassicLinkDnsSupport

#
Service
ec2

Description

Describes the ClassicLink DNS support status of one or more VPCs.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "7445d04f-062d-4248-b930-1c5f53644f4d",
  "eventName": "DescribeVpcClassicLinkDnsSupport",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "2cff7748-7483-4a82-a170-4ea18db16d00",
  "requestParameters": {
    "DescribeVpcClassicLinkDnsSupportRequest": {
      "VpcIds": {
        "content": "vpc-06fe1a64761a0f720",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeVpcEncryptionControls

#
Service
ec2

Description

Describes one or more VPC Encryption Control configurations.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "b86638fb-f92c-453e-96f0-32c3b58b317a",
  "eventName": "DescribeVpcEncryptionControls",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c4a0cf20-5c43-47b2-9e50-d20c4fee1d3e",
  "requestParameters": {
    "DescribeVpcEncryptionControlsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeVpcEndpointAssociations

#
Service
ec2

Description

Describes the VPC resources, VPC endpoint services, Amazon Lattice services, or service networks associated with the VPC endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "8c585b3c-0bf3-45d5-b95a-e8dd9aa3b9be",
  "eventName": "DescribeVpcEndpointAssociations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "3eb9039b-d35b-43f3-b31f-81bf1ab06403",
  "requestParameters": {
    "DescribeVpcEndpointAssociationsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeVpcEndpointConnections

#
Service
ec2

Description

Describes the VPC endpoint connections to your VPC endpoint services, including any endpoints that are pending your acceptance.

Example CloudTrail Event #

{
  "awsRegion": "ap-south-1",
  "eventID": "a8138a81-4cd0-4a4c-b95d-31f557bed7e5",
  "eventName": "DescribeVpcEndpointConnections",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-08-05T17:07:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "ae2c2413-3172-45c5-8777-40ce18cb5b28",
  "requestParameters": {
    "DescribeVpcEndpointConnectionsRequest": {}
  },
  "responseElements": null,
  "sourceIPAddress": "250.251.253.3",
  "userAgent": "Boto3/1.5.32 Python/3.6.4 Darwin/17.6.0 Botocore/1.8.50",
  "userIdentity": {
    "accessKeyId": "ASIAPYBUDZE3ZQU169GB",
    "accountId": "811596193553",
    "arn": "arn:aws:sts::811596193553:assumed-role/SummitRouteAudit/4032461535040776536",
    "principalId": "AROAMY611GPC0EPB1P0F9:4032461535040776536",
    "sessionContext": {
      "attributes": {
        "creationDate": "2018-08-05T17:00:49Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {
        "accountId": "811596193553",
        "arn": "arn:aws:iam::811596193553:role/SummitRouteAudit",
        "principalId": "AROAMY611GPC0EPB1P0F9",
        "type": "Role",
        "userName": "SummitRouteAudit"
      }
    },
    "type": "AssumedRole"
  }
}

References #

DescribeVpcEndpoints

#
Service
ec2

Description

Describes one or more of your VPC endpoints.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "05a18e4f-a57c-4ff4-bdf2-e457af1d335d",
  "eventName": "DescribeVpcEndpoints",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:13:32Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "eb6c6d0a-3cd1-444e-9d3a-09c5cd98b22b",
  "requestParameters": {
    "DescribeVpcEndpointsRequest": {
      "Filter": {
        "Name": "vpc-id",
        "Value": {
          "content": "vpc-098ff30ff74b36f73",
          "tag": 1
        },
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCSUD2OWV6",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:13:16Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeVpcEndpointServiceConfigurations

#
Service
ec2

Description

Describes the VPC endpoint service configurations in your account (your services).

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "628238ec-ac92-4875-a158-15c667144d81",
  "eventName": "DescribeVpcEndpointServiceConfigurations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:13:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "b246466b-52e5-4ffe-bb9e-04b42885a79a",
  "requestParameters": {
    "DescribeVpcEndpointServiceConfigurationsRequest": {
      "MaxResults": 1000
    }
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCSUD2OWV6",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:13:16Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeVpcEndpointServicePermissions

#
Service
ec2

Description

Describes the principals (service consumers) that are permitted to discover your VPC endpoint service.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.DryRunOperation",
  "errorMessage": "Request would have succeeded, but DryRun flag is set.",
  "eventID": "10d1ab88-079e-4fbb-9767-c24662cc6008",
  "eventName": "DescribeVpcEndpointServicePermissions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-11-10T12:01:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "c0d80764-7fe3-4dcb-93ba-4c94d5ad1ca7",
  "requestParameters": {
    "DescribeVpcEndpointServicePermissionsRequest": {
      "ServiceId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "43.254.0.31",
  "userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeVpcEndpointServices

#
Service
ec2

Description

Describes all supported AWS services that can be specified when creating a VPC endpoint.

Example CloudTrail Event #

{
  "awsRegion": "ap-south-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventCategory": "Management",
  "eventID": "1f2d8d59-9e54-4890-9c25-3660ef877c28",
  "eventName": "DescribeVpcEndpointServices",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-04-13T11:35:22Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "111111111111",
  "requestID": "97ba7cdd-b188-4ec7-af8b-ee78bb52fe8a",
  "requestParameters": {
    "DescribeVpcEndpointServicesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "95.90.195.80",
  "userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
    "accountId": "111111111111",
    "arn": "arn:aws:iam::111111111111:user/cloudsploit",
    "principalId": "AIDAYTOGP2RLMDEPWZWMJ",
    "type": "IAMUser",
    "userName": "cloudsploit"
  }
}

References #

DescribeVpcPeeringConnections

#
Service
ec2

Description

Describes one or more of your VPC peering connections.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "7308ba6e-285a-4a91-82e3-dd7287bb2fe6",
  "eventName": "DescribeVpcPeeringConnections",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:13:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "7a599722-580d-4522-8783-1f80d98bec63",
  "requestParameters": {
    "filterSet": {},
    "maxResults": 1000,
    "vpcPeeringConnectionIdSet": {}
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCSUD2OWV6",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:13:16Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeVpnConcentrators

#
Service
ec2

Description

Describes one or more of your VPN concentrators.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "ea50ee7e-50c1-427f-b560-305fdd605949",
  "eventName": "DescribeVpnConcentrators",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "86ad15ec-75ec-4fe9-9bca-ab0392d43988",
  "requestParameters": {
    "DescribeVpnConcentratorsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeVpnConnections

#
Service
ec2

Description

Describes one or more of your VPN connections.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "27c3dc94-3ee3-492a-b5f8-980cd779071c",
  "eventName": "DescribeVpnConnections",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:13:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "16105444-3ba0-49c1-96c3-af8ea024a56d",
  "requestParameters": {
    "filterSet": {},
    "vpnConnectionSet": {}
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCSUD2OWV6",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:13:16Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DescribeVpnGateways

#
Service
ec2

Description

Describes one or more of your virtual private gateways.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "0f1005c9-210f-407e-86de-a5006d4782f4",
  "eventName": "DescribeVpnGateways",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:13:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "85709788-8d91-428e-82f6-8f5c39524563",
  "requestParameters": {
    "filterSet": {},
    "vpnGatewaySet": {}
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCSUD2OWV6",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:13:16Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DetachClassicLinkVpc

#
Service
ec2

Description

Unlinks (detaches) a linked EC2-Classic instance from a VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidInstanceID.Malformed",
  "errorMessage": "The instance ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "27a9b25d-dbd2-43c4-88ea-f5bb1faa5e3f",
  "eventName": "DetachClassicLinkVpc",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:40Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f92e2b41-cdb4-4f02-a657-dfb22815e6ac",
  "requestParameters": {
    "instanceId": "dw-probe",
    "vpcId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DetachImageWatermark

#
Service
ec2

Description

Removes a watermark from the specified AMI.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidAMIID.Malformed",
  "errorMessage": "The image ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "5f8db8e8-eca7-4a7e-8a62-599048ac3964",
  "eventName": "DetachImageWatermark",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:40Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0cb00722-1d96-4da6-9966-d06335e9d44d",
  "requestParameters": {
    "DetachImageWatermarkRequest": {
      "ImageId": "dw-probe",
      "WatermarkKey": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DetachInternetGateway

#
Service
ec2

Description

Detaches an Internet gateway from a VPC, disabling connectivity between the Internet and the VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "391942a4-c330-4d17-9497-343e28c0b8a1",
  "eventName": "DetachInternetGateway",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:12:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "40a130e8-f287-4bb9-8d8a-0be8dd7cffd8",
  "requestParameters": {
    "internetGatewayId": "igw-02a84e4222d62e16b",
    "vpcId": "vpc-06fe1a64761a0f720"
  },
  "responseElements": {
    "_return": true,
    "requestId": "40a130e8-f287-4bb9-8d8a-0be8dd7cffd8"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

DetachNetworkInterface

#
Service
ec2

Description

Detaches a network interface from an instance.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.InvalidAttachmentID.NotFound",
  "errorMessage": "The interface attachment 'eni-attach-02aca13293a6fe1b9' does not exist.",
  "eventCategory": "Management",
  "eventID": "39fba6c9-a3ab-406b-9b67-e43e05cd0899",
  "eventName": "DetachNetworkInterface",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:09:08Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "024edddb-94cf-4d36-9aed-7abc1ebf71d3",
  "requestParameters": {
    "attachmentId": "eni-attach-02aca13293a6fe1b9",
    "force": true
  },
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

DetachVerifiedAccessTrustProvider

#
Service
ec2

Description

Detaches the specified Amazon Web Services Verified Access trust provider from the specified Amazon Web Services Verified Access instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVerifiedAccessTrustProviderId.NotFound",
  "errorMessage": "VerifiedAccessTrustProvider dw-probe does not exist",
  "eventCategory": "Management",
  "eventID": "c41d6b8f-514d-4546-b89b-b7a7feed5661",
  "eventName": "DetachVerifiedAccessTrustProvider",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:40Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "43b84fdb-4c04-458f-ac6a-e9ed7d7e9fd4",
  "requestParameters": {
    "DetachVerifiedAccessTrustProviderRequest": {
      "ClientToken": "4c2c34dc-0477-4503-ab04-4c3e84e03c1d",
      "VerifiedAccessInstanceId": "dw-probe",
      "VerifiedAccessTrustProviderId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DetachVolume

#
Service
ec2

Description

Detaches an Amazon EBS volume from an instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation. Encoded authorization failure message: HYJFvwruKwBtMwIhS15T8i9rGXMn-2WgMxuVssxwqEdBjV8gZgFV12dK4KpKJWxJy8fVrBt6GP-G8HVY_HE8Y0wm0nHZr53vtC13RKPBJ9We8o90FgshcH7gkJLVixFD1dBFF_PwCEUr51WbCVA75bAn1DGW1g70siNFfutnKuQIgim7G4wq--3lmV4nydaRLMlGnie36viGWBpFffQKDMgstqaNqwlr7HuO9mhBtxw-ppy_N59gnvfYq2EyBDhl1KjmqfvrtYGxpdwySciIAq1BlTpC2kHGZ-dEKJiVr4pUlckewHB6220uJqgfgdMOj_cQu7zcKjYIlGy0cXJZ5BZuZB1bN8P-UgBieZEzrshEciCzHfnQ3Z-67LfLygzCg6mNVXq5lqgmvgSwqJMZ020Wl5grGrz-IDGBNgL1u0iZyOCLvutRvTuWuQU5E8Oa6ye7JNyeAA5QNNT-uwUel0b1HqoeerjVUwAOmwBKoVJnBLBEB9GdwssJzXv3mOqgdMK-A02kh98hick5ad5zwIRzorUiQoZvytdzd37GZjKEcT61okgE-Y8U-Q_YS6NkN3Jvc59ClLchepxeXInFFop5824phdyPHIb7YehpHYR6kmoUzKJJK_P9ogCef88X3fOOu23hfUVXK-bLJVb9gZoYEX7xUal1GPF5H8XknwEvSIisIkQP8IfrsHo_Cgh6",
  "eventID": "2e4c49af-a5c9-4686-8cdd-b326edee9ec4",
  "eventName": "DetachVolume",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-07-27T12:01:08Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "661dea5e-265d-4e0e-82ba-122c8adcf6d3",
  "requestParameters": {
    "force": false,
    "volumeId": "vol-8e100f305b7a6fef3"
  },
  "responseElements": null,
  "sourceIPAddress": "253.6.241.250",
  "userAgent": "aws-cli/1.15.4 Python/2.7.6 Linux/4.4.0-75-generic botocore/1.10.4",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DetachVpnGateway

#
Service
ec2

Description

Detaches a virtual private gateway from a VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpnGatewayID.NotFound",
  "errorMessage": "The vpnGateway ID 'dw-probe' does not exist",
  "eventCategory": "Management",
  "eventID": "fc887de2-f567-42db-a718-d23bc2833a7b",
  "eventName": "DetachVpnGateway",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8e0c8694-7aea-4737-9485-25617ce0711a",
  "requestParameters": {
    "vpcId": "dw-probe",
    "vpnGatewayId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableAddressTransfer

#
Service
ec2

Description

Disables Elastic IP address transfer.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidElasticIpID.NotFound",
  "errorMessage": "The allocation ID 'dw-probe' does not exist",
  "eventCategory": "Management",
  "eventID": "24605631-0a7e-4daf-ac63-bc13d09a644f",
  "eventName": "DisableAddressTransfer",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d4a50b68-dc8b-49a1-9b5d-86a85942b805",
  "requestParameters": {
    "DisableAddressTransferRequest": {
      "AllocationId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableAllowedImagesSettings

#
Service
ec2

Description

Disables Allowed AMIs for your account in the specified Amazon Web Services Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "579403dc-1da2-4b77-9abf-73c1d5987f75",
  "eventName": "DisableAllowedImagesSettings",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:43:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a1effc51-a9ed-405d-ae90-95995ed77d61",
  "requestParameters": {
    "DisableAllowedImagesSettingsRequest": ""
  },
  "responseElements": {
    "DisableAllowedImagesSettingsResponse": {
      "allowedImagesSettingsState": "disabled",
      "requestId": "a1effc51-a9ed-405d-ae90-95995ed77d61",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableAwsNetworkPerformanceMetricSubscription

#
Service
ec2

Description

Disables Infrastructure Performance metric subscriptions.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "Missing required parameter: Source",
  "eventCategory": "Management",
  "eventID": "3861ad9d-3682-4cbb-8a09-f54e0a017e1a",
  "eventName": "DisableAwsNetworkPerformanceMetricSubscription",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:45:17Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3c092b3c-17ae-4bab-8adf-4f0972ac320d",
  "requestParameters": {
    "DisableAwsNetworkPerformanceMetricSubscriptionRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableCapacityManager

#
Service
ec2

Description

Disables EC2 Capacity Manager for your account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.CapacityManager.Disabled",
  "errorMessage": "Capacity Manager isn't enabled for this account.",
  "eventCategory": "Management",
  "eventID": "b45118f6-5ce1-4546-b567-3738cd3064c9",
  "eventName": "DisableCapacityManager",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:45:17Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f44eb21b-d9fb-4387-8642-a0a9698b6e90",
  "requestParameters": {
    "DisableCapacityManagerRequest": {
      "ClientToken": "e34262b0-f35d-4b63-a639-839b3b037fc7"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableFastLaunch

#
Service
ec2

Description

Discontinue Windows fast launch for a Windows AMI, and clean up existing pre-provisioned snapshots.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRequest",
  "errorMessage": "2 validation errors detected: Value 'dw-probe' at 'imageId' failed to satisfy constraint: Member must have length greater than or equal to 12; Value 'dw-probe' at 'imageId' failed to satisfy constraint: Member must satisfy regular expression pattern: ami-[a-z0-9]+",
  "eventCategory": "Management",
  "eventID": "8c659b80-cbd1-42a3-8405-c177842588d4",
  "eventName": "DisableFastLaunch",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "49251be9-d0c9-4b76-9a3f-e3c77932fac1",
  "requestParameters": {
    "DisableFastLaunchRequest": {
      "ImageId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableFastSnapshotRestores

#
Service
ec2

Description

Disables fast snapshot restores for the specified snapshots in the specified Availability Zones.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "AvailabilityZone or AvailabilityZoneId must be specified in the request, but not both.",
  "eventCategory": "Management",
  "eventID": "02e026bf-1566-4f05-abf9-0474dfc1bd57",
  "eventName": "DisableFastSnapshotRestores",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:41Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c33b2126-353f-4dd6-b88e-3b3459f01b2e",
  "requestParameters": {
    "DisableFastSnapshotRestoresRequest": {
      "SourceSnapshotId": {
        "content": "dw-probe",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableImage

#
Service
ec2

Description

Sets the AMI state to disabled and removes all launch permissions from the AMI.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidAMIID.Malformed",
  "errorMessage": "The image ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "8b04835f-fe70-4699-88fa-e1bc09357d0b",
  "eventName": "DisableImage",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0c986b31-8de4-4c80-b1d4-fac46e6f0bec",
  "requestParameters": {
    "DisableImageRequest": {
      "ImageId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableImageBlockPublicAccess

#
Service
ec2

Description

Disables block public access for AMIs at the account level in the specified Amazon Web Services Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "fac4fc0a-ca0d-4d61-b8f2-65148eb70deb",
  "eventName": "DisableImageBlockPublicAccess",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:43:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0b23bfcb-9572-43d3-ae3c-be9f04c78886",
  "requestParameters": {
    "DisableImageBlockPublicAccessRequest": ""
  },
  "responseElements": {
    "DisableImageBlockPublicAccessResponse": {
      "imageBlockPublicAccessState": "unblocked",
      "requestId": "0b23bfcb-9572-43d3-ae3c-be9f04c78886",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableImageDeprecation

#
Service
ec2

Description

Cancels the deprecation of the specified AMI.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidAMIID.Malformed",
  "errorMessage": "The image ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "9eab49db-9cf3-4449-9681-2dddf0efac5e",
  "eventName": "DisableImageDeprecation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "dbdc9084-fa7f-4856-a0c4-b106e423f757",
  "requestParameters": {
    "DisableImageDeprecationRequest": {
      "ImageId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableImageDeregistrationProtection

#
Service
ec2

Description

Disables deregistration protection for an AMI.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidAMIID.Malformed",
  "errorMessage": "The image ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "3c9b4ff4-4def-4a74-b65b-91db4498b747",
  "eventName": "DisableImageDeregistrationProtection",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:42Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ee222e83-cb4f-4f85-9c88-8d4af7d0d6fa",
  "requestParameters": {
    "DisableImageDeregistrationProtectionRequest": {
      "ImageId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableInstanceSqlHaStandbyDetections

#
Service
ec2

Description

Disable Amazon EC2 instances running in an SQL Server High Availability cluster from SQL Server High Availability instance standby detection monitoring.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidInstanceID.Malformed",
  "errorMessage": "The instance ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "546c0416-f9a9-4485-bc1d-40d41018f8d3",
  "eventName": "DisableInstanceSqlHaStandbyDetections",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:43Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8d3b4c14-8ee3-4d20-a108-a12ead4786b3",
  "requestParameters": {
    "DisableInstanceSqlHaStandbyDetectionsRequest": {
      "InstanceId": {
        "content": "dw-probe",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableIpamOrganizationAdminAccount

#
Service
ec2

Description

Disable the IPAM account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "The delegated admin account ID is not valid.",
  "eventCategory": "Management",
  "eventID": "71bc1cf2-4234-47a9-abc1-eeb819448b67",
  "eventName": "DisableIpamOrganizationAdminAccount",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:43Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c58fdd8e-97b7-40d2-a429-66a4dee813c8",
  "requestParameters": {
    "DisableIpamOrganizationAdminAccountRequest": {
      "DelegatedAdminAccountId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableIpamPolicy

#
Service
ec2

Description

Disables an IPAM policy.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamPolicyId.Malformed",
  "errorMessage": "The ipam-policy ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "dd7730c9-c586-4d9a-a485-032eac1f985e",
  "eventName": "DisableIpamPolicy",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:43Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2014a946-ef9f-4f09-83a8-9a1d36c7e2e2",
  "requestParameters": {
    "DisableIpamPolicyRequest": {
      "IpamPolicyId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableRouteServerPropagation

#
Service
ec2

Description

Disables route propagation from a route server to a specified route table.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRouteServerId.Malformed",
  "errorMessage": "The route-server ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "a5e73bd7-a773-4380-8f4b-f76528303ed5",
  "eventName": "DisableRouteServerPropagation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9edb2345-b6ca-46be-8369-503984fbe578",
  "requestParameters": {
    "DisableRouteServerPropagationRequest": {
      "RouteServerId": "dw-probe",
      "RouteTableId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableSerialConsoleAccess

#
Service
ec2

Description

Disables access to the EC2 serial console of all instances for your account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "cb948f0c-2ed1-4143-b1c1-3b2215a06e1b",
  "eventName": "DisableSerialConsoleAccess",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:43:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b3bff592-2c14-425c-95d0-11325d5b4477",
  "requestParameters": {
    "DisableSerialConsoleAccessRequest": ""
  },
  "responseElements": {
    "DisableSerialConsoleAccessResponse": {
      "requestId": "b3bff592-2c14-425c-95d0-11325d5b4477",
      "serialConsoleAccessEnabled": false,
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableSnapshotBlockPublicAccess

#
Service
ec2

Description

Disables the block public access for snapshots setting at the account level for the specified Amazon Web Services Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "fb41b99d-95a1-4ec6-9279-b1b6795be53f",
  "eventName": "DisableSnapshotBlockPublicAccess",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:43:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "aaff370c-216d-48c7-bde0-dbb0bba64071",
  "requestParameters": {
    "DisableSnapshotBlockPublicAccessRequest": ""
  },
  "responseElements": {
    "DisableSnapshotBlockPublicAccessResponse": {
      "requestId": "aaff370c-216d-48c7-bde0-dbb0bba64071",
      "state": "unblocked",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableTransitGatewayRouteTablePropagation

#
Service
ec2

Description

Disables the specified resource attachment from propagating routes to the specified propagation route table.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRouteTableId.Malformed",
  "errorMessage": "Invalid Transit Gateway Route Table id dw-probe.",
  "eventCategory": "Management",
  "eventID": "05fad80f-5b01-43f0-be00-e22f4f52b648",
  "eventName": "DisableTransitGatewayRouteTablePropagation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "094ab4e4-35a0-4941-aee4-4a58ccf0eb88",
  "requestParameters": {
    "DisableTransitGatewayRouteTablePropagationRequest": {
      "TransitGatewayRouteTableId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableVgwRoutePropagation

#
Service
ec2

Description

Disables a virtual private gateway (VGW) from propagating routes to a specified route table of a VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRouteTableID.NotFound",
  "errorMessage": "The routeTable ID 'dw-probe' does not exist",
  "eventCategory": "Management",
  "eventID": "a6ca8fa1-1bbe-40c9-921e-5a30e1efc6d6",
  "eventName": "DisableVgwRoutePropagation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5f545c51-7424-4633-926b-2bf7b8fd5aa5",
  "requestParameters": {
    "gatewayId": "dw-probe",
    "routeTableId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisableVpcClassicLink

#
Service
ec2

DisableVpcClassicLinkDnsSupport

#
Service
ec2

Description

Disables ClassicLink DNS support for a VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "The request must contain the parameter vpcId",
  "eventCategory": "Management",
  "eventID": "1c9d654e-5094-4b30-a83f-73165426f7e0",
  "eventName": "DisableVpcClassicLinkDnsSupport",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:45:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "fab69118-a65d-4a96-983c-a20f9e4a9994",
  "requestParameters": {
    "DisableVpcClassicLinkDnsSupportRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateAddress

#
Service
ec2

Description

Disassociates an Elastic IP address from the instance or network interface it's associated with.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "Either public IP or association id must be specified",
  "eventCategory": "Management",
  "eventID": "ecc55b76-96f9-4bee-9819-5873221dcce2",
  "eventName": "DisassociateAddress",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:45:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c048216f-74d8-4868-bcc1-911f4915eb96",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateCapacityReservationBillingOwner

#
Service
ec2

Description

Cancels a pending request to assign billing of the unused capacity of a Capacity Reservation to a consumer account, or revokes a request that has already been accepted.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidCapacityReservationId.Malformed",
  "errorMessage": "Capacity Reservation ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "3cca8200-7fae-46cb-b773-c83fe6729440",
  "eventName": "DisassociateCapacityReservationBillingOwner",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6a0221cc-d8a7-4392-8fa4-78513e2c8968",
  "requestParameters": {
    "DisassociateCapacityReservationBillingOwnerRequest": {
      "CapacityReservationId": "dw-probe",
      "UnusedReservationBillingOwnerId": "dddddddddddd"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateClientVpnTargetNetwork

#
Service
ec2

Description

Disassociates a target network from the specified Client VPN endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidClientVpnEndpointId.NotFound",
  "errorMessage": "The client-vpn-endpoint ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "e1af69b9-0c39-4466-9722-bd666cca97b9",
  "eventName": "DisassociateClientVpnTargetNetwork",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9854b8c0-49ab-4eae-ae22-8a11d4fae8a0",
  "requestParameters": {
    "DisassociateClientVpnTargetNetworkRequest": {
      "AssociationId": "dw-probe",
      "ClientVpnEndpointId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateEnclaveCertificateIamRole

#
Service
ec2

Description

Disassociates an IAM role from an Certificate Manager (ACM) certificate.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidCertificateArn.Malformed",
  "errorMessage": "The request must contain a valid certificate arn",
  "eventCategory": "Management",
  "eventID": "5ee02384-4539-4902-a8f4-fc80691ef9d1",
  "eventName": "DisassociateEnclaveCertificateIamRole",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0f7104c6-8bf7-4340-8a97-5e748c42604b",
  "requestParameters": {
    "DisassociateEnclaveCertificateIamRoleRequest": {
      "CertificateArn": "dw-probe",
      "RoleArn": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateIamInstanceProfile

#
Service
ec2

Description

Disassociates an IAM instance profile from a running or stopped instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "Invalid Id: dw-probe",
  "eventCategory": "Management",
  "eventID": "b274b5d3-c009-4faa-8a87-69cfbabc837a",
  "eventName": "DisassociateIamInstanceProfile",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "dfbcb412-4b42-4dd1-9030-691fa06b8ff7",
  "requestParameters": {
    "DisassociateIamInstanceProfileRequest": {
      "AssociationId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DisassociateInstanceEventWindow

#
Service
ec2

Description

Disassociates one or more targets from an event window.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "The request must include the AssociationTarget parameter. Add the required parameter and retry the request.",
  "eventCategory": "Management",
  "eventID": "db13a59d-1b57-4138-a374-0eca0b3d7af8",
  "eventName": "DisassociateInstanceEventWindow",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ce3fb886-16cb-428d-9cb4-51184b48bb69",
  "requestParameters": {
    "DisassociateInstanceEventWindowRequest": {
      "InstanceEventWindowId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

DisassociateIpamByoasn

#
Service
ec2

Description

Remove the association between your Autonomous System Number (ASN) and your BYOIP CIDR.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidCidr.NotFound",
  "errorMessage": "The requested CIDR could not be found in IPAM.",
  "eventCategory": "Management",
  "eventID": "f513a1e5-22e7-49da-8614-ac91b6f06fb8",
  "eventName": "DisassociateIpamByoasn",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2c829acb-5af1-44bb-aa37-7cf363e4e5c7",
  "requestParameters": {
    "DisassociateIpamByoasnRequest": {
      "Asn": "dw-probe",
      "Cidr": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateIpamResourceDiscovery

#
Service
ec2

Description

Disassociates a resource discovery from an Amazon VPC IPAM.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamResourceDiscoveryAssociationId.Malformed",
  "errorMessage": "The ipam-resource-discovery-association ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "55290604-8f53-491c-a436-3122bd3842a2",
  "eventName": "DisassociateIpamResourceDiscovery",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "bb4d4fdc-7efa-4bf0-a159-397b13158468",
  "requestParameters": {
    "DisassociateIpamResourceDiscoveryRequest": {
      "IpamResourceDiscoveryAssociationId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateNatGatewayAddress

#
Service
ec2

Description

Disassociates secondary Elastic IP addresses (EIPs) from a public NAT gateway.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.NatGatewayMalformed",
  "errorMessage": "The natgateway ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "1de493ef-4cf5-4f7a-86fa-c57591e6169d",
  "eventName": "DisassociateNatGatewayAddress",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "fe8fcca5-b86a-4764-bfb1-ba235aa70d26",
  "requestParameters": {
    "DisassociateNatGatewayAddressRequest": {
      "AssociationId": {
        "content": "dw-probe",
        "tag": 1
      },
      "NatGatewayId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateRouteServer

#
Service
ec2

Description

Disassociates a route server from a VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRouteServerId.Malformed",
  "errorMessage": "The route-server ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "3842e46c-7882-466e-8ee2-87bb93aa9c2f",
  "eventName": "DisassociateRouteServer",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "692c6fe9-b8a4-4cd6-9bf9-f03705141b2c",
  "requestParameters": {
    "DisassociateRouteServerRequest": {
      "RouteServerId": "dw-probe",
      "VpcId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateSecurityGroupVpc

#
Service
ec2

Description

Disassociates a security group from a VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpcId.Malformed",
  "errorMessage": "The vpc ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "2f836f82-d6fe-4f06-9d7c-dab5d83cba23",
  "eventName": "DisassociateSecurityGroupVpc",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c0bba649-2ed2-403e-a983-ee8d4297423f",
  "requestParameters": {
    "DisassociateSecurityGroupVpcRequest": {
      "GroupId": "dw-probe",
      "VpcId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateSubnetCidrBlock

#
Service
ec2

Description

Disassociates a CIDR block from a subnet.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidSubnetCidrBlockAssociationId.Malformed",
  "errorMessage": "The subnet CIDR block with association ID dw-probe is malformed",
  "eventCategory": "Management",
  "eventID": "f3ab2a67-301a-4ffc-87e5-12663e3e4ce0",
  "eventName": "DisassociateSubnetCidrBlock",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7c9e4755-83f7-4b76-a01f-89597cddbc95",
  "requestParameters": {
    "DisassociateSubnetCidrBlockRequest": {
      "AssociationId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateTransitGatewayMulticastDomain

#
Service
ec2

Description

Disassociates the specified subnets from the transit gateway multicast domain.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayMulticastDomainId.Malformed",
  "errorMessage": "Invalid Transit Gateway Multicast Domain id dw-probe.",
  "eventCategory": "Management",
  "eventID": "0d14298e-8875-4076-a3e5-f26aebd9359f",
  "eventName": "DisassociateTransitGatewayMulticastDomain",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "733c16c4-ba18-4a9f-96fc-b678810387a6",
  "requestParameters": {
    "DisassociateTransitGatewayMulticastDomainRequest": {
      "SubnetIds": {
        "content": "dw-probe",
        "tag": 1
      },
      "TransitGatewayAttachmentId": "dw-probe",
      "TransitGatewayMulticastDomainId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateTransitGatewayPolicyTable

#
Service
ec2

Description

Removes the association between an an attachment and a policy table.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayPolicyTableId.Malformed",
  "errorMessage": "Invalid Transit Gateway Policy Table id dw-probe.",
  "eventCategory": "Management",
  "eventID": "c5e07b67-91df-452a-9952-a53fe8abe757",
  "eventName": "DisassociateTransitGatewayPolicyTable",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0149e87d-e433-4dc9-9596-344a4f7ba653",
  "requestParameters": {
    "DisassociateTransitGatewayPolicyTableRequest": {
      "TransitGatewayAttachmentId": "dw-probe",
      "TransitGatewayPolicyTableId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateTransitGatewayRouteTable

#
Service
ec2

Description

Disassociates a resource attachment from a transit gateway route table.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRouteTableId.Malformed",
  "errorMessage": "Invalid Transit Gateway Route Table id dw-probe.",
  "eventCategory": "Management",
  "eventID": "6c782e35-d5ea-4144-b977-e5f2c9cc07e6",
  "eventName": "DisassociateTransitGatewayRouteTable",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:47Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b5158537-2e96-4921-a187-b0ca79c3a448",
  "requestParameters": {
    "DisassociateTransitGatewayRouteTableRequest": {
      "TransitGatewayAttachmentId": "dw-probe",
      "TransitGatewayRouteTableId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateTrunkInterface

#
Service
ec2

Description

Removes an association between a branch network interface with a trunk network interface.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.OperationNotPermitted",
  "errorMessage": "User 123456789012 is not permitted to perform this operation",
  "eventCategory": "Management",
  "eventID": "7146f051-bd4b-429e-bf3d-bab7fd2d1dc7",
  "eventName": "DisassociateTrunkInterface",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "49112bf4-fb43-4d3e-92a5-eef0ec1ffbc7",
  "requestParameters": {
    "DisassociateTrunkInterfaceRequest": {
      "AssociationId": "dw-probe",
      "ClientToken": "880034cd-3c62-465c-b6a4-4d06a6289dba"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisassociateVpcCidrBlock

#
Service
ec2

Description

Disassociates a CIDR block from a VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpcCidrBlockAssociationId.Malformed",
  "errorMessage": "The vpc CIDR block with association ID dw-probe is malformed",
  "eventCategory": "Management",
  "eventID": "2cb13068-890f-40fd-90d1-946e71a4e9c7",
  "eventName": "DisassociateVpcCidrBlock",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4ac86607-639b-4fb5-8027-9085467a0eb6",
  "requestParameters": {
    "DisassociateVpcCidrBlockRequest": {
      "AssociationId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

EnableAddressTransfer

#
Service
ec2

Description

Enables Elastic IP address transfer.

EnableAllowedImagesSettings

#
Service
ec2

Description

Enables Allowed AMIs for your account in the specified Amazon Web Services Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "757ea468-81ab-4f9a-9f1e-e7083557d1b6",
  "eventName": "EnableAllowedImagesSettings",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:43:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "327a587e-795a-4be9-9c6f-19219706e2cd",
  "requestParameters": {
    "EnableAllowedImagesSettingsRequest": {
      "AllowedImagesSettingsState": "audit-mode"
    }
  },
  "responseElements": {
    "EnableAllowedImagesSettingsResponse": {
      "allowedImagesSettingsState": "audit-mode",
      "requestId": "327a587e-795a-4be9-9c6f-19219706e2cd",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

EnableAwsNetworkPerformanceMetricSubscription

#
Service
ec2

Description

Enables Infrastructure Performance subscriptions.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "2c24fa3c-43bf-401d-8ec7-d0e4a4e47406",
  "eventName": "EnableAwsNetworkPerformanceMetricSubscription",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:46:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8f39469a-2964-4b7d-a47d-e2401c21f81c",
  "requestParameters": {
    "EnableAwsNetworkPerformanceMetricSubscriptionRequest": {
      "Destination": "us-east-1",
      "Metric": "aggregate-latency",
      "Source": "us-west-1",
      "Statistic": "p50"
    }
  },
  "responseElements": {
    "EnableAwsNetworkPerformanceMetricSubscriptionResponse": {
      "output": true,
      "requestId": "8f39469a-2964-4b7d-a47d-e2401c21f81c",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

EnableCapacityManager

#
Service
ec2

Description

Enables EC2 Capacity Manager for your account.

EnableEbsEncryptionByDefault

#
Service
ec2

Description

Enables EBS encryption by default for your account in the current Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "febe1bcf-da4c-46f1-b943-06a8027b0234",
  "eventName": "EnableEbsEncryptionByDefault",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:43:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8c3d5071-9a8d-4d2e-a193-7ba04a78ba14",
  "requestParameters": {
    "EnableEbsEncryptionByDefaultRequest": ""
  },
  "responseElements": {
    "EnableEbsEncryptionByDefaultResponse": {
      "ebsEncryptionByDefault": true,
      "requestId": "8c3d5071-9a8d-4d2e-a193-7ba04a78ba14",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

EnableFastLaunch

#
Service
ec2

Description

When you enable Windows fast launch for a Windows AMI, images are pre-provisioned, using snapshots to launch instances up to 65% faster.

EnableFastSnapshotRestores

#
Service
ec2

Description

Enables fast snapshot restores for the specified snapshots in the specified Availability Zones.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f9a27ec1-9f14-476f-ae21-ba7d1427d22a",
  "eventName": "EnableFastSnapshotRestores",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:42:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "78244183-c9d4-4c9e-b343-7bbb0b350769",
  "requestParameters": {
    "EnableFastSnapshotRestoresRequest": {
      "AvailabilityZone": {
        "content": "us-west-1a",
        "tag": 1
      },
      "SourceSnapshotId": {
        "content": "snap-0ae577a47e091fcaa",
        "tag": 1
      }
    }
  },
  "responseElements": {
    "EnableFastSnapshotRestoresResponse": {
      "requestId": "78244183-c9d4-4c9e-b343-7bbb0b350769",
      "successful": {
        "item": {
          "availabilityZone": "us-west-1a",
          "availabilityZoneId": "usw1-az1",
          "enablingTime": "2026-06-29T22:42:02.187Z",
          "ownerId": "123456789012",
          "snapshotId": "snap-0ae577a47e091fcaa",
          "state": "enabling",
          "stateTransitionReason": "Client.UserInitiated"
        }
      },
      "unsuccessful": "",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

EnableImage

#
Service
ec2

Description

Re-enables a disabled AMI.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "3c9862f6-bd90-464a-88ac-737f5d16de95",
  "eventName": "EnableImage",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:45:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7f4e68ca-6332-4e39-a43b-0aece6ee8138",
  "requestParameters": {
    "EnableImageRequest": {
      "ImageId": "ami-0d80fdb354d9dd786"
    }
  },
  "responseElements": {
    "EnableImageResponse": {
      "requestId": "7f4e68ca-6332-4e39-a43b-0aece6ee8138",
      "return": true,
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

EnableImageBlockPublicAccess

#
Service
ec2

Description

Enables block public access for AMIs at the account level in the specified Amazon Web Services Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "b474c8fc-d23a-40f3-a786-e54dc15cb192",
  "eventName": "EnableImageBlockPublicAccess",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:43:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d62f881c-ac89-456e-b86d-3f82b62c75fa",
  "requestParameters": {
    "EnableImageBlockPublicAccessRequest": {
      "ImageBlockPublicAccessState": "block-new-sharing"
    }
  },
  "responseElements": {
    "EnableImageBlockPublicAccessResponse": {
      "imageBlockPublicAccessState": "block-new-sharing",
      "requestId": "d62f881c-ac89-456e-b86d-3f82b62c75fa",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

EnableImageDeprecation

#
Service
ec2

Description

Enables deprecation of the specified AMI at the specified date and time.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "b0cea53b-210e-4b43-96e3-dd8ec5ade16e",
  "eventName": "EnableImageDeprecation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:45:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5fcfcb9d-71c5-4d12-a474-894fe11d2e6b",
  "requestParameters": {
    "EnableImageDeprecationRequest": {
      "DeprecateAt": "2027-06-29T22:45:35Z",
      "ImageId": "ami-0d80fdb354d9dd786"
    }
  },
  "responseElements": {
    "EnableImageDeprecationResponse": {
      "requestId": "5fcfcb9d-71c5-4d12-a474-894fe11d2e6b",
      "return": true,
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

EnableImageDeregistrationProtection

#
Service
ec2

Description

Enables deregistration protection for an AMI.

EnableInstanceSqlHaStandbyDetections

#
Service
ec2

Description

Enable Amazon EC2 instances running in an SQL Server High Availability cluster for SQL Server High Availability instance standby detection monitoring.

EnableIpamOrganizationAdminAccount

#
Service
ec2

Description

Enable an Organizations member account as the IPAM admin account.

EnableIpamPolicy

#
Service
ec2

Description

Enables an IPAM policy.

EnableReachabilityAnalyzerOrganizationSharing

#
Service
ec2

Description

Establishes a trust relationship between Reachability Analyzer and Organizations.

EnableRouteServerPropagation

#
Service
ec2

Description

Defines which route tables the route server can update with routes.

EnableSnapshotBlockPublicAccess

#
Service
ec2

Description

Enables or modifies the block public access for snapshots setting at the account level for the specified Amazon Web Services Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "38c04daa-96ba-46d6-8d30-7d0fd0a33274",
  "eventName": "EnableSnapshotBlockPublicAccess",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:43:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cbe4aabc-0d4b-4078-8f8a-9fa492575ad5",
  "requestParameters": {
    "EnableSnapshotBlockPublicAccessRequest": {
      "State": "block-new-sharing"
    }
  },
  "responseElements": {
    "EnableSnapshotBlockPublicAccessResponse": {
      "requestId": "cbe4aabc-0d4b-4078-8f8a-9fa492575ad5",
      "state": "block-new-sharing",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

EnableTransitGatewayRouteTablePropagation

#
Service
ec2

Description

Enables the specified attachment to propagate routes to the specified propagation route table.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "6a42b894-08a6-496b-8d24-f7a86487d00b",
  "eventName": "EnableTransitGatewayRouteTablePropagation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:47:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "09a443da-853f-4834-b023-ebc8e5a37b4d",
  "requestParameters": {
    "EnableTransitGatewayRouteTablePropagationRequest": {
      "TransitGatewayAttachmentId": "tgw-attach-08d8a09ccdcb3d355",
      "TransitGatewayRouteTableId": "tgw-rtb-0f5c12c8b5c90a1a1"
    }
  },
  "responseElements": {
    "EnableTransitGatewayRouteTablePropagationResponse": {
      "propagation": {
        "resourceId": "vpc-00c0dad452596a616",
        "resourceType": "vpc",
        "state": "enabled",
        "transitGatewayAttachmentId": "tgw-attach-08d8a09ccdcb3d355",
        "transitGatewayRouteTableId": "tgw-rtb-0f5c12c8b5c90a1a1"
      },
      "requestId": "09a443da-853f-4834-b023-ebc8e5a37b4d",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

EnableVgwRoutePropagation

#
Service
ec2

Description

Enables a virtual private gateway (VGW) to propagate routes to the specified route table of a VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.Gateway.NotAttached",
  "errorMessage": "resource vgw-03b7415aef1ba49a5",
  "eventCategory": "Management",
  "eventID": "0db1bdd8-38c9-47a1-b4f3-4b35160c8571",
  "eventName": "EnableVgwRoutePropagation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:46:04Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f5cc6ebe-db89-4120-89ea-35c66b1c8300",
  "requestParameters": {
    "gatewayId": "vgw-03b7415aef1ba49a5",
    "routeTableId": "rtb-06b1ec38aa8ffb600"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

EnableVolumeIO

#
Service
ec2

Description

Enables I/O operations for a volume that had I/O operations disabled because the data on the volume was potentially inconsistent.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "32c6b3cd-2c72-4adc-9a98-9e45d969ae44",
  "eventName": "EnableVolumeIO",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-01-18T18:31:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "e2d0f0f8-ea81-4e33-a8dd-a5ba4e52c2df",
  "requestParameters": {
    "volumeId": "vol-8e100f305b7a6fef3"
  },
  "responseElements": null,
  "sourceIPAddress": "184.93.254.21",
  "userAgent": "aws-cli/1.14.18 Python/2.7.3 Linux/3.18.0-kali1-amd64 botocore/1.8.22",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

EnableVpcClassicLink

#
Service
ec2

EnableVpcClassicLinkDnsSupport

#
Service
ec2

Description

Enables a VPC to support DNS hostname resolution for ClassicLink.

ExportClientVpnClientCertificateRevocationList

#
Service
ec2

Description

Downloads the client certificate revocation list for the specified Client VPN endpoint.

ExportClientVpnClientConfiguration

#
Service
ec2

Description

Downloads the contents of the Client VPN endpoint configuration file for the specified Client VPN endpoint.

ExportTransitGatewayRoutes

#
Service
ec2

Description

Exports routes from the specified transit gateway route table to the specified S3 bucket.

ExportVerifiedAccessInstanceClientConfiguration

#
Service
ec2

Description

Exports the client configuration for a Verified Access instance.

GetActiveVpnTunnelStatus

#
Service
ec2

Description

Returns the currently negotiated security parameters for an active VPN tunnel, including IKE version, DH groups, encryption algorithms, and integrity algorithms.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpnConnectionID.NotFound",
  "errorMessage": "The vpn-connection ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "7252d7a6-6382-4a27-b0df-da8af7d3dbe5",
  "eventName": "GetActiveVpnTunnelStatus",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c1d5251e-3b84-41ea-bcb0-8781e7cfea6c",
  "requestParameters": {
    "GetActiveVpnTunnelStatusRequest": {
      "VpnConnectionId": "dw-probe",
      "VpnTunnelOutsideIpAddress": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetAllowedImagesSettings

#
Service
ec2

Description

Gets the current state of the Allowed AMIs setting and the list of Allowed AMIs criteria at the account level in the specified Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f63faadf-d3c3-4dfb-bb88-483e24d21421",
  "eventName": "GetAllowedImagesSettings",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "87dad9b0-fe76-4aa2-8ab4-cc2b84f04c97",
  "requestParameters": {
    "GetAllowedImagesSettingsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetAssociatedEnclaveCertificateIamRoles

#
Service
ec2

Description

Returns the IAM roles that are associated with the specified ACM (ACM) certificate.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidCertificateArn.Malformed",
  "errorMessage": "The request must contain a valid certificate arn",
  "eventCategory": "Management",
  "eventID": "3a10495e-9cd4-45ed-b32f-fd615f9bc1b5",
  "eventName": "GetAssociatedEnclaveCertificateIamRoles",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "d7e48616-dc1f-4f12-b7d7-287e09a10702",
  "requestParameters": {
    "GetAssociatedEnclaveCertificateIamRolesRequest": {
      "CertificateArn": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetAssociatedIpv6PoolCidrs

#
Service
ec2

Description

Gets information about the IPv6 CIDR block associations for a specified IPv6 address pool.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "9bbc54e2-f669-42bb-9c07-8c5cf62a34f6",
  "eventName": "GetAssociatedIpv6PoolCidrs",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-05-19T17:44:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "5f73d087-c13f-48e4-a60b-949917a501c1",
  "requestParameters": {
    "GetAssociatedIpv6PoolCidrsRequest": {
      "PoolId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "255.251.4.254",
  "userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

GetAwsNetworkPerformanceData

#
Service
ec2

Description

Gets network performance data.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "Missing data queries parameter",
  "eventCategory": "Management",
  "eventID": "d8394840-4c37-4cba-81cc-327a5452e930",
  "eventName": "GetAwsNetworkPerformanceData",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:53Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "374f379b-8962-403f-80fa-43ddc6e3fe5d",
  "requestParameters": {
    "GetAwsNetworkPerformanceDataRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetCapacityManagerAttributes

#
Service
ec2

Description

Retrieves the current configuration and status of EC2 Capacity Manager for your account, including enablement status, Organizations access settings, and data ingestion status.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.CapacityManager.Disabled",
  "errorMessage": "Capacity Manager isn't enabled for this account.",
  "eventCategory": "Management",
  "eventID": "1ee1e079-a5fa-4dd0-a05c-2b367fe7a13e",
  "eventName": "GetCapacityManagerAttributes",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:53Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "cb75c4c9-f297-4b70-a5ab-a1ae05fcd2ed",
  "requestParameters": {
    "GetCapacityManagerAttributesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetCapacityManagerMetricData

#
Service
ec2

Description

Retrieves capacity usage metrics for your EC2 resources.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterCombination",
  "errorMessage": "EndTime must be after StartTime.",
  "eventCategory": "Management",
  "eventID": "b05142fe-6d1d-4f1c-9e30-f7a88e176d60",
  "eventName": "GetCapacityManagerMetricData",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "4a23670d-eaea-48d9-a481-5e772a11463a",
  "requestParameters": {
    "GetCapacityManagerMetricDataRequest": {
      "EndTime": "2020-01-01T00:00:00Z",
      "MetricName": {
        "content": "reservation-total-capacity-hrs-vcpu",
        "tag": 1
      },
      "Period": 3600,
      "StartTime": "2020-01-01T00:00:00Z"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetCapacityManagerMetricDimensions

#
Service
ec2

Description

Retrieves the available dimension values for capacity metrics within a specified time range.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterCombination",
  "errorMessage": "EndTime must be after StartTime.",
  "eventCategory": "Management",
  "eventID": "78fc28d6-96af-441a-9e62-8c439a52dbdf",
  "eventName": "GetCapacityManagerMetricDimensions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:12Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "28d77001-3f78-46b9-a8dc-0ad13b2b5ba5",
  "requestParameters": {
    "GetCapacityManagerMetricDimensionsRequest": {
      "EndTime": "2020-01-01T00:00:00Z",
      "GroupBy": {
        "content": "resource-region",
        "tag": 1
      },
      "MetricName": {
        "content": "reservation-total-capacity-hrs-vcpu",
        "tag": 1
      },
      "StartTime": "2020-01-01T00:00:00Z"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetCapacityManagerMonitoredTagKeys

#
Service
ec2

Description

Retrieves the tag keys that are currently being monitored by EC2 Capacity Manager.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.CapacityManager.Disabled",
  "errorMessage": "Capacity Manager isn't enabled for this account.",
  "eventCategory": "Management",
  "eventID": "854673dd-d9b8-48d0-a228-4b0464e0a800",
  "eventName": "GetCapacityManagerMonitoredTagKeys",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:53Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "d549ca48-5b44-4a17-bc5b-af819c71a6f4",
  "requestParameters": {
    "GetCapacityManagerMonitoredTagKeysRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetCapacityReservationUsage

#
Service
ec2

Description

Gets usage information about a Capacity Reservation.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.InvalidCapacityReservationId.Malformed",
  "errorMessage": "The capacity-reservation ID 'dummy_data' is malformed",
  "eventID": "85e9371b-d48d-43af-aee1-a631a6da8242",
  "eventName": "GetCapacityReservationUsage",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-05-19T17:44:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "d7425e64-98e3-4c05-9b35-7329f9766df9",
  "requestParameters": {
    "GetCapacityReservationUsageRequest": {
      "CapacityReservationId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "255.251.4.254",
  "userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

GetCoipPoolUsage

#
Service
ec2

Description

Describes the allocations from the specified customer-owned address pool.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "080f4663-1dcb-44ba-aa9f-d1a55d592480",
  "eventName": "GetCoipPoolUsage",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-05-19T17:44:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "8e8bfc66-eac7-4ad6-9b6b-54a770a17c55",
  "requestParameters": {
    "GetCoipPoolUsageRequest": {
      "PoolId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "255.251.4.254",
  "userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

GetConsoleOutput

#
Service
ec2

Description

Gets the console output for the specified instance.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "e13e1ac7-2a1d-43b7-b7ab-ec0d91d52fb5",
  "eventName": "GetConsoleOutput",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-07-07T17:29:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "4cd4c8c2-ca0f-4f21-8c28-283bca3b03a2",
  "requestParameters": {
    "instanceId": "i-0630822f0d30a09ee"
  },
  "responseElements": null,
  "sourceIPAddress": "3.142.206.200",
  "userAgent": "Boto3/1.17.24 Python/3.6.13 Linux/4.19.0-17-cloud-amd64 Botocore/1.20.98",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI37S4KUWNVD",
    "accountId": "797507667711",
    "arn": "arn:aws:sts::797507667711:assumed-role/Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG/1625678983.751919",
    "principalId": "AROA3TLZJI37S6HPJWVJ2:1625678983.751919",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T17:29:43Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "797507667711",
        "arn": "arn:aws:iam::797507667711:role/Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG",
        "principalId": "AROA3TLZJI37S6HPJWVJ2",
        "type": "Role",
        "userName": "Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

References #

GetConsoleScreenshot

#
Service
ec2

Description

Retrieve a JPG-format screenshot of a running instance to help with troubleshooting.

Example CloudTrail Event #

{
  "awsRegion": "us-east-2",
  "eventCategory": "Management",
  "eventID": "b5a1e7d2-5dd8-4fc4-ab50-7ac38ea52292",
  "eventName": "GetConsoleScreenshot",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-07-07T17:29:44Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "797507667711",
  "requestID": "f6270591-e0a0-471d-8470-600e7af128ec",
  "requestParameters": {
    "GetConsoleScreenshotRequest": {
      "InstanceId": "i-0630822f0d30a09ee",
      "WakeUp": true
    }
  },
  "responseElements": null,
  "sourceIPAddress": "3.142.206.200",
  "userAgent": "Boto3/1.17.24 Python/3.6.13 Linux/4.19.0-17-cloud-amd64 Botocore/1.20.98",
  "userIdentity": {
    "accessKeyId": "ASIA3TLZJI37S4KUWNVD",
    "accountId": "797507667711",
    "arn": "arn:aws:sts::797507667711:assumed-role/Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG/1625678983.751919",
    "principalId": "AROA3TLZJI37S6HPJWVJ2:1625678983.751919",
    "sessionContext": {
      "attributes": {
        "creationDate": "2021-07-07T17:29:43Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "797507667711",
        "arn": "arn:aws:iam::797507667711:role/Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG",
        "principalId": "AROA3TLZJI37S6HPJWVJ2",
        "type": "Role",
        "userName": "Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

References #

GetDeclarativePoliciesReportSummary

#
Service
ec2

Description

Retrieves a summary of the account status report.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidDeclarativePoliciesReportId.Malformed",
  "errorMessage": "The declarative-policies-report ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "b27de176-3784-4a20-8676-d678a56cb970",
  "eventName": "GetDeclarativePoliciesReportSummary",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "259338a6-8301-44ef-8c20-ae9931e5398f",
  "requestParameters": {
    "GetDeclarativePoliciesReportSummaryRequest": {
      "ReportId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetDefaultCreditSpecification

#
Service
ec2

Description

Describes the default credit option for CPU usage of a burstable performance instance family.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "10acc567-5ea8-4c0c-93a2-993d94ff614c",
  "eventName": "GetDefaultCreditSpecification",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-05-19T17:44:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "182f8680-f2ea-44c2-b968-06adcc483ea1",
  "requestParameters": {
    "GetDefaultCreditSpecificationRequest": {
      "InstanceFamily": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "255.251.4.254",
  "userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

GetEnabledIpamPolicy

#
Service
ec2

Description

Gets the enabled IPAM policy.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "592083cd-54ba-4cf0-92f8-ce5ece76952f",
  "eventName": "GetEnabledIpamPolicy",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "e182b5fb-0127-4b7c-87ab-45d94b9bd325",
  "requestParameters": {
    "GetEnabledIpamPolicyRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetFlowLogsIntegrationTemplate

#
Service
ec2

Description

Generates a CloudFormation template that streamlines and automates the integration of VPC flow logs with Amazon Athena.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "The request must include the IntegrateServices parameter. Add the required parameter and retry the request.",
  "eventCategory": "Management",
  "eventID": "918c5973-f60d-4bb8-8caa-59851bc6395d",
  "eventName": "GetFlowLogsIntegrationTemplate",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "40c15f61-4e5b-4b66-9e49-c9075995cfd3",
  "requestParameters": {
    "GetFlowLogsIntegrationTemplateRequest": {
      "ConfigDeliveryS3DestinationArn": "dw-probe",
      "FlowLogId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetGroupsForCapacityReservation

#
Service
ec2

Description

Lists the resource groups to which a Capacity Reservation has been added.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation. Encoded authorization failure message: n2jmViN2L53KhPN33l5uB0J3hLP-5h_UpLkGl58BorOtWmGe5NcK_hyEGTgUTgKCL0-NRHIylkMjMqBowGfKSZKdMxEowsEgYjNr9MOA-zDTTSMfSIsqeGbBZJ05z-9t_ZzSI3z2zCIaYDPz5alpA-Tau9cIl0s46fZ8y2KXkppUK7Y5JZYi5uz9JQRTB2ErbVOzl87Er4gArXkRbq4hKrQU_bbj_0Lsdr32mXhXYtabwD9BAb9HyyD5q2xFpnkhetM-BsWkoGQaapaG-CFuSsx1v5KE8_AAeGxgp-C4rLBiOXQrP1kxTCaGGveDqJf4xF_pI0r6QfFPpGHiF0o4wZxMxKx0w1yJYKcwGVEzNnoopjIgNgMa_e7UoFkE1tjOGBjrCPnirSo2_3uUhSI4o1YrvWgbTEt77hXM7b8Kp-dvUlgL9RL8UMmc8kX9tyvu3isLlBWHUcRbTgWdhuRubA5H2hgGIS7pdwsp_5ZLkP3G-_qu4pzzLf1c9UbOMjza-87I_DTJAaQ77f9Lpg",
  "eventID": "53461c-6ff0-4191-8e7b-6a2372c3f29a",
  "eventName": "GetGroupsForCapacityReservation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-09-21T04:27:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "815d0b4d-d306-4bc9-9dbb-accaae76eba7",
  "requestParameters": {
    "GetGroupsForCapacityReservationRequest": {
      "CapacityReservationId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "9.240.250.1",
  "userAgent": "Boto3/1.14.51 Python/3.8.5 Linux/4.19.76-linuxkit Botocore/1.17.51",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

GetHostReservationPurchasePreview

#
Service
ec2

Description

Preview a reservation purchase with configurations that match those of your Dedicated Host.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "087620b4e-bd3c-4069-a85b-72e9cacd78ef",
  "eventName": "GetHostReservationPurchasePreview",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-11-10T12:01:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "469424d7e-cd01-4fb6-95ff-e7cfb5420da3",
  "requestParameters": {
    "GetHostReservationPurchasePreviewRequest": {
      "HostIdSet": {
        "content": "test",
        "tag": 1
      },
      "OfferingId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "43.254.0.31",
  "userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

GetImageAncestry

#
Service
ec2

Description

Retrieves the ancestry chain of the specified AMI, tracing its lineage back to the root AMI.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidAMIID.Malformed",
  "errorMessage": "The image ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "81f35a16-f14e-4c4c-baf5-6f0d3d3769de",
  "eventName": "GetImageAncestry",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "1943b873-3770-464a-9e57-e73463a7e170",
  "requestParameters": {
    "GetImageAncestryRequest": {
      "ImageId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetImageBlockPublicAccessState

#
Service
ec2

Description

Gets the current state of block public access for AMIs at the account level in the specified Amazon Web Services Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "27e3c5cf-2b24-46b5-8ea6-3ee64fcec7f8",
  "eventName": "GetImageBlockPublicAccessState",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "faa3de84-68f5-4cd6-88ba-043c71bc907e",
  "requestParameters": {
    "GetImageBlockPublicAccessStateRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetInstanceMetadataDefaults

#
Service
ec2

Description

Gets the default instance metadata service (IMDS) settings that are set at the account level in the specified Amazon Web Services Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "a30fd4b4-fe76-4ac9-8c14-c5aed5c865be",
  "eventName": "GetInstanceMetadataDefaults",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "ea13785b-1982-467f-ae2c-79bf9f391036",
  "requestParameters": {
    "GetInstanceMetadataDefaultsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetInstanceTpmEkPub

#
Service
ec2

Description

Gets the public endorsement key associated with the Nitro Trusted Platform Module (NitroTPM) for the specified instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidInstanceID.Malformed",
  "errorMessage": "The instance ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "721a1d56-6dd3-42bf-9d26-58735d7ccdbe",
  "eventName": "GetInstanceTpmEkPub",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "20e34ea8-84a1-431c-8920-0288a0d7bc40",
  "requestParameters": {
    "GetInstanceTpmEkPubRequest": {
      "InstanceId": "dw-probe",
      "KeyFormat": "der",
      "KeyType": "rsa-2048"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetInstanceTypesFromInstanceRequirements

#
Service
ec2

Description

Returns a list of instance types with the specified instance attributes.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "a203bf35-fd03-46a1-bb9e-f5c7a8bdb898",
  "eventName": "GetInstanceTypesFromInstanceRequirements",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "cb02e203-e1d5-4866-9e51-7dc577802136",
  "requestParameters": {
    "GetInstanceTypesFromInstanceRequirementsRequest": {
      "ArchitectureType": {
        "content": "i386",
        "tag": 1
      },
      "InstanceRequirements": {
        "MemoryMiB": {
          "Min": 1
        },
        "VCpuCount": {
          "Min": 1
        }
      },
      "VirtualizationType": {
        "content": "hvm",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetInstanceUefiData

#
Service
ec2

Description

A binary representation of the UEFI variable store.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidInstanceID.Malformed",
  "errorMessage": "The instance ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "4a5cf493-aa10-4ac2-9dba-b0ac121c829e",
  "eventName": "GetInstanceUefiData",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:13Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "a3379a42-c24c-489a-823a-bae06543dddc",
  "requestParameters": {
    "GetInstanceUefiDataRequest": {
      "InstanceId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetIpamAddressHistory

#
Service
ec2

Description

Retrieve historical information about a CIDR within an IPAM scope.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamScopeId.Malformed",
  "errorMessage": "The ipam-scope ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "ef9b4a65-d82b-4785-8ce3-9e6a8d2f3f84",
  "eventName": "GetIpamAddressHistory",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "9a36fa65-a5e5-459c-90be-e683b30099f6",
  "requestParameters": {
    "GetIpamAddressHistoryRequest": {
      "Cidr": "dw-probe",
      "IpamScopeId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetIpamDiscoveredAccounts

#
Service
ec2

Description

Gets IPAM discovered accounts.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamResourceDiscoveryId.Malformed",
  "errorMessage": "The specified IPAM resource discovery ID is not valid. Specify an IPAM resource discovery ID in the form ipam-res-disco-xxxxxxxxxxxxxxxxx.",
  "eventCategory": "Management",
  "eventID": "968d6ccd-90eb-4b96-8c48-e80e6bb99f51",
  "eventName": "GetIpamDiscoveredAccounts",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "4ea46af2-5449-48a2-b06e-472da04fd19e",
  "requestParameters": {
    "GetIpamDiscoveredAccountsRequest": {
      "DiscoveryRegion": "dw-probe",
      "IpamResourceDiscoveryId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetIpamDiscoveredPublicAddresses

#
Service
ec2

Description

Gets the public IP addresses that have been discovered by IPAM.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamResourceDiscoveryId.Malformed",
  "errorMessage": "The ipam-resource-discovery ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "e5926711-037b-4739-af22-ad5a5b736a6a",
  "eventName": "GetIpamDiscoveredPublicAddresses",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "dc270a67-9ca8-4430-8542-3dd4e52e45ad",
  "requestParameters": {
    "GetIpamDiscoveredPublicAddressesRequest": {
      "AddressRegion": "dw-probe",
      "IpamResourceDiscoveryId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetIpamDiscoveredResourceCidrs

#
Service
ec2

Description

Returns the resource CIDRs that are monitored as part of a resource discovery.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamResourceDiscoveryId.Malformed",
  "errorMessage": "The specified IPAM resource discovery ID is not valid. Specify an IPAM resource discovery ID in the form ipam-res-disco-xxxxxxxxxxxxxxxxx.",
  "eventCategory": "Management",
  "eventID": "1831c654-afe5-4a7a-9d9b-43339c00adff",
  "eventName": "GetIpamDiscoveredResourceCidrs",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "5c33db58-87d5-46f6-8e32-a946c0c5b1a1",
  "requestParameters": {
    "GetIpamDiscoveredResourceCidrsRequest": {
      "IpamResourceDiscoveryId": "dw-probe",
      "ResourceRegion": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetIpamPolicyAllocationRules

#
Service
ec2

Description

Gets the allocation rules for an IPAM policy.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamPolicyId.Malformed",
  "errorMessage": "The ipam-policy ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "69c3fa61-c8ba-4f7f-9e05-e2192e93908a",
  "eventName": "GetIpamPolicyAllocationRules",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "7958f433-5e45-4b81-be25-b7d51e699ef6",
  "requestParameters": {
    "GetIpamPolicyAllocationRulesRequest": {
      "IpamPolicyId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetIpamPolicyOrganizationTargets

#
Service
ec2

Description

Gets the Amazon Web Services Organizations targets for an IPAM policy.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamPolicyId.Malformed",
  "errorMessage": "The ipam-policy ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "95f70605-0f76-4c10-959e-993342b2a793",
  "eventName": "GetIpamPolicyOrganizationTargets",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "d6af9561-42d6-458f-9ecf-a3b70e3358c5",
  "requestParameters": {
    "GetIpamPolicyOrganizationTargetsRequest": {
      "IpamPolicyId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetIpamPoolAllocations

#
Service
ec2

Description

Get a list of all the CIDR allocations in an IPAM pool.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamPoolId.Malformed",
  "errorMessage": "The specified IPAM pool ID is not valid. Specify an IPAM pool ID in the form ipam-pool-xxxxxxxxxxxxxxxxx.",
  "eventCategory": "Management",
  "eventID": "3fb029cf-a3cc-477b-90a1-be216a4072d4",
  "eventName": "GetIpamPoolAllocations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "fdf2fc96-b808-4aab-ac99-7fd39327ced0",
  "requestParameters": {
    "GetIpamPoolAllocationsRequest": {
      "IpamPoolId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetIpamPoolCidrs

#
Service
ec2

Description

Get the CIDRs provisioned to an IPAM pool.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamPoolId.Malformed",
  "errorMessage": "The specified IPAM pool ID is not valid. Specify an IPAM pool ID in the form ipam-pool-xxxxxxxxxxxxxxxxx.",
  "eventCategory": "Management",
  "eventID": "0811c7b7-7b80-45d4-8cac-172679451e95",
  "eventName": "GetIpamPoolCidrs",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "aae9b16a-144a-4190-8c1a-b1749a8f15f5",
  "requestParameters": {
    "GetIpamPoolCidrsRequest": {
      "IpamPoolId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetIpamPrefixListResolverRules

#
Service
ec2

Description

Retrieves the CIDR selection rules for an IPAM prefix list resolver.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamPrefixListResolverId.Malformed",
  "errorMessage": "The ipam-prefix-list-resolver ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "35fc83d3-c269-4b87-babe-a2af901efce2",
  "eventName": "GetIpamPrefixListResolverRules",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "e82de3a1-ef4f-4b6b-ad40-7484f1d34628",
  "requestParameters": {
    "GetIpamPrefixListResolverRulesRequest": {
      "IpamPrefixListResolverId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetIpamPrefixListResolverVersionEntries

#
Service
ec2

Description

Retrieves the CIDR entries for a specific version of an IPAM prefix list resolver.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamPrefixListResolverId.Malformed",
  "errorMessage": "The ipam-prefix-list-resolver ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "30af075d-f564-4945-bc83-eb59da83c24e",
  "eventName": "GetIpamPrefixListResolverVersionEntries",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "71d23c0f-1e7e-4536-b51f-5570633b41c7",
  "requestParameters": {
    "GetIpamPrefixListResolverVersionEntriesRequest": {
      "IpamPrefixListResolverId": "dw-probe",
      "IpamPrefixListResolverVersion": 1
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetIpamPrefixListResolverVersions

#
Service
ec2

Description

Retrieves version information for an IPAM prefix list resolver.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamPrefixListResolverId.Malformed",
  "errorMessage": "The ipam-prefix-list-resolver ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "4e05c503-8d1e-4c18-a9aa-dcd651898642",
  "eventName": "GetIpamPrefixListResolverVersions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:16Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "0182edda-dcb2-4452-aa17-a9807e5edefd",
  "requestParameters": {
    "GetIpamPrefixListResolverVersionsRequest": {
      "IpamPrefixListResolverId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetIpamResourceCidrs

#
Service
ec2

Description

Returns resource CIDRs managed by IPAM in a given scope.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamScopeId.Malformed",
  "errorMessage": "The specified IPAM scope ID is not valid. Specify an IPAM scope ID in the form ipam-scope-xxxxxxxxxxxxxxxxx.",
  "eventCategory": "Management",
  "eventID": "9839bd9d-2d22-4b48-95dc-1403a02c0ab2",
  "eventName": "GetIpamResourceCidrs",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:16Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "f451aba3-d9a3-4850-a5b5-83ceb70fca40",
  "requestParameters": {
    "GetIpamResourceCidrsRequest": {
      "IpamScopeId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetLaunchTemplateData

#
Service
ec2

Description

Retrieves the configuration data of the specified instance.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "c5afea9e-09db-444c-97a3-545459a6aa",
  "eventName": "GetLaunchTemplateData",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-11-10T12:01:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "755bb977-df50-4cd3-b2d6-5fdd3f2d0fc2",
  "requestParameters": {
    "GetLaunchTemplateDataRequest": {
      "InstanceId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "43.254.0.31",
  "userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

GetManagedPrefixListAssociations

#
Service
ec2

Description

Gets information about the resources that are associated with the specified managed prefix list.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "fa18e079-2317-437e-9a46-4fe99e6e6e4a",
  "eventName": "GetManagedPrefixListAssociations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-07-20T15:26:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "41bef85a-e95e-484d-8168-5de2dfe831315",
  "requestParameters": {
    "GetManagedPrefixListAssociationsRequest": {
      "PrefixListId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "105.204.6.57",
  "userAgent": "Boto3/1.14.20 Python/3.8.2 Linux/5.4.0-40-generic Botocore/1.17.20",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

GetManagedPrefixListEntries

#
Service
ec2

Description

Gets information about the entries for a specified managed prefix list.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation. Encoded authorization failure message: yAKdGWY5sn5xqtrskcTboMjjYWXJ6k7LqCK7yT-GFmfFW8uKSqKdx4cObEbgAwxL7KPebKYCF7U35p6v1b1nPUUSdaefFU11gx1AybkcufCTQ3ov8GGTJ-03smp4qdcnJHZQLdgcbVtcMwUowvSsT760fHrsonB4JryJYkhnVw0FImJDvaczS1SmAlYR3aNHa5aDe5bBafAvHd0MU1u3bZkxz8DLBvdbV2k5OGE8iXTN5bi6F6Gm0yLNgb2ZtXlw7uysXDStcr-l2bL57shyyi9uixsbuGe1Fxst9Z8Wx3WaAxxqVUY2sFYu7bH6oe0wpz2XnPmeOuafVevAi9Izo5s41WVomRqU4zs2CCI1ZFQM2xtl6IlHZkERPmCLquUVVz9UHHn77FlDEpCwGfGrGxibMvGAO3ANN0cSMLy37pUTe0VDlCk9CMndFj8XIZSe7EilTsVtKfnoMd5LmcU91GFO4TM2s8p-tNt95JqbcdCj62QlnFO0IN64A4HC1MMS8MZAgJ8EWGlpbeP_kRo",
  "eventID": "275f2526-1284-4bc0-b71d-8d13a21ab87a",
  "eventName": "GetManagedPrefixListEntries",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-07-20T15:26:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "2ddc2b23-1a72-470b-9333-fd8a486dd10f",
  "requestParameters": {
    "GetManagedPrefixListEntriesRequest": {
      "PrefixListId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "105.204.6.57",
  "userAgent": "Boto3/1.14.20 Python/3.8.2 Linux/5.4.0-40-generic Botocore/1.17.20",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

GetManagedResourceVisibility

#
Service
ec2

Description

Retrieves the managed resource visibility configuration for the account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "3544a2d1-1aa4-47ef-a30c-82a51c43dc84",
  "eventName": "GetManagedResourceVisibility",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "52f579a7-0389-42a1-8a15-deab0a2ff002",
  "requestParameters": {
    "GetManagedResourceVisibilityRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetNetworkInsightsAccessScopeAnalysisFindings

#
Service
ec2

Description

Gets the findings for the specified Network Access Scope analysis.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "dw-probe is not a valid NetworkInsightsAccessScopeAnalysisId.",
  "eventCategory": "Management",
  "eventID": "ed754418-43dc-45c5-8a51-b4d0064ae315",
  "eventName": "GetNetworkInsightsAccessScopeAnalysisFindings",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:16Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "953f5adc-8531-42ea-a4c8-ad24d822ec4a",
  "requestParameters": {
    "GetNetworkInsightsAccessScopeAnalysisFindingsRequest": {
      "NetworkInsightsAccessScopeAnalysisId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetNetworkInsightsAccessScopeContent

#
Service
ec2

Description

Gets the content for the specified Network Access Scope.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "dw-probe is not a valid NetworkInsightsAccessScopeId.",
  "eventCategory": "Management",
  "eventID": "ccaa3962-7656-4930-9d61-b43e11af1889",
  "eventName": "GetNetworkInsightsAccessScopeContent",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:16Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "52ebab74-0430-45a9-82f9-fc70e8a5f753",
  "requestParameters": {
    "GetNetworkInsightsAccessScopeContentRequest": {
      "NetworkInsightsAccessScopeId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetReservedInstancesExchangeQuote

#
Service
ec2

Description

Returns details about the values and term of your specified Convertible Reserved Instances.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "5d669dd7-a4d8-4b7b-adee-bf6fa7dbc032",
  "eventName": "GetReservedInstancesExchangeQuote",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-11-10T12:01:53Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "0830e907-c5a7-4a85-84b3-c8f878ca30c2",
  "requestParameters": {
    "GetReservedInstancesExchangeQuoteRequest": {
      "ReservedInstanceId": {
        "content": "test",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "43.254.0.31",
  "userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

GetRouteServerAssociations

#
Service
ec2

Description

Gets information about the associations for the specified route server.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRouteServerId.Malformed",
  "errorMessage": "The route-server ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "8799992a-3d77-42ea-97b4-74f5e5c80956",
  "eventName": "GetRouteServerAssociations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:17Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "39e1d15f-7009-4901-a2b9-f8947bc0602d",
  "requestParameters": {
    "GetRouteServerAssociationsRequest": {
      "RouteServerId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetRouteServerPropagations

#
Service
ec2

Description

Gets information about the route propagations for the specified route server.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRouteServerId.Malformed",
  "errorMessage": "The route-server ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "2cc34321-5e45-4bdf-8a17-b9f7cd085b48",
  "eventName": "GetRouteServerPropagations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:17Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "d180cebf-0de0-48cd-aff4-6bf965927a24",
  "requestParameters": {
    "GetRouteServerPropagationsRequest": {
      "RouteServerId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetRouteServerRoutingDatabase

#
Service
ec2

Description

Gets the routing database for the specified route server.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRouteServerId.Malformed",
  "errorMessage": "The route-server ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "fed53428-66c2-488b-aaaa-fd1b0c2fb2a1",
  "eventName": "GetRouteServerRoutingDatabase",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:17Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "1d5938cd-5941-48fe-9caa-66a1b4baa87f",
  "requestParameters": {
    "GetRouteServerRoutingDatabaseRequest": {
      "RouteServerId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetSecurityGroupsForVpc

#
Service
ec2

Description

Gets security groups that can be associated by the Amazon Web Services account making the request with network interfaces in the specified VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpcId.Malformed",
  "errorMessage": "The vpc ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "19741f83-5b0f-414d-b97d-80afb52eabe5",
  "eventName": "GetSecurityGroupsForVpc",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:17Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "bf81fdf7-6c67-4814-802b-d603bc44b0f0",
  "requestParameters": {
    "GetSecurityGroupsForVpcRequest": {
      "VpcId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetSerialConsoleAccessStatus

#
Service
ec2

Description

Retrieves the access status of your account to the EC2 serial console of all instances.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "8a0e1ed4-37a2-4499-9733-a0e39174f698",
  "eventName": "GetSerialConsoleAccessStatus",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "1fa55ef6-ebdd-4399-8708-2d5b226f701b",
  "requestParameters": {
    "GetSerialConsoleAccessStatusRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetSnapshotBlockPublicAccessState

#
Service
ec2

Description

Gets the current state of block public access for snapshots setting for the account and Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "6c97b418-864d-453e-8f18-2d8da3b5fd12",
  "eventName": "GetSnapshotBlockPublicAccessState",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "8312e87a-cfde-4e00-b568-3e131d47bf8f",
  "requestParameters": {
    "GetSnapshotBlockPublicAccessStateRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetSpotPlacementScores

#
Service
ec2

Description

Calculates the Spot placement score for a Region or Availability Zone based on the specified target capacity and compute requirements.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "The request must contain either InstanceTypes or InstanceRequirements, but not both.",
  "eventCategory": "Management",
  "eventID": "dd7b9b65-b185-46bd-b019-344c1b05bc4f",
  "eventName": "GetSpotPlacementScores",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:17Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "f680b345-b516-48f6-8a63-843e5b6d05e6",
  "requestParameters": {
    "GetSpotPlacementScoresRequest": {
      "TargetCapacity": 1
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetSubnetCidrReservations

#
Service
ec2

Description

Gets information about the subnet CIDR reservations.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "Invalid value 'dw-probe' for subnetId.",
  "eventCategory": "Management",
  "eventID": "233da6a8-0353-43df-8f3f-b8714c4a41d2",
  "eventName": "GetSubnetCidrReservations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "25f42b9f-4418-4799-a131-6bd5804bc338",
  "requestParameters": {
    "GetSubnetCidrReservationsRequest": {
      "SubnetId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetTransitGatewayAttachmentPropagations

#
Service
ec2

Description

Lists the route tables to which the specified resource attachment propagates routes.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "6bb0f9c8-6b0c-4403-81a6-3dcfe145217de",
  "eventName": "GetTransitGatewayAttachmentPropagations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-05-19T17:44:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "c7784b3c-33c7-4476-88f7-63de2daa476b",
  "requestParameters": {
    "GetTransitGatewayAttachmentPropagationsRequest": {
      "TransitGatewayAttachmentId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "255.251.4.254",
  "userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

GetTransitGatewayMeteringPolicyEntries

#
Service
ec2

Description

Retrieves the entries for a transit gateway metering policy.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayMeteringPolicyIdMalformedException",
  "errorMessage": "The transit-gateway-metering-policy ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "87a4c79d-ae21-4068-9aa3-787bb24b45b0",
  "eventName": "GetTransitGatewayMeteringPolicyEntries",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "40316bed-1afc-4db3-8101-c294aabcfe60",
  "requestParameters": {
    "GetTransitGatewayMeteringPolicyEntriesRequest": {
      "TransitGatewayMeteringPolicyId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetTransitGatewayMulticastDomainAssociations

#
Service
ec2

Description

Gets information about the associations for the transit gateway multicast domain.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "7a08a086-801c-400a-9920-92ec7a0b6a33",
  "eventName": "GetTransitGatewayMulticastDomainAssociations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-05-19T17:44:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "f84ffe43-b30b-402d-98f3-2cad954190ba",
  "requestParameters": {
    "GetTransitGatewayMulticastDomainAssociationsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "255.251.4.254",
  "userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

GetTransitGatewayPolicyTableAssociations

#
Service
ec2

Description

Gets a list of the transit gateway policy table associations.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayPolicyTableId.Malformed",
  "errorMessage": "The transit-gateway-policy-table ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "63d7a1bc-de46-46f5-bbe3-1e42eacc007f",
  "eventName": "GetTransitGatewayPolicyTableAssociations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "adb43c76-258e-447a-9f8f-c68e9bbf11b5",
  "requestParameters": {
    "GetTransitGatewayPolicyTableAssociationsRequest": {
      "TransitGatewayPolicyTableId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetTransitGatewayPolicyTableEntries

#
Service
ec2

Description

Returns a list of transit gateway policy table entries.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayPolicyTableId.Malformed",
  "errorMessage": "The transit-gateway-policy-table ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "8eb1e2b1-186d-452e-8d4a-2f2e4f7d5bfe",
  "eventName": "GetTransitGatewayPolicyTableEntries",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "3f5db42d-b6d4-4c7d-a165-8e3281468ce6",
  "requestParameters": {
    "GetTransitGatewayPolicyTableEntriesRequest": {
      "TransitGatewayPolicyTableId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetTransitGatewayPrefixListReferences

#
Service
ec2

Description

Gets information about the prefix list references in a specified transit gateway route table.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "0a9ec832-e2af-4dbb-9e16-f23c80e7a373",
  "eventName": "GetTransitGatewayPrefixListReferences",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-09-21T04:27:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "76ad76e7-221e-49c6-a6d1-cd9ebbe426993",
  "requestParameters": {
    "GetTransitGatewayPrefixListReferencesRequest": {
      "TransitGatewayRouteTableId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "9.240.250.1",
  "userAgent": "Boto3/1.14.51 Python/3.8.5 Linux/4.19.76-linuxkit Botocore/1.17.51",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

GetTransitGatewayRouteTablePropagations

#
Service
ec2

Description

Gets information about the route table propagations for the specified transit gateway route table.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "9eae5a5a-5d5c-435b-82a9-b8bf0d194ff8",
  "eventName": "GetTransitGatewayRouteTablePropagations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2020-05-19T17:44:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "1dc285747-2084-4339-be75-a1b22a227785f",
  "requestParameters": {
    "GetTransitGatewayRouteTablePropagationsRequest": {
      "TransitGatewayRouteTableId": "dummy_data"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "255.251.4.254",
  "userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

GetVerifiedAccessEndpointPolicy

#
Service
ec2

Description

Get the Verified Access policy associated with the endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVerifiedAccessEndpointId.NotFound",
  "errorMessage": "VerifiedAccessEndpoint dw-probe does not exist",
  "eventCategory": "Management",
  "eventID": "abfd5096-d6b6-46ca-93dc-5687422ad972",
  "eventName": "GetVerifiedAccessEndpointPolicy",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "336fba56-08aa-4489-beb7-3379fce9c545",
  "requestParameters": {
    "GetVerifiedAccessEndpointPolicyRequest": {
      "VerifiedAccessEndpointId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetVerifiedAccessEndpointTargets

#
Service
ec2

Description

Gets the targets for the specified network CIDR endpoint for Verified Access.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVerifiedAccessEndpointId.NotFound",
  "errorMessage": "VerifiedAccessEndpoint dw-probe does not exist",
  "eventCategory": "Management",
  "eventID": "e91dd203-7eab-4621-8bfd-ab57ef2adaa6",
  "eventName": "GetVerifiedAccessEndpointTargets",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "4c409015-e9d2-415a-b2ef-1b991aa4b15c",
  "requestParameters": {
    "GetVerifiedAccessEndpointTargetsRequest": {
      "VerifiedAccessEndpointId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetVerifiedAccessGroupPolicy

#
Service
ec2

Description

Shows the contents of the Verified Access policy associated with the group.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVerifiedAccessGroupId.NotFound",
  "errorMessage": "VerifiedAccessGroup dw-probe does not exist",
  "eventCategory": "Management",
  "eventID": "a11eaecd-1a02-41b3-b29f-213f1c8f3568",
  "eventName": "GetVerifiedAccessGroupPolicy",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "8257e787-438d-43c7-bdef-b629a3dd4869",
  "requestParameters": {
    "GetVerifiedAccessGroupPolicyRequest": {
      "VerifiedAccessGroupId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetVpcResourcesBlockingEncryptionEnforcement

#
Service
ec2

Description

Gets information about resources in a VPC that are blocking encryption enforcement.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpcId.Malformed",
  "errorMessage": "The vpc ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "f85ac521-c612-4b8a-83ce-3a0caf824b95",
  "eventName": "GetVpcResourcesBlockingEncryptionEnforcement",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "bd594b0a-36a1-4eee-85c6-bca352a67d9f",
  "requestParameters": {
    "GetVpcResourcesBlockingEncryptionEnforcementRequest": {
      "VpcId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetVpnConnectionDeviceSampleConfiguration

#
Service
ec2

Description

Download an Amazon Web Services-provided sample configuration file to be used with the customer gateway device specified for your Site-to-Site VPN connection.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpnConnectionDeviceTypeId.NotFound",
  "errorMessage": "Invalid vpn connection device type id specified.",
  "eventCategory": "Management",
  "eventID": "14376254-f878-4ccb-ba18-1d361713505a",
  "eventName": "GetVpnConnectionDeviceSampleConfiguration",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "105b35e3-98f6-40a2-bcd8-e2e1d421d051",
  "requestParameters": {
    "GetVpnConnectionDeviceSampleConfigurationRequest": {
      "VpnConnectionDeviceTypeId": "dw-probe",
      "VpnConnectionId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetVpnConnectionDeviceTypes

#
Service
ec2

Description

Obtain a list of customer gateway devices for which sample configuration files can be provided.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "9aa190e0-7396-4541-b82b-d4caa88327dc",
  "eventName": "GetVpnConnectionDeviceTypes",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "64fcecb6-fd51-4b70-9d57-3deb573d05b4",
  "requestParameters": {
    "GetVpnConnectionDeviceTypesRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

GetVpnTunnelReplacementStatus

#
Service
ec2

Description

Get details of available tunnel endpoint maintenance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpnConnectionID.NotFound",
  "errorMessage": "The vpnConnection ID 'dw-probe' does not exist",
  "eventCategory": "Management",
  "eventID": "b09a1e0b-cfb7-48ee-bc77-24448292ebce",
  "eventName": "GetVpnTunnelReplacementStatus",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "6b03969e-5a56-42c0-9da3-724c83cd1893",
  "requestParameters": {
    "GetVpnTunnelReplacementStatusRequest": {
      "VpnConnectionId": "dw-probe",
      "VpnTunnelOutsideIpAddress": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ImportClientVpnClientCertificateRevocationList

#
Service
ec2

Description

Uploads a client certificate revocation list to the specified Client VPN endpoint.

ImportImage

#
Service
ec2

Description

Import single or multi-volume disk images or Amazon EBS snapshots into an Amazon Machine Image (AMI).

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
aws::errorCode (panther rule field)neClient.DryRunOperation1 rulepanther

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ImportInstance

#
Service
ec2

Description

Creates an import instance task using metadata from the specified disk image.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ImportSnapshot

#
Service
ec2

Description

Import a disk into an Amazon Elastic Block Store (Amazon EBS) snapshot.

ImportVolume

#
Service
ec2

Description

Creates an import volume task using metadata from the specified disk image.

ListImagesInRecycleBin

#
Service
ec2

Description

Lists one or more AMIs that are currently in the Recycle Bin.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "e2c1d1cb-fadb-46eb-a5d2-814137afcde4",
  "eventName": "ListImagesInRecycleBin",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "57feb0cf-94b5-452d-8e11-6fc0265101d2",
  "requestParameters": {
    "ListImagesInRecycleBinRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListSnapshotsInRecycleBin

#
Service
ec2

Description

Lists one or more snapshots that are currently in the Recycle Bin.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "079eef97-f422-4a7d-9f2c-0b9a79766434",
  "eventName": "ListSnapshotsInRecycleBin",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "c33211c9-ab85-4bdc-a027-d05e181d5623",
  "requestParameters": {
    "ListSnapshotsInRecycleBinRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListVolumesInRecycleBin

#
Service
ec2

Description

Lists one or more volumes that are currently in the Recycle Bin.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "e0d4e541-2a68-4f80-af00-123ae158081c",
  "eventName": "ListVolumesInRecycleBin",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:31:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "37af0e01-8ab9-4520-a1ae-91264a8963e1",
  "requestParameters": {
    "ListVolumesInRecycleBinRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

LockSnapshot

#
Service
ec2

Description

Locks an Amazon EBS snapshot in either governance or compliance mode to protect it against accidental or malicious deletions for a specific duration.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f79852db-0c57-4a52-8bac-ad195b623d9b",
  "eventName": "LockSnapshot",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:42:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "91315e94-65fd-47e5-a442-b3e1f0c14ec3",
  "requestParameters": {
    "LockSnapshotRequest": {
      "LockDuration": 1,
      "LockMode": "governance",
      "SnapshotId": "snap-0c0fb4e5cd0eee943"
    }
  },
  "responseElements": {
    "LockSnapshotResponse": {
      "lockCreatedOn": "2026-06-29T22:42:01.690Z",
      "lockDuration": 1,
      "lockDurationStartTime": "2026-06-29T22:42:01.690Z",
      "lockExpiresOn": "2026-06-30T22:42:01.690Z",
      "lockState": "governance",
      "requestId": "91315e94-65fd-47e5-a442-b3e1f0c14ec3",
      "snapshotId": "snap-0c0fb4e5cd0eee943",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyAddressAttribute

#
Service
ec2

Description

Modifies an attribute of the specified Elastic IP address.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidAllocationID.NotFound",
  "errorMessage": "The allocation ID 'dw-probe' does not exist",
  "eventCategory": "Management",
  "eventID": "c4279fa1-6468-4b37-b94e-d713f8fd2dfc",
  "eventName": "ModifyAddressAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ee20b5af-c3ac-4b51-b343-409b594a34c3",
  "requestParameters": {
    "ModifyAddressAttributeRequest": {
      "AllocationId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyAvailabilityZoneGroup

#
Service
ec2

Description

Changes the opt-in status of the specified zone group for your account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidAZGroup.NotFound",
  "errorMessage": "Invalid Availability Zone group provided",
  "eventCategory": "Management",
  "eventID": "33f4acca-d340-4ab2-9e52-d69259452bf2",
  "eventName": "ModifyAvailabilityZoneGroup",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:48Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c1f2a362-aeaa-410c-a9ee-0036efd8a62e",
  "requestParameters": {
    "ModifyAvailabilityZoneGroupRequest": {
      "GroupName": "dw-probe",
      "OptInStatus": "opted-in"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyCapacityReservation

#
Service
ec2

Description

Modifies a Capacity Reservation's capacity, instance eligibility, and the conditions under which it is to be released.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidCapacityReservationId.Malformed",
  "errorMessage": "Capacity Reservation ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "0ddd927b-1882-4e2e-b05b-d4453970827b",
  "eventName": "ModifyCapacityReservation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b3c4ce0a-8102-4cb4-93b9-6034d6e1b69a",
  "requestParameters": {
    "ModifyCapacityReservationRequest": {
      "CapacityReservationId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyCapacityReservationFleet

#
Service
ec2

Description

Modifies a Capacity Reservation Fleet.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidCapacityReservationFleetId.Malformed",
  "errorMessage": "The capacity-reservation-fleet ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "628aac8c-1318-48f8-b6a1-9d34d90b147e",
  "eventName": "ModifyCapacityReservationFleet",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "68e7f3fc-ba7f-47dc-b6a4-e7b0aa8498f7",
  "requestParameters": {
    "ModifyCapacityReservationFleetRequest": {
      "CapacityReservationFleetId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyClientVpnEndpoint

#
Service
ec2

Description

Modifies the specified Client VPN endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidClientVpnEndpointId.NotFound",
  "errorMessage": "The client-vpn-endpoint ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "abe430e5-52ef-4df6-bb4a-6da3ee4f3028",
  "eventName": "ModifyClientVpnEndpoint",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "bbef9c62-f40c-4579-ad7d-5f1313b3c519",
  "requestParameters": {
    "ModifyClientVpnEndpointRequest": {
      "ClientVpnEndpointId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyDefaultCreditSpecification

#
Service
ec2

Description

Modifies the default credit option for CPU usage of burstable performance instances.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "The CpuCredits parameter requires a value of either Standard or Unlimited. Change the value and try again.",
  "eventCategory": "Management",
  "eventID": "4ab56216-ec4c-4542-993f-862d11e14ca5",
  "eventName": "ModifyDefaultCreditSpecification",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:49Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4ac57f66-bce1-4656-823e-4f81f5a072e4",
  "requestParameters": {
    "ModifyDefaultCreditSpecificationRequest": {
      "CpuCredits": "dw-probe",
      "InstanceFamily": "t2"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyEbsDefaultKmsKeyId

#
Service
ec2

Description

Changes the default KMS key for EBS encryption by default for your account in this Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "Invalid keyId 'dw-probe'",
  "eventCategory": "Management",
  "eventID": "a367bf43-a953-4611-a133-75e3ba12ef32",
  "eventName": "ModifyEbsDefaultKmsKeyId",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e3f5c9ee-b251-4a0c-96e1-571795ca8c8a",
  "requestParameters": {
    "ModifyEbsDefaultKmsKeyIdRequest": {
      "KmsKeyId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyFleet

#
Service
ec2

Description

Modifies the specified EC2 Fleet.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidFleetId.Malformed",
  "errorMessage": "Provided Fleet Id Malformed",
  "eventCategory": "Management",
  "eventID": "da4df8df-f8be-45aa-a25e-d57918caa683",
  "eventName": "ModifyFleet",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6ab2f13c-4b60-4a41-89f9-1a665398c0dd",
  "requestParameters": {
    "ModifyFleetRequest": {
      "FleetId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyFpgaImageAttribute

#
Service
ec2

Description

Modifies the specified attribute of the specified Amazon FPGA Image (AFI).

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.UnsupportedOperation",
  "errorMessage": "The functionality you requested is not available in this region.",
  "eventCategory": "Management",
  "eventID": "95c5fee5-8e25-42fa-b9ea-5c2e0101e648",
  "eventName": "ModifyFpgaImageAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d39f3e02-6cfa-463c-8115-a345bf92b6ca",
  "requestParameters": {
    "ModifyFpgaImageAttributeRequest": {
      "FpgaImageId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyHosts

#
Service
ec2

Description

Modify the auto-placement setting of a Dedicated host.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f330d400-fd0a-4d79-969d-e54dae101c1e",
  "eventName": "ModifyHosts",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d6574d82-79ba-4a03-b3d3-5fd84bc5531b",
  "requestParameters": {
    "ModifyHostsRequest": {
      "HostId": {
        "content": "dw-probe",
        "tag": 1
      }
    }
  },
  "responseElements": {
    "ModifyHostsResponse": {
      "requestId": "d6574d82-79ba-4a03-b3d3-5fd84bc5531b",
      "successful": "",
      "unsuccessful": {
        "item": {
          "error": {
            "code": "Client.InvalidHostID.Malformed",
            "message": "The specified Dedicated host IDs ['dw-probe'] are not valid."
          },
          "resourceId": "dw-probe"
        }
      },
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyIdentityIdFormat

#
Service
ec2

Description

Modifies the ID format of a resource for a specified IAM user, IAM role, or the root user for an account; or all IAM users, IAM roles, and the root user for an account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "b6018819-d387-43d2-9dca-f86435142d20",
  "eventName": "ModifyIdentityIdFormat",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "635ea9a5-8617-4050-a1a8-e22c893ed898",
  "requestParameters": {
    "ModifyIdentityIdFormatRequest": {
      "PrincipalArn": "dw-probe",
      "Resource": "dw-probe",
      "UseLongIds": false
    }
  },
  "responseElements": {
    "ModifyIdentityIdFormatResponse": {
      "requestId": "635ea9a5-8617-4050-a1a8-e22c893ed898",
      "return": true,
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyIdFormat

#
Service
ec2

Description

Modifies the ID format for the specified resource on a per-region basis.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "bbedb9d1-b916-4b3d-b14f-c5a7582b6006",
  "eventName": "ModifyIdFormat",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "dde49649-0a4b-498e-846c-10aeaf1899da",
  "requestParameters": {
    "resource": "dw-probe",
    "useLongIds": false
  },
  "responseElements": {
    "_return": true,
    "requestId": "dde49649-0a4b-498e-846c-10aeaf1899da"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyInstanceCapacityReservationAttributes

#
Service
ec2

Description

Modifies the Capacity Reservation settings for a stopped instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "Required field \"instance-id\" missing or malformed.",
  "eventCategory": "Management",
  "eventID": "0ab69c83-423a-4f0b-89eb-3b5d0cadd9a1",
  "eventName": "ModifyInstanceCapacityReservationAttributes",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e062c873-5dd9-44e2-a06b-7e013de988a6",
  "requestParameters": {
    "ModifyInstanceCapacityReservationAttributesRequest": {
      "InstanceId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ModifyInstanceConnectEndpoint

#
Service
ec2

Description

Modifies the specified EC2 Instance Connect Endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidInstanceConnectEndpointId.Malformed",
  "errorMessage": "The instance-connect-endpoint ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "b316e87c-8143-48d0-9afe-79b4693f4eed",
  "eventName": "ModifyInstanceConnectEndpoint",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:50Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2422a05e-c772-468d-9908-2f5f58702b2e",
  "requestParameters": {
    "ModifyInstanceConnectEndpointRequest": {
      "InstanceConnectEndpointId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyInstanceCpuOptions

#
Service
ec2

Description

By default, all vCPUs for the instance type are active when you launch an instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidInstanceID.Malformed",
  "errorMessage": "The instance ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "cae2ee33-1864-4d51-b7f9-7a2f242012d1",
  "eventName": "ModifyInstanceCpuOptions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2dac5ac6-6db4-49c1-8d2b-7bacd890421f",
  "requestParameters": {
    "ModifyInstanceCpuOptionsRequest": {
      "InstanceId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyInstanceCreditSpecification

#
Service
ec2

Description

Modifies the credit option for CPU usage on a running or stopped burstable performance instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidInstanceID.Malformed",
  "errorMessage": "The instance ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "e2edb421-bec6-429a-a8f4-37f14c8ee6b9",
  "eventName": "ModifyInstanceCreditSpecification",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "fe2c798d-5421-40a3-9f8a-94929e72eefd",
  "requestParameters": {
    "ModifyInstanceCreditSpecificationRequest": {
      "InstanceCreditSpecification": {
        "InstanceId": "dw-probe",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ModifyInstanceEventStartTime

#
Service
ec2

Description

Modifies the start time for a scheduled Amazon EC2 instance event.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidInstanceID.Malformed",
  "errorMessage": "The instance ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "0235115e-533b-441b-8a79-2123efa16af9",
  "eventName": "ModifyInstanceEventStartTime",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:51Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "783a6804-7784-4689-aab7-3ac84cfde418",
  "requestParameters": {
    "ModifyInstanceEventStartTimeRequest": {
      "InstanceEventId": "dw-probe",
      "InstanceId": "dw-probe",
      "NotBefore": "2020-01-01T00:00:00Z"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ModifyInstanceEventWindow

#
Service
ec2

Description

Modifies the specified event window.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidInstanceEventWindowId.Malformed",
  "errorMessage": "The instance-event-window ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "43225947-9121-4b2c-9cb0-d68a5afe0b1c",
  "eventName": "ModifyInstanceEventWindow",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a009c721-6630-4efd-9b0d-b9e7791dc996",
  "requestParameters": {
    "ModifyInstanceEventWindowRequest": {
      "InstanceEventWindowId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ModifyInstanceMaintenanceOptions

#
Service
ec2

Description

Modifies the recovery behavior of your instance to disable simplified automatic recovery or set the recovery behavior to default.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidInstanceID.Malformed",
  "errorMessage": "The instance ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "ad7f3182-169e-43dc-add3-3865a8142477",
  "eventName": "ModifyInstanceMaintenanceOptions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "eef1f3a4-c07f-42e7-befc-70b01bbfd675",
  "requestParameters": {
    "ModifyInstanceMaintenanceOptionsRequest": {
      "InstanceId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ModifyInstanceMetadataDefaults

#
Service
ec2

Description

Modifies the default instance metadata service (IMDS) settings at the account level in the specified Amazon Web Services Region.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "d97d67d6-ee8a-42a0-a5ed-284d93706aa7",
  "eventName": "ModifyInstanceMetadataDefaults",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:40:26Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8a67a582-c580-4d79-90b2-c353afafbb44",
  "requestParameters": {
    "ModifyInstanceMetadataDefaultsRequest": {
      "HttpEndpoint": "enabled",
      "HttpTokens": "optional",
      "InstanceMetadataTags": "disabled"
    }
  },
  "responseElements": {
    "ModifyInstanceMetadataDefaultsResponse": {
      "requestId": "8a67a582-c580-4d79-90b2-c353afafbb44",
      "return": true,
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyInstanceMetadataOptions

#
Service
ec2

Description

Modify the instance metadata parameters on a running or stopped instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidInstanceID.Malformed",
  "errorMessage": "The instance ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "28065793-2eff-4e65-b150-de60c4e53dab",
  "eventName": "ModifyInstanceMetadataOptions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b35a3525-78e7-4484-b15c-1a6228a9f256",
  "requestParameters": {
    "ModifyInstanceMetadataOptionsRequest": {
      "InstanceId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ModifyInstanceNetworkPerformanceOptions

#
Service
ec2

Description

Change the configuration of the network performance options for an existing instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidInstanceID.Malformed",
  "errorMessage": "The instance ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "6defc50a-8083-4425-bdb2-362fad475636",
  "eventName": "ModifyInstanceNetworkPerformanceOptions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:53Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c938a197-41b6-4ac6-a7aa-347448a7fa52",
  "requestParameters": {
    "ModifyInstanceNetworkPerformanceOptionsRequest": {
      "BandwidthWeighting": "default",
      "InstanceId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyInstancePlacement

#
Service
ec2

Description

Set the instance affinity value for a specific stopped instance and modify the instance tenancy setting.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidInstanceID.Malformed",
  "errorMessage": "The given virtId: dw-probe is not valid",
  "eventCategory": "Management",
  "eventID": "4fae0b9f-62ef-4ec3-9584-6c24895abe47",
  "eventName": "ModifyInstancePlacement",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:53Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "32f4f45f-13b5-4912-8f68-7e853b2a908a",
  "requestParameters": {
    "ModifyInstancePlacementRequest": {
      "InstanceId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ModifyIpam

#
Service
ec2

Description

Modify the configurations of an IPAM.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamId.Malformed",
  "errorMessage": "The specified IPAM Id is not valid. Specify an IPAM Id in the form ipam-xxxxxxxxxxxxxxxxx.",
  "eventCategory": "Management",
  "eventID": "7db95047-3d8d-40b3-8a85-b3aa13f2b57e",
  "eventName": "ModifyIpam",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:53Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5bf02d1f-cecb-4f5f-9936-6b42e88fb7d9",
  "requestParameters": {
    "ModifyIpamRequest": {
      "IpamId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyIpamPolicyAllocationRules

#
Service
ec2

Description

Modifies the allocation rules in an IPAM policy.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamPolicyId.Malformed",
  "errorMessage": "The ipam-policy ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "6057eb31-ab32-402e-883f-e34bb146983c",
  "eventName": "ModifyIpamPolicyAllocationRules",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "97ea21fd-7dae-4424-9bdd-e458ab9b7252",
  "requestParameters": {
    "ModifyIpamPolicyAllocationRulesRequest": {
      "IpamPolicyId": "dw-probe",
      "Locale": "dw-probe",
      "ResourceType": "alb"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyIpamPool

#
Service
ec2

Description

Modify the configurations of an IPAM pool.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamPoolId.Malformed",
  "errorMessage": "The specified IPAM pool ID is not valid. Specify an IPAM pool ID in the form ipam-pool-xxxxxxxxxxxxxxxxx.",
  "eventCategory": "Management",
  "eventID": "48389a1a-3dfd-4609-88af-1f3ebd19e941",
  "eventName": "ModifyIpamPool",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8420e9c8-a8ec-4655-ba71-b350e6b3e191",
  "requestParameters": {
    "ModifyIpamPoolRequest": {
      "IpamPoolId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyIpamPoolAllocation

#
Service
ec2

Description

Modifies the description of an IPAM pool allocation.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamPoolAllocationId.Malformed",
  "errorMessage": "The ipam-pool-allocation ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "04547ae5-655d-45c0-8e1d-ec7a8c5fc2f1",
  "eventName": "ModifyIpamPoolAllocation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e1ab85d4-8e73-4ad3-8e4b-c299b953fb50",
  "requestParameters": {
    "ModifyIpamPoolAllocationRequest": {
      "IpamPoolAllocationId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyIpamPrefixListResolver

#
Service
ec2

Description

Modifies an IPAM prefix list resolver.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamPrefixListResolverId.Malformed",
  "errorMessage": "The ipam-prefix-list-resolver ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "764ff86b-9f4d-453d-a9bd-67c6dc548f23",
  "eventName": "ModifyIpamPrefixListResolver",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "09685d86-c1da-4a95-a446-3c8b20453681",
  "requestParameters": {
    "ModifyIpamPrefixListResolverRequest": {
      "IpamPrefixListResolverId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyIpamPrefixListResolverTarget

#
Service
ec2

Description

Modifies an IPAM prefix list resolver target.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamPrefixListResolverTargetId.Malformed",
  "errorMessage": "The ipam-prefix-list-resolver-target ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "e5c9025b-4fd0-47c5-aaf2-a19098542f42",
  "eventName": "ModifyIpamPrefixListResolverTarget",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "28b81725-91da-4e45-92f6-cada18431f6f",
  "requestParameters": {
    "ModifyIpamPrefixListResolverTargetRequest": {
      "ClientToken": "f69d0826-27af-44a1-b04b-62dc8a4476f3",
      "IpamPrefixListResolverTargetId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyIpamResourceCidr

#
Service
ec2

Description

Modify a resource CIDR.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamScopeId.Malformed",
  "errorMessage": "The ipam-scope ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "359cd2bd-3de5-4d05-b5fd-b718d812a2f1",
  "eventName": "ModifyIpamResourceCidr",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6d66a53d-12fc-4a67-9164-333a451ace0e",
  "requestParameters": {
    "ModifyIpamResourceCidrRequest": {
      "CurrentIpamScopeId": "dw-probe",
      "Monitored": false,
      "ResourceCidr": "dw-probe",
      "ResourceId": "dw-probe",
      "ResourceRegion": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyIpamResourceDiscovery

#
Service
ec2

Description

Modifies a resource discovery.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamResourceDiscoveryId.Malformed",
  "errorMessage": "The specified IPAM resource discovery ID is not valid. Specify an IPAM resource discovery ID in the form ipam-res-disco-xxxxxxxxxxxxxxxxx.",
  "eventCategory": "Management",
  "eventID": "c7333481-6948-4dc8-bb18-eb4ab4a8abd3",
  "eventName": "ModifyIpamResourceDiscovery",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "eb6e12e6-e5eb-4111-a11d-99b471a26fe8",
  "requestParameters": {
    "ModifyIpamResourceDiscoveryRequest": {
      "IpamResourceDiscoveryId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyIpamScope

#
Service
ec2

Description

Modify an IPAM scope.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamScopeId.Malformed",
  "errorMessage": "The specified IPAM scope ID is not valid. Specify an IPAM scope ID in the form ipam-scope-xxxxxxxxxxxxxxxxx.",
  "eventCategory": "Management",
  "eventID": "f14b69c5-5fc4-49f5-a34a-700c77ca05a1",
  "eventName": "ModifyIpamScope",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d1c458aa-b130-475e-bd05-849e0db6db66",
  "requestParameters": {
    "ModifyIpamScopeRequest": {
      "IpamScopeId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyLaunchTemplate

#
Service
ec2

Description

Modifies a launch template.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "89ad7824-5ba4-420d-87c9-bcb42944f32d",
  "eventName": "ModifyLaunchTemplate",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:59:23Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0cf3ea49-eb3f-4135-b0d3-ed0d013d82b3",
  "requestParameters": {
    "ModifyLaunchTemplateRequest": {
      "ClientToken": "aaf53eb7-d047-4886-8196-a7045aab3688",
      "LaunchTemplateId": "lt-0e15e74d047fa83a3",
      "SetDefaultVersion": 1
    }
  },
  "responseElements": {
    "ModifyLaunchTemplateResponse": {
      "launchTemplate": {
        "createTime": "1970-01-01T00:00:00.000Z",
        "createdBy": "arn:aws:iam::123456789012:user/sample-user",
        "defaultVersionNumber": 1,
        "latestVersionNumber": 2,
        "launchTemplateId": "lt-0e15e74d047fa83a3",
        "launchTemplateName": "dwfix-lt",
        "operator": {
          "managed": false
        }
      },
      "requestId": "0cf3ea49-eb3f-4135-b0d3-ed0d013d82b3",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyLocalGatewayRoute

#
Service
ec2

Description

Modifies the specified local gateway route.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidLocalGatewayRouteTableID.Malformed",
  "errorMessage": "Invalid LocalGateway Route Table id dw-probe",
  "eventCategory": "Management",
  "eventID": "f75e0318-c1e2-4b87-896b-f60fa35cdc96",
  "eventName": "ModifyLocalGatewayRoute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "b358cf9c-293a-45b9-98a0-13c6d8193379",
  "requestParameters": {
    "ModifyLocalGatewayRouteRequest": {
      "LocalGatewayRouteTableId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyManagedPrefixList

#
Service
ec2

Description

Modifies the specified managed prefix list.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidPrefixListId.Malformed",
  "errorMessage": "The prefix-list ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "ad4d12a1-873b-4482-a19a-118f5c90b741",
  "eventName": "ModifyManagedPrefixList",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "dd33ad26-e997-4ce1-81da-74a899bff550",
  "requestParameters": {
    "ModifyManagedPrefixListRequest": {
      "PrefixListId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyManagedResourceVisibility

#
Service
ec2

Description

Modifies the managed resource visibility configuration for the account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "9af05b60-902b-4302-a677-2f98e4f5d11a",
  "eventName": "ModifyManagedResourceVisibility",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e7debbd9-ca51-4dca-bf39-2f058e1cd79e",
  "requestParameters": {
    "ModifyManagedResourceVisibilityRequest": {
      "DefaultVisibility": "hidden"
    }
  },
  "responseElements": {
    "ModifyManagedResourceVisibilityResponse": {
      "requestId": "e7debbd9-ca51-4dca-bf39-2f058e1cd79e",
      "visibility": {
        "defaultVisibility": "hidden"
      },
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyNetworkInterfaceAttribute

#
Service
ec2

Description

Modifies the specified network interface attribute.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidNetworkInterfaceId.Malformed",
  "errorMessage": "Invalid id: \"dw-probe\" (expecting \"eni-...\")",
  "eventCategory": "Management",
  "eventID": "144e63fb-e45a-4695-b9fd-f245fb822470",
  "eventName": "ModifyNetworkInterfaceAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "85f4ac78-2955-44b4-aadc-422228309da0",
  "requestParameters": {
    "networkInterfaceId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyPrivateDnsNameOptions

#
Service
ec2

Description

Modifies the options for instance hostnames for the specified instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.UnknownResource",
  "errorMessage": "User (123456789012) does not own a resource dw-probe .",
  "eventCategory": "Management",
  "eventID": "cb61fed4-0623-490a-b39d-a2fbe0e8eb4e",
  "eventName": "ModifyPrivateDnsNameOptions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:56Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "fbaf5f9a-82b3-4846-a283-3a3dcccf7232",
  "requestParameters": {
    "ModifyPrivateDnsNameOptionsRequest": {
      "InstanceId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyPublicIpDnsNameOptions

#
Service
ec2

Description

Modify public hostname options for a network interface.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidNetworkInterfaceId.Malformed",
  "errorMessage": "The network-interface ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "ca3959e0-40d5-45ff-b8f9-04bf4c67abe6",
  "eventName": "ModifyPublicIpDnsNameOptions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cc1d40bc-f00f-4fe0-802d-86b3d1f76ffc",
  "requestParameters": {
    "ModifyPublicIpDnsNameOptionsRequest": {
      "HostnameType": "public-dual-stack-dns-name",
      "NetworkInterfaceId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyReservedInstances

#
Service
ec2

Description

Modifies the Availability Zone, instance count, instance type, or network platform (EC2-Classic or EC2-VPC) of your Reserved Instances.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "Invalid value 'dw-probe' for ReservedInstancesId.",
  "eventCategory": "Management",
  "eventID": "ed846192-e56b-4846-a138-8d682ae43395",
  "eventName": "ModifyReservedInstances",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "73ce093d-a65d-46a6-bcca-923edfed251f",
  "requestParameters": {
    "reservedInstancesSet": {
      "items": [
        {
          "reservedInstancesId": "dw-probe"
        }
      ]
    },
    "targetConfigurationSet": {}
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyRouteServer

#
Service
ec2

Description

Modifies the configuration of an existing route server.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRouteServerId.Malformed",
  "errorMessage": "The route-server ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "605f3046-9b2d-4d2a-a5d0-21de8d12c58d",
  "eventName": "ModifyRouteServer",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6cb127be-9dfe-44b2-934d-e89cb9a05848",
  "requestParameters": {
    "ModifyRouteServerRequest": {
      "RouteServerId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifySnapshotTier

#
Service
ec2

Description

Archives an Amazon EBS snapshot.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "Value (dw-probe) for parameter snapshotId is invalid.",
  "eventCategory": "Management",
  "eventID": "b687ab62-3f09-4da6-a11d-062d618905bb",
  "eventName": "ModifySnapshotTier",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7b0d0787-47be-4af0-97fc-75f2480a8653",
  "requestParameters": {
    "ModifySnapshotTierRequest": {
      "SnapshotId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifySpotFleetRequest

#
Service
ec2

Description

Modifies the specified Spot fleet request.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "1 validation error detected: Value 'dw-probe' at 'spotFleetRequestId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^(sfr|fleet)-[a-z0-9-]{36}\\b",
  "eventCategory": "Management",
  "eventID": "a635fe1c-e64c-453c-9062-1fc0bdf886ea",
  "eventName": "ModifySpotFleetRequest",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "88e90951-53ea-4179-b991-e97bbcc722d8",
  "requestParameters": {
    "ModifySpotFleetRequestRequest": {
      "SpotFleetRequestId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifySubnetAttribute

#
Service
ec2

Description

Modifies a subnet attribute.

Example CloudTrail Event #

{
  "awsRegion": "eu-central-1",
  "eventCategory": "Management",
  "eventID": "3729db59-9c67-4575-b459-469159529934",
  "eventName": "ModifySubnetAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-01-12T08:23:55Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "111111111111",
  "requestID": "288dc4d2-ad01-4f99-affd-306a6713724a",
  "requestParameters": {
    "mapPublicIpOnLaunch": {
      "value": true
    },
    "subnetId": "subnet-0b7135186b73850ed"
  },
  "responseElements": {
    "_return": true,
    "requestId": "288dc4d2-ad01-4f99-affd-306a6713724a"
  },
  "sourceIPAddress": "95.90.199.65",
  "userAgent": "aws-sdk-go/1.36.19 (go1.15.5; darwin; amd64) APN/1.0 HashiCorp/1.0 Terraform/0.14.4 (+https://www.terraform.io)",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E",
    "accountId": "111111111111",
    "arn": "arn:aws:iam::111111111111:user/patrick_cli",
    "principalId": "AIDAYTOGP2RLNALZHZ6KX",
    "type": "IAMUser",
    "userName": "patrick_cli"
  }
}

References #

ModifyTrafficMirrorFilterNetworkServices

#
Service
ec2

Description

Allows or restricts mirroring network services.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTrafficMirrorFilterId.NotFound",
  "errorMessage": "The traffic-mirror-filter ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "c1631c9a-b583-43e5-86a5-889ddcca6097",
  "eventName": "ModifyTrafficMirrorFilterNetworkServices",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d128e4e9-9be7-405f-bb48-b98d9a180bd6",
  "requestParameters": {
    "ModifyTrafficMirrorFilterNetworkServicesRequest": {
      "TrafficMirrorFilterId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ModifyTrafficMirrorFilterRule

#
Service
ec2

Description

Modifies the specified Traffic Mirror rule.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "Invalid ID: dw-probe. Filter rule ID must be 21 characters!",
  "eventCategory": "Management",
  "eventID": "23290aeb-a6c1-4ff2-aab8-c7a0ee58d711",
  "eventName": "ModifyTrafficMirrorFilterRule",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "da81aad2-dfc6-4290-bc12-106768150b66",
  "requestParameters": {
    "ModifyTrafficMirrorFilterRuleRequest": {
      "TrafficMirrorFilterRuleId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ModifyTrafficMirrorSession

#
Service
ec2

Description

Modifies a Traffic Mirror session.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "Invalid ID: dw-probe",
  "eventCategory": "Management",
  "eventID": "199e2f20-1d71-4ca6-8631-f0e37d29c640",
  "eventName": "ModifyTrafficMirrorSession",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "dc83bab4-482e-4a03-bbec-7fd434679e24",
  "requestParameters": {
    "ModifyTrafficMirrorSessionRequest": {
      "TrafficMirrorSessionId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ModifyTransitGateway

#
Service
ec2

Description

Modifies the specified transit gateway.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayID.Malformed",
  "errorMessage": "The transit-gateway ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "b5f51599-2228-44bb-a26c-42df098ed306",
  "eventName": "ModifyTransitGateway",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a313fe15-b8f7-4ca3-aad4-4d8b50b72b65",
  "requestParameters": {
    "ModifyTransitGatewayRequest": {
      "TransitGatewayId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyTransitGatewayMeteringPolicy

#
Service
ec2

Description

Modifies a transit gateway metering policy.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayMeteringPolicyIdMalformedException",
  "errorMessage": "The transit-gateway-metering-policy ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "fb699eed-5dc7-4e35-8f13-52d79779aae0",
  "eventName": "ModifyTransitGatewayMeteringPolicy",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "48d4f159-554a-4fd7-8c56-f9d751fe9a93",
  "requestParameters": {
    "ModifyTransitGatewayMeteringPolicyRequest": {
      "TransitGatewayMeteringPolicyId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyTransitGatewayPrefixListReference

#
Service
ec2

Description

Modifies a reference (route) to a prefix list in a specified transit gateway route table.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRouteTableId.Malformed",
  "errorMessage": "Invalid Transit Gateway Route Table id dw-probe.",
  "eventCategory": "Management",
  "eventID": "2c937f57-d884-44d9-8602-a486d6f6fbf7",
  "eventName": "ModifyTransitGatewayPrefixListReference",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8ce310d5-c7ea-4fb6-866a-976298883b18",
  "requestParameters": {
    "ModifyTransitGatewayPrefixListReferenceRequest": {
      "PrefixListId": "dw-probe",
      "TransitGatewayRouteTableId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyTransitGatewayVpcAttachment

#
Service
ec2

Description

Modifies the specified VPC attachment.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayAttachmentID.Malformed",
  "errorMessage": "Invalid Transit Gateway Attachment id.",
  "eventCategory": "Management",
  "eventID": "1fc6c2fa-cfbb-4761-9705-c621bf0f9532",
  "eventName": "ModifyTransitGatewayVpcAttachment",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3a61e488-e27b-4eb9-a1ca-841f14d90b7a",
  "requestParameters": {
    "ModifyTransitGatewayVpcAttachmentRequest": {
      "TransitGatewayAttachmentId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVerifiedAccessEndpoint

#
Service
ec2

Description

Modifies the configuration of the specified Amazon Web Services Verified Access endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVerifiedAccessEndpointId.NotFound",
  "errorMessage": "VerifiedAccessEndpoint dw-probe does not exist",
  "eventCategory": "Management",
  "eventID": "942830f7-fe9a-4d53-9f50-778d1c56fb24",
  "eventName": "ModifyVerifiedAccessEndpoint",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:22:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5299a833-25f4-41f9-be29-0df160ff4617",
  "requestParameters": {
    "ModifyVerifiedAccessEndpointRequest": {
      "ClientToken": "f357b3d2-89a6-4a2e-940d-7a2b609e031b",
      "VerifiedAccessEndpointId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVerifiedAccessEndpointPolicy

#
Service
ec2

Description

Modifies the specified Amazon Web Services Verified Access endpoint policy.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVerifiedAccessEndpointId.NotFound",
  "errorMessage": "VerifiedAccessEndpoint dw-probe does not exist",
  "eventCategory": "Management",
  "eventID": "f95e350e-0c16-4f97-a824-b59217eece22",
  "eventName": "ModifyVerifiedAccessEndpointPolicy",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0a96cd63-5b0e-49ed-8c97-b1e3ca094175",
  "requestParameters": {
    "ModifyVerifiedAccessEndpointPolicyRequest": {
      "ClientToken": "211c7b52-5704-42bd-b6a1-ffd177cff40c",
      "VerifiedAccessEndpointId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVerifiedAccessGroup

#
Service
ec2

Description

Modifies the specified Amazon Web Services Verified Access group configuration.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVerifiedAccessGroupId.NotFound",
  "errorMessage": "VerifiedAccessGroup dw-probe does not exist",
  "eventCategory": "Management",
  "eventID": "ee6e4f70-ccc9-480a-84ed-b36d0a30727d",
  "eventName": "ModifyVerifiedAccessGroup",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d3184b3f-da51-4aab-abbf-23de854d269c",
  "requestParameters": {
    "ModifyVerifiedAccessGroupRequest": {
      "ClientToken": "406000c4-a073-4acc-ba04-1a3b899074e5",
      "VerifiedAccessGroupId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVerifiedAccessGroupPolicy

#
Service
ec2

Description

Modifies the specified Amazon Web Services Verified Access group policy.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVerifiedAccessGroupId.NotFound",
  "errorMessage": "VerifiedAccessGroup dw-probe does not exist",
  "eventCategory": "Management",
  "eventID": "6e5ac594-1794-43f0-849c-0101389e8de7",
  "eventName": "ModifyVerifiedAccessGroupPolicy",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:00Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6fdc429a-6aa3-4c78-b85b-cf6789fcf944",
  "requestParameters": {
    "ModifyVerifiedAccessGroupPolicyRequest": {
      "ClientToken": "5dc5b740-1a8a-4f4e-87da-59ccc3dfa9ad",
      "VerifiedAccessGroupId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVerifiedAccessInstance

#
Service
ec2

Description

Modifies the configuration of the specified Amazon Web Services Verified Access instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVerifiedAccessInstanceId.NotFound",
  "errorMessage": "VerifiedAccessInstance dw-probe does not exist",
  "eventCategory": "Management",
  "eventID": "9d1e2e45-b658-4d19-9fb6-98261a958825",
  "eventName": "ModifyVerifiedAccessInstance",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "156cc931-574d-4051-bd34-b5ca7d720834",
  "requestParameters": {
    "ModifyVerifiedAccessInstanceRequest": {
      "ClientToken": "660a53b7-3852-4e28-9f9c-4aeb94abefd0",
      "VerifiedAccessInstanceId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVerifiedAccessInstanceLoggingConfiguration

#
Service
ec2

Description

Modifies the logging configuration for the specified Amazon Web Services Verified Access instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "The request must include the AccessLogs parameter. Add the required parameter and retry the request.",
  "eventCategory": "Management",
  "eventID": "64abdd3d-c074-4689-a02c-508a50e0715c",
  "eventName": "ModifyVerifiedAccessInstanceLoggingConfiguration",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c7a896fb-e8fd-4833-a4c6-f6d190aa3e9e",
  "requestParameters": {
    "ModifyVerifiedAccessInstanceLoggingConfigurationRequest": {
      "ClientToken": "29558dd6-3e38-4741-a874-ddf330827ac2",
      "VerifiedAccessInstanceId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVerifiedAccessTrustProvider

#
Service
ec2

Description

Modifies the configuration of the specified Amazon Web Services Verified Access trust provider.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVerifiedAccessTrustProviderId.NotFound",
  "errorMessage": "VerifiedAccessTrustProvider dw-probe does not exist",
  "eventCategory": "Management",
  "eventID": "d6f05df2-de74-45df-aa1b-7525806cc1f0",
  "eventName": "ModifyVerifiedAccessTrustProvider",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "be94e0ab-ba97-4994-971c-2a48bbb0ba3d",
  "requestParameters": {
    "ModifyVerifiedAccessTrustProviderRequest": {
      "ClientToken": "14541c05-dd2f-4169-b750-b36c66a82b2a",
      "VerifiedAccessTrustProviderId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVolume

#
Service
ec2

Description

You can modify several parameters of an existing EBS volume, including volume size, volume type, and IOPS capacity.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "Value (dw-probe) for parameter volumeId is invalid. Expected: 'vol-...'.",
  "eventCategory": "Management",
  "eventID": "bfade3d0-436f-48cc-bfd2-968156ba8816",
  "eventName": "ModifyVolume",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c849979b-6ef3-4a82-a580-95c122b9b5a3",
  "requestParameters": {
    "ModifyVolumeRequest": {
      "VolumeId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVolumeAttribute

#
Service
ec2

Description

Modifies a volume attribute.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVolumeID.Malformed",
  "errorMessage": "The volume ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "9c9e9d71-84e0-4da7-82ad-2fc04b79a952",
  "eventName": "ModifyVolumeAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "2464768a-f319-44f2-9939-72d5c9f6fab6",
  "requestParameters": {
    "volumeId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVpcAttribute

#
Service
ec2

Description

Modifies the specified attribute of the specified VPC.

Example CloudTrail Event #

{
  "awsRegion": "eu-central-1",
  "eventCategory": "Management",
  "eventID": "c4fab597-8681-4053-854d-52a9e4203180",
  "eventName": "ModifyVpcAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-01-12T08:23:38Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "111111111111",
  "requestID": "a7d9d49e-839c-476b-bd1b-7732f4c4ca4e",
  "requestParameters": {
    "enableDnsHostnames": {
      "value": true
    },
    "vpcId": "vpc-0cba59db5968227e2"
  },
  "responseElements": {
    "_return": true,
    "requestId": "a7d9d49e-839c-476b-bd1b-7732f4c4ca4e"
  },
  "sourceIPAddress": "95.90.199.65",
  "userAgent": "aws-sdk-go/1.36.19 (go1.15.5; darwin; amd64) APN/1.0 HashiCorp/1.0 Terraform/0.14.4 (+https://www.terraform.io)",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E",
    "accountId": "111111111111",
    "arn": "arn:aws:iam::111111111111:user/patrick_cli",
    "principalId": "AIDAYTOGP2RLNALZHZ6KX",
    "type": "IAMUser",
    "userName": "patrick_cli"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

ModifyVpcBlockPublicAccessExclusion

#
Service
ec2

Description

Modify VPC Block Public Access (BPA) exclusions.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.VpcBlockPublicAccessExclusionId.Malformed",
  "errorMessage": "The vpc-block-public-access-exclusion ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "b44bfd50-7203-4ce7-b184-13c5acf913f2",
  "eventName": "ModifyVpcBlockPublicAccessExclusion",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a27599de-17e3-48c9-aa70-7bc68bf903b8",
  "requestParameters": {
    "ModifyVpcBlockPublicAccessExclusionRequest": {
      "ExclusionId": "dw-probe",
      "InternetGatewayExclusionMode": "allow-bidirectional"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVpcBlockPublicAccessOptions

#
Service
ec2

Description

Modify VPC Block Public Access (BPA) options.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "9900fd1f-4201-46d2-a89a-a56584a75a2d",
  "eventName": "ModifyVpcBlockPublicAccessOptions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f607c613-50c1-4e64-879d-5dba99d957b4",
  "requestParameters": {
    "ModifyVpcBlockPublicAccessOptionsRequest": {
      "InternetGatewayBlockMode": "off"
    }
  },
  "responseElements": {
    "ModifyVpcBlockPublicAccessOptionsResponse": {
      "requestId": "f607c613-50c1-4e64-879d-5dba99d957b4",
      "vpcBlockPublicAccessOptions": {
        "awsAccountId": "123456789012",
        "awsRegion": "us-west-1",
        "exclusionsAllowed": "allowed",
        "internetGatewayBlockMode": "off",
        "managedBy": "account",
        "reason": "Default State",
        "state": "default-state"
      },
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVpcEncryptionControl

#
Service
ec2

Description

Modifies the encryption control configuration for a VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpcEncryptionControlId.Malformed",
  "errorMessage": "The vpc-encryption-control ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "1fba7331-9301-400b-8053-fc6fe6b5b236",
  "eventName": "ModifyVpcEncryptionControl",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3e4e6618-cb53-48fb-8036-c431b099d8ce",
  "requestParameters": {
    "ModifyVpcEncryptionControlRequest": {
      "VpcEncryptionControlId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVpcEndpoint

#
Service
ec2

Description

Modifies attributes of a specified VPC endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpcEndpointId.Malformed",
  "errorMessage": "Invalid Id: 'dw-probe' (expecting 'vpce-...; the Id may only contain lowercase alphanumeric characters and a single dash')",
  "eventCategory": "Management",
  "eventID": "a2c60b37-5df0-48f1-9ab3-ae5cc1b4b6a4",
  "eventName": "ModifyVpcEndpoint",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1723908b-b1d3-4007-b6fe-a6c0c53a4805",
  "requestParameters": {
    "ModifyVpcEndpointRequest": {
      "VpcEndpointId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVpcEndpointConnectionNotification

#
Service
ec2

Description

Modifies a connection notification for VPC endpoint or VPC endpoint service.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameter",
  "errorMessage": "Invalid Id: 'dw-probe' (expecting 'vpce-nfn-...; the Id may only contain lowercase alphanumeric characters and two dashes')",
  "eventCategory": "Management",
  "eventID": "4a73741d-e9da-4329-b56e-e0beeab65cec",
  "eventName": "ModifyVpcEndpointConnectionNotification",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9110051c-4eaa-4a60-9a67-39d49feb0156",
  "requestParameters": {
    "ModifyVpcEndpointConnectionNotificationRequest": {
      "ConnectionNotificationId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVpcEndpointServiceConfiguration

#
Service
ec2

Description

Modifies the attributes of the specified VPC endpoint service configuration.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpcEndpointServiceId.Malformed",
  "errorMessage": "Invalid Id: 'dw-probe' (expecting 'vpce-svc-...; the Id may only contain lowercase alphanumeric characters and two dashes')",
  "eventCategory": "Management",
  "eventID": "877e532c-9f0f-4933-aaf4-b0474211055d",
  "eventName": "ModifyVpcEndpointServiceConfiguration",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:03Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "0761782a-a0e6-47c4-92ad-d77a5e200799",
  "requestParameters": {
    "ModifyVpcEndpointServiceConfigurationRequest": {
      "ServiceId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVpcEndpointServicePayerResponsibility

#
Service
ec2

Description

Modifies the payer responsibility for your VPC endpoint service.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.UnsupportedOperation",
  "errorMessage": "You must be explicitly allowlisted to call this API.",
  "eventCategory": "Management",
  "eventID": "5b9e175a-ad74-4c2e-a9f6-306dc4311497",
  "eventName": "ModifyVpcEndpointServicePayerResponsibility",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:04Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "716d0417-2dd6-4044-bfd5-5d835ec3676f",
  "requestParameters": {
    "ModifyVpcEndpointServicePayerResponsibilityRequest": {
      "PayerResponsibility": "ServiceOwner",
      "ServiceId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVpcEndpointServicePermissions

#
Service
ec2

Description

Modifies the permissions for your VPC endpoint service.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpcEndpointServiceId.Malformed",
  "errorMessage": "Invalid Id: 'dw-probe' (expecting 'vpce-svc-...; the Id may only contain lowercase alphanumeric characters and two dashes')",
  "eventCategory": "Management",
  "eventID": "08a0e6f8-1cea-4eec-8ce8-a106e38c8d33",
  "eventName": "ModifyVpcEndpointServicePermissions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:04Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d76557be-f982-41e7-bf6d-f685896adccf",
  "requestParameters": {
    "ModifyVpcEndpointServicePermissionsRequest": {
      "ServiceId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVpcPeeringConnectionOptions

#
Service
ec2

Description

Modifies the VPC peering connection options on one side of a VPC peering connection.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpcPeeringConnectionId.Malformed",
  "errorMessage": "The peering ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "9bbe6334-8c5f-4c4d-a6f4-43675f8675f9",
  "eventName": "ModifyVpcPeeringConnectionOptions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:04Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ce076e12-d0c4-45e1-9334-69371346103e",
  "requestParameters": {
    "ModifyVpcPeeringConnectionOptionsRequest": {
      "VpcPeeringConnectionId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVpcTenancy

#
Service
ec2

Description

Modifies the instance tenancy attribute of the specified VPC.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpcId.Malformed",
  "errorMessage": "The vpc ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "f21b4e2c-76ed-48c4-8fcb-24d223b40270",
  "eventName": "ModifyVpcTenancy",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:04Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8cae0838-c0b7-4055-8d2e-63e2a3bcdfa3",
  "requestParameters": {
    "ModifyVpcTenancyRequest": {
      "InstanceTenancy": "default",
      "VpcId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVpnConnection

#
Service
ec2

Description

Modifies the customer gateway or the target gateway of an Amazon Web Services Site-to-Site VPN connection.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameter",
  "errorMessage": "Parameter vpnConnectionId=dw-probe has an invalid format.",
  "eventCategory": "Management",
  "eventID": "e300197d-d17c-43fe-849b-8af3c3f9df83",
  "eventName": "ModifyVpnConnection",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:04Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "1382eaf4-07bd-4ccb-8a01-619d63a7351e",
  "requestParameters": {
    "ModifyVpnConnectionRequest": {
      "VpnConnectionId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVpnConnectionOptions

#
Service
ec2

Description

Modifies the connection options for your Site-to-Site VPN connection.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpnConnectionID.NotFound",
  "errorMessage": "The vpnConnection ID 'dw-probe' does not exist",
  "eventCategory": "Management",
  "eventID": "c15a21ad-68bb-455c-a8ec-a10c20c3bf04",
  "eventName": "ModifyVpnConnectionOptions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "aa7957b3-e68a-4e54-ac26-762158a8b4d2",
  "requestParameters": {
    "ModifyVpnConnectionOptionsRequest": {
      "VpnConnectionId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVpnTunnelCertificate

#
Service
ec2

Description

Modifies the VPN tunnel endpoint certificate.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "Value (dw-probe) for parameter vpnTunnelOutsideIpAddress is invalid.",
  "eventCategory": "Management",
  "eventID": "fd6e1743-d30f-426f-af3d-da2710453e9e",
  "eventName": "ModifyVpnTunnelCertificate",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "48cdfcf8-4f18-423b-acad-055916f19fa4",
  "requestParameters": {
    "ModifyVpnTunnelCertificateRequest": {
      "VpnConnectionId": "dw-probe",
      "VpnTunnelOutsideIpAddress": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ModifyVpnTunnelOptions

#
Service
ec2

Description

Modifies the options for a VPN tunnel in an Amazon Web Services Site-to-Site VPN connection.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameter",
  "errorMessage": "Parameter vpnConnectionId=dw-probe has an invalid format.",
  "eventCategory": "Management",
  "eventID": "95690e34-35b8-4a7d-abca-c3ab81fe27c6",
  "eventName": "ModifyVpnTunnelOptions",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "405ebdaa-e2b0-4bb7-8cde-003383d2129e",
  "requestParameters": {
    "ModifyVpnTunnelOptionsRequest": {
      "VpnConnectionId": "dw-probe",
      "VpnTunnelOutsideIpAddress": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

MonitorInstances

#
Service
ec2

Description

Enables monitoring for a running instance.

Example CloudTrail Event #

{
  "awsRegion": "eu-central-1",
  "eventCategory": "Management",
  "eventID": "7598220f-8422-4a10-a22f-18cd62ae43a1",
  "eventName": "MonitorInstances",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-01-12T08:24:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "111111111111",
  "requestID": "9abce318-3267-42a2-95c1-51c9f67da8d7",
  "requestParameters": {
    "instancesSet": {
      "items": [
        {
          "instanceId": "i-0a1bb25cf91ffe954"
        }
      ]
    }
  },
  "responseElements": {
    "instancesSet": {
      "items": [
        {
          "instanceId": "i-0a1bb25cf91ffe954",
          "monitoring": {
            "state": "enabled"
          }
        }
      ]
    },
    "requestId": "9abce318-3267-42a2-95c1-51c9f67da8d7"
  },
  "sourceIPAddress": "95.90.199.65",
  "userAgent": "aws-sdk-go/1.36.19 (go1.15.5; darwin; amd64) APN/1.0 HashiCorp/1.0 Terraform/0.14.4 (+https://www.terraform.io)",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLJ2OYSF6E",
    "accountId": "111111111111",
    "arn": "arn:aws:iam::111111111111:user/patrick_cli",
    "principalId": "AIDAYTOGP2RLNALZHZ6KX",
    "type": "IAMUser",
    "userName": "patrick_cli"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

MoveAddressToVpc

#
Service
ec2

Description

Moves an Elastic IP address from the EC2-Classic platform to the EC2-VPC platform.

MoveByoipCidrToIpam

#
Service
ec2

Description

Move a BYOIPv4 CIDR to IPAM from a public IPv4 pool.

MoveCapacityReservationInstances

#
Service
ec2

Description

Move available capacity from a source Capacity Reservation to a destination Capacity Reservation.

ProvisionByoipCidr

#
Service
ec2

Description

Provisions an IPv4 or IPv6 address range for use with your Amazon Web Services resources through bring your own IP addresses (BYOIP) and creates a corresponding address pool.

ProvisionIpamByoasn

#
Service
ec2

Description

Provisions your Autonomous System Number (ASN) for use in your Amazon Web Services account.

ProvisionIpamPoolCidr

#
Service
ec2

Description

Provision a CIDR to an IPAM pool.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "9d240ea0-2f75-43af-9d33-512867de78c5",
  "eventName": "ProvisionIpamPoolCidr",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:48:30Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e621cd26-ece7-488c-b9e7-47e5d84db1b7",
  "requestParameters": {
    "ProvisionIpamPoolCidrRequest": {
      "Cidr": "10.99.0.0/16",
      "ClientToken": "ea06295a-c4fc-44a6-8435-56496d9ec034",
      "IpamPoolId": "ipam-pool-0b5795c40ef5b6d99"
    }
  },
  "responseElements": {
    "ProvisionIpamPoolCidrResponse": {
      "ipamPoolCidr": {
        "cidr": "10.99.0.0/16",
        "ipamPoolCidrId": "ipam-pool-cidr-00a9fa47cce7f4a0a9bdbda8809e6cc1f",
        "netmaskLength": 16,
        "state": "pending-provision"
      },
      "requestId": "e621cd26-ece7-488c-b9e7-47e5d84db1b7",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ProvisionPublicIpv4PoolCidr

#
Service
ec2

Description

Provision a CIDR to a public IPv4 pool.

PurchaseCapacityBlock

#
Service
ec2

Description

Purchase the Capacity Block for use with your account.

PurchaseCapacityBlockExtension

#
Service
ec2

Description

Purchase the Capacity Block extension for use with your account.

PurchaseHostReservation

#
Service
ec2

Description

Purchase a reservation with configurations that match those of your Dedicated Host.

PurchaseReservedInstancesOffering

#
Service
ec2

Description

Purchases a Reserved Instance for use with your account.

PurchaseScheduledInstances

#
Service
ec2

Description

Purchases one or more Scheduled Instances with the specified schedule.

RebootInstances

#
Service
ec2

Description

Requests a reboot of one or more instances.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation. Encoded authorization failure message: V6s_RP0ptFCww-lvtvVv7zgAGy8WG7W8jY6WnnqYko8kkc4G2ZOCfJyzJD2RKKr3Al2C7huwVfZASBvZWsZyO5DEBgx3XfeUuqjA-doRcJXAnWAWKn1IIP-B49mKZB8HdQXjPAZs2Fov48mjqfCTp56eKQHwBqqq6gBT-sWrtybayc0AHiaS1Clvnc-gR1gqtikZcrnev0qWPCSnT8iZseNFGyOgLHLo8hJlSz_vjQ0lSEqhQ4shpz83ZVngiGyr6ZqGxa-e15vdsnk2myxL6H9LlRxsztJwMQJGRNooO7fmmljJmPZ1RvPgkSB1noWt24wrh21wbDBxxD_X2N4UBcjxY-7EAzd1VxXwQztDJIPaZo4TCN53CvbmKgaJBp4U8H4lXCOD1Sw4J3urmixCgHY3pljMHMf9JSFqEQkGsR-nM3q7KLdiiix2OayiEQgPKlqhTy1wvsuhCuNnDJjM2Ve44ncF6VPNAQEpz1rNJLcUVXEUQv-D9JsvZJ2C5bGAaSIcGstB_q-J1cjUa3-u2gF-vVb6SfFMAclIvxPgK4U0VX_a6-jh5Qmp6GLFasY16jKo-rWQGje9rN3Z7n69yRo7O2UiPU7xvKjqrUgj8th00xDjX9kDxh4OFw-Fa7BncOlAP2XSQM4dbQfz0_YQZcacU7rU7GNm_ZlvsA7d8uzOH6huDcPLWzhFlHE",
  "eventID": "e2de6c85-f52a-4252-8a9e-bad0e837640c",
  "eventName": "RebootInstances",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2018-11-16T18:35:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "3208b295-f6c6-4be5-8794-a2c58e42c259",
  "requestParameters": {
    "instancesSet": {
      "items": [
        {
          "instanceId": "i-aa2d3b42e5c6e801a"
        }
      ]
    }
  },
  "responseElements": null,
  "sourceIPAddress": "0.35.253.179",
  "userAgent": "aws-cli/1.14.58 Python/2.7.9 Windows/8 botocore/1.9.11",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

RegisterImage

#
Service
ec2

Description

Registers an AMI.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "fa0d7aad-7d72-46c4-a0cf-230834779e81",
  "eventName": "RegisterImage",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:10:53Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "33421278-4323-41d0-92a9-f32b478dd054",
  "requestParameters": {
    "architecture": "x86_64",
    "blockDeviceMapping": {
      "items": [
        {
          "deviceName": "/dev/xvda",
          "ebs": {
            "deleteOnTermination": true,
            "snapshotId": "snap-01ee6be9876379b3b",
            "volumeSize": 1,
            "volumeType": "standard"
          }
        }
      ]
    },
    "enaSupport": false,
    "name": "stratus-red-team-share-ami-ami",
    "rootDeviceName": "/dev/xvda",
    "sriovNetSupport": "simple"
  },
  "responseElements": {
    "imageId": "ami-0aa1d83d0b0985c86",
    "requestId": "33421278-4323-41d0-92a9-f32b478dd054"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_b47d6b97-21d3-4b01-8937-6f0c23cb2d4b HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

RegisterInstanceEventNotificationAttributes

#
Service
ec2

Description

Registers a set of tag keys to include in scheduled event notifications for your resources.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "daf1d9f4-d9b2-4612-ba8e-2eaeb0d7c3f3",
  "eventName": "RegisterInstanceEventNotificationAttributes",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:40:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c083c5b2-69b3-47d3-a06a-5f7c64632ccf",
  "requestParameters": {
    "RegisterInstanceEventNotificationAttributesRequest": {
      "InstanceTagAttribute": {
        "IncludeAllTagsOfInstance": true
      }
    }
  },
  "responseElements": {
    "RegisterInstanceEventNotificationAttributesResponse": {
      "instanceTagAttribute": {
        "includeAllTagsOfInstance": true,
        "instanceTagKeySet": ""
      },
      "requestId": "c083c5b2-69b3-47d3-a06a-5f7c64632ccf",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

RegisterTransitGatewayMulticastGroupMembers

#
Service
ec2

Description

Registers members (network interfaces) with the transit gateway multicast group.

RegisterTransitGatewayMulticastGroupSources

#
Service
ec2

Description

Registers sources (network interfaces) with the specified transit gateway multicast group.

RejectCapacityReservationBillingOwnership

#
Service
ec2

Description

Rejects a request to assign billing of the available capacity of a shared Capacity Reservation to your account.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidCapacityReservationId.Malformed",
  "errorMessage": "Capacity Reservation ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "d167e705-0953-4e71-bb4e-934104dff1d8",
  "eventName": "RejectCapacityReservationBillingOwnership",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "89a0de1f-4ed8-467d-8b24-8d0f0d256eec",
  "requestParameters": {
    "RejectCapacityReservationBillingOwnershipRequest": {
      "CapacityReservationId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RejectTransitGatewayClientVpnAttachment

#
Service
ec2

Description

Rejects a Transit Gateway attachment request for a Client VPN endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayAttachmentID.Malformed",
  "errorMessage": "The transit-gateway-attachment ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "52bb07fb-9fd0-40b7-892d-660ada9b9885",
  "eventName": "RejectTransitGatewayClientVpnAttachment",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "9233c1f9-98d5-44ce-967b-f4238d20b76a",
  "requestParameters": {
    "RejectTransitGatewayClientVpnAttachmentRequest": {
      "TransitGatewayAttachmentId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RejectTransitGatewayMulticastDomainAssociations

#
Service
ec2

Description

Rejects a request to associate cross-account subnets with a transit gateway multicast domain.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.MissingParameter",
  "errorMessage": "Missing required parameter in request: TransitGatewayMulticastDomainId.",
  "eventCategory": "Management",
  "eventID": "687020de-b0c0-4842-922a-0b6d2b195879",
  "eventName": "RejectTransitGatewayMulticastDomainAssociations",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:45:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8b90786e-3fa3-4d81-8329-17cf619dac5e",
  "requestParameters": {
    "RejectTransitGatewayMulticastDomainAssociationsRequest": ""
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RejectTransitGatewayPeeringAttachment

#
Service
ec2

Description

Rejects a transit gateway peering attachment request.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayAttachmentID.Malformed",
  "errorMessage": "Invalid Transit Gateway Attachment id.",
  "eventCategory": "Management",
  "eventID": "aef49558-f7f2-405f-8bbc-fc7739526d7e",
  "eventName": "RejectTransitGatewayPeeringAttachment",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e2ad3267-c96f-4ffa-bd35-e334960907d0",
  "requestParameters": {
    "RejectTransitGatewayPeeringAttachmentRequest": {
      "TransitGatewayAttachmentId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RejectTransitGatewayVpcAttachment

#
Service
ec2

Description

Rejects a request to attach a VPC to a transit gateway.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayAttachmentID.Malformed",
  "errorMessage": "Invalid Transit Gateway Attachment id.",
  "eventCategory": "Management",
  "eventID": "568cef2e-65d2-4ef6-8332-4ed2ebc99a69",
  "eventName": "RejectTransitGatewayVpcAttachment",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a18cc887-4b66-4b22-9fdb-0bf911cfa094",
  "requestParameters": {
    "RejectTransitGatewayVpcAttachmentRequest": {
      "TransitGatewayAttachmentId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RejectVpcEndpointConnections

#
Service
ec2

Description

Rejects VPC endpoint connection requests to your VPC endpoint service.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpcEndpointServiceId.Malformed",
  "errorMessage": "Invalid Id: 'dw-probe' (expecting 'vpce-svc-...; the Id may only contain lowercase alphanumeric characters and two dashes')",
  "eventCategory": "Management",
  "eventID": "4aaf5246-696a-4881-9807-d8e46259d70d",
  "eventName": "RejectVpcEndpointConnections",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5e17333c-d5a2-4ddd-8f0e-20d5cf5d9a1f",
  "requestParameters": {
    "RejectVpcEndpointConnectionsRequest": {
      "ServiceId": "dw-probe",
      "VpcEndpointId": {
        "content": "dw-probe",
        "tag": 1
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RejectVpcPeeringConnection

#
Service
ec2

Description

Rejects a VPC peering connection request.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidVpcPeeringConnectionId.Malformed",
  "errorMessage": "The vpc-peering-connection ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "a318de83-b713-4356-bd9c-cedfa909bb7b",
  "eventName": "RejectVpcPeeringConnection",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:07Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "f71f1db9-55a5-4e5b-99e7-957adc032484",
  "requestParameters": {
    "vpcPeeringConnectionId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ReleaseAddress

#
Service
ec2

Description

Releases the specified Elastic IP address.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "540b0193-0d7f-4682-b665-9e6a6f734b1f",
  "eventName": "ReleaseAddress",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:07:24Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "aec8cb85-7a00-4f0a-a8b4-ce023d4a8942",
  "requestParameters": {
    "allocationId": "eipalloc-09d58d8a1fc361502",
    "networkBorderGroup": "us-east-1"
  },
  "responseElements": {
    "_return": true,
    "requestId": "aec8cb85-7a00-4f0a-a8b4-ce023d4a8942"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

References #

ReleaseHosts

#
Service
ec2

Description

When you no longer want to use a Dedicated host it can be released.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "0afe2854-457d-44cb-83ed-10d424e5366b",
  "eventName": "ReleaseHosts",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:07Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "8e1028c9-a843-493e-89d9-026917fe43f9",
  "requestParameters": {
    "ReleaseHostsRequest": {
      "HostId": {
        "content": "dw-probe",
        "tag": 1
      }
    }
  },
  "responseElements": {
    "ReleaseHostsResponse": {
      "requestId": "8e1028c9-a843-493e-89d9-026917fe43f9",
      "successful": "",
      "unsuccessful": {
        "item": {
          "error": {
            "code": "Client.InvalidHostID.Malformed",
            "message": "The specified Dedicated host IDs ['dw-probe'] are not valid."
          },
          "resourceId": "dw-probe"
        }
      },
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ReleaseIpamPoolAllocation

#
Service
ec2

Description

Release an allocation within an IPAM pool.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidIpamPoolId.Malformed",
  "errorMessage": "The specified IPAM pool ID is not valid. Specify an IPAM pool ID in the form ipam-pool-xxxxxxxxxxxxxxxxx.",
  "eventCategory": "Management",
  "eventID": "adc30a63-aad8-42da-9f3e-04b384682cad",
  "eventName": "ReleaseIpamPoolAllocation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:07Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "134ffb6b-7bcb-46ff-9662-09b7a99df8be",
  "requestParameters": {
    "ReleaseIpamPoolAllocationRequest": {
      "Cidr": "dw-probe",
      "IpamPoolAllocationId": "dw-probe",
      "IpamPoolId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ReplaceIamInstanceProfileAssociation

#
Service
ec2

Description

Replaces an IAM instance profile for the specified running instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation. Encoded authorization failure message: 8EJjHUgzAIUK29zdJSWzOxy3pADpDZ568u_LfdbhSqijqHcrGJeQqNkFLAVM_dkpVlmTPuqzyvoFYvXa3CC3s4OE_S8ZSSxlX07PSof9PXgOnEEFWQr6c-A6ShlgFhvuJpmra4sDSv_k9UMT8eRpdfxS--ceCREJd2uFsg87FFjMBAqIRuxiZhRddWAs8QM3X9acWrTB19hOr6ZaMGjkiteQMgTu8reLVOLuvnouYg4LFoF-1R9xpRvqj6vncZC8_vzA09Mf-stImsB2tlKbm_X31vXGxgQK1JXSmZMMhQwtWh75cMQLkWo9egN7bb_5wOezRhEnxvr_VaTlTr7zQG096Qv7qE-tLTNXaYZNVjI23xU4TAW3l2J3f_9l5zUS7AqyM7G5MB6Vpbb_ayZUUDNNPpqIPFEYfm_JPEByPZD1aFlDiXHBGhYNSUKSza6GPn8-bqGYDL18Kc2laNhkfQp-PNHWWibvqMJrqfSq4I5kUBjSL28AgAEOjs30iQAU7xNQdPnKYw38RWZ7CPuWP56_XTH0fiibFVHSlbQILhTbwIiN2wgWNc7ybjeySZuy7V6-Xdv_XjfDR9tvK5veC4jJLkVYUVcAEwnhrYNmFNuqjBuZtrFPwzsqs0-tWCKHCCfPEMzBwJQB7Ic2yq7thzP1D8-o7jxvxHx-ti72N2aZl2Bo_AM7D0pRBe-3TNHYAX4rnqg-ucE",
  "eventID": "1d6fd722-668b-46fc-8e03-0d5296ddd0be",
  "eventName": "ReplaceIamInstanceProfileAssociation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2019-11-17T06:58:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "753e9f92-9850-4881-8859-b0301d6bdd37",
  "requestParameters": {
    "ReplaceIamInstanceProfileAssociationRequest": {
      "AssociationId": "iip-assoc-56ccc7f0af6b28173",
      "IamInstanceProfile": {
        "Name": "instanceprofilename"
      }
    }
  },
  "responseElements": null,
  "sourceIPAddress": "8.103.248.255",
  "userAgent": "aws-cli/1.16.260 Python/3.7.3 Linux/5.0.0-32-generic botocore/1.12.250",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ReplaceImageCriteriaInAllowedImagesSettings

#
Service
ec2

Description

Sets or replaces the criteria for Allowed AMIs.

ReplaceNetworkAclAssociation

#
Service
ec2

Description

Changes which network ACL a subnet is associated with.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "fd5b99ad-1b76-4c94-b04d-8108e3b22ae9",
  "eventName": "ReplaceNetworkAclAssociation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:39:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "94e00318-b0e7-40f2-b016-75405234b478",
  "requestParameters": {
    "associationId": "aclassoc-0fd4ae72616ddbe51",
    "networkAclId": "acl-04d473e8d2029fa23"
  },
  "responseElements": {
    "newAssociationId": "aclassoc-02eb71d8668128857",
    "requestId": "94e00318-b0e7-40f2-b016-75405234b478"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ReplaceTransitGatewayRoute

#
Service
ec2

Description

Replaces the specified route in the specified transit gateway route table.

ReplaceVpnTunnel

#
Service
ec2

Description

Trigger replacement of specified VPN tunnel.

ReportInstanceStatus

#
Service
ec2

Description

Submits feedback about the status of an instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "bea294f0-9f6a-47c8-9831-553f9a3d673e",
  "eventName": "ReportInstanceStatus",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:40:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "67fc0e0d-8a97-42a2-b193-e3beff54881c",
  "requestParameters": {
    "instancesSet": {
      "items": [
        {
          "instanceId": "i-0a4c8f9124bcc1a50"
        }
      ]
    },
    "reasonCodesSet": {
      "items": [
        {
          "reasonCode": "instance-stuck-in-state"
        }
      ]
    },
    "status": "ok"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

RequestSpotFleet

#
Service
ec2

Description

Creates a Spot fleet request.

RequestSpotInstances

#
Service
ec2

Description

Creates a Spot Instance request.

Example CloudTrail Event #

{
  "awsRegion": "us-west-2",
  "errorCode": "Client.UnauthorizedOperation",
  "errorMessage": "You are not authorized to perform this operation.",
  "eventID": "ab9ab691-61b8-48b7-9480-c99310",
  "eventName": "RequestSpotInstances",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2019-05-20T09:29:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "bac37d14-c130-419f-aea7-6fd228eb80b1",
  "requestParameters": {
    "instanceCount": 1
  },
  "responseElements": null,
  "sourceIPAddress": "240.48.251.119",
  "userAgent": "aws-cli/1.16.158 Python/3.7.3 Linux/5.0.13-arch1-1-ARCH botocore/1.12.148",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

ResetAddressAttribute

#
Service
ec2

Description

Resets the attribute of the specified IP address.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidAllocationID.NotFound",
  "errorMessage": "The allocation ID 'dw-probe' does not exist",
  "eventCategory": "Management",
  "eventID": "80ff7048-bc65-4be5-8bb8-c84e98033805",
  "eventName": "ResetAddressAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:07Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "d380ff12-62db-4fd9-959b-569d949b0c50",
  "requestParameters": {
    "ResetAddressAttributeRequest": {
      "AllocationId": "dw-probe",
      "Attribute": "domain-name"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ResetEbsDefaultKmsKeyId

#
Service
ec2

Description

Resets the default KMS key for EBS encryption for your account in this Region to the Amazon Web Services managed KMS key for EBS.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "be7720ac-2bd6-411c-9aeb-9fa25c259d03",
  "eventName": "ResetEbsDefaultKmsKeyId",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:45:19Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "3f128fb5-a95b-4593-93e5-aa747762882c",
  "requestParameters": {
    "ResetEbsDefaultKmsKeyIdRequest": ""
  },
  "responseElements": {
    "ResetEbsDefaultKmsKeyIdResponse": {
      "kmsKeyId": "arn:aws:kms:us-west-1:123456789012:key/286ef80c-015b-4690-b517-43de4b604d27",
      "requestId": "3f128fb5-a95b-4593-93e5-aa747762882c",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ResetFpgaImageAttribute

#
Service
ec2

Description

Resets the specified attribute of the specified Amazon FPGA Image (AFI) to its default value.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.UnsupportedOperation",
  "errorMessage": "The functionality you requested is not available in this region.",
  "eventCategory": "Management",
  "eventID": "aaf4af93-a566-4a90-884e-477fee37bbdd",
  "eventName": "ResetFpgaImageAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:08Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "a540df85-196c-4f17-a345-a563d0cce449",
  "requestParameters": {
    "ResetFpgaImageAttributeRequest": {
      "FpgaImageId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ResetImageAttribute

#
Service
ec2

Description

Resets an attribute of an AMI to its default value.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidAMIID.Malformed",
  "errorMessage": "Invalid id: \"dw-probe\" (expecting \"ami-...\")",
  "eventCategory": "Management",
  "eventID": "2abe44f1-5889-49cb-900a-2521c416fcbe",
  "eventName": "ResetImageAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:08Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "940e158c-a415-4fa1-9d2a-10f45016af6e",
  "requestParameters": {
    "attributeType": "launchPermission",
    "imageId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ResetInstanceAttribute

#
Service
ec2

Description

Resets an attribute of an instance to its default value.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterValue",
  "errorMessage": "Value (instanceType) for parameter attribute is invalid. Unknown attribute.",
  "eventCategory": "Management",
  "eventID": "1e535919-8311-45ca-9cb5-68fb79f716c8",
  "eventName": "ResetInstanceAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:08Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c20cb3c2-4cd2-4981-be6d-b4b6e98c1d74",
  "requestParameters": {
    "attribute": "instanceType",
    "instanceId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

ResetNetworkInterfaceAttribute

#
Service
ec2

Description

Resets a network interface attribute.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidParameterCombination",
  "errorMessage": "No attributes specified.",
  "eventCategory": "Management",
  "eventID": "24a43563-2864-431b-a500-0d98df34ccc8",
  "eventName": "ResetNetworkInterfaceAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "66c4cdfe-2c6b-435f-981e-86c3e225384d",
  "requestParameters": {
    "networkInterfaceId": "dw-probe"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ResetSnapshotAttribute

#
Service
ec2

Description

Resets permission settings for the specified snapshot.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRequest",
  "errorMessage": "The request received was invalid.",
  "eventCategory": "Management",
  "eventID": "a5d21b65-68d7-4217-92de-0efb837d4a90",
  "eventName": "ResetSnapshotAttribute",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "416a3f53-91e2-42b4-8909-b7d481bc543d",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RestoreAddressToClassic

#
Service
ec2

Description

Restores an Elastic IP address that was previously moved to the EC2-VPC platform back to the EC2-Classic platform.

RestoreImageFromRecycleBin

#
Service
ec2

Description

Restores an AMI from the Recycle Bin.

RestoreManagedPrefixListVersion

#
Service
ec2

Description

Restores the entries from a previous version of a managed prefix list to a new version of the prefix list.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.PrefixListVersionMismatch",
  "errorMessage": "The prefix list has the incorrect version number.",
  "eventCategory": "Management",
  "eventID": "2a2a2f96-8c43-41d9-9afd-ac4493d35837",
  "eventName": "RestoreManagedPrefixListVersion",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:40:04Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "4cf91261-7938-4f13-abd1-b8163730f2c6",
  "requestParameters": {
    "RestoreManagedPrefixListVersionRequest": {
      "CurrentVersion": 2,
      "PrefixListId": "pl-0019d1157c40d82a7",
      "PreviousVersion": 1
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RestoreSnapshotFromRecycleBin

#
Service
ec2

Description

Restores a snapshot from the Recycle Bin.

RestoreSnapshotTier

#
Service
ec2

Description

Restores an archived Amazon EBS snapshot for use temporarily or permanently, or modifies the restore period or restore type for a snapshot that was previously temporarily restored.

RestoreVolumeFromRecycleBin

#
Service
ec2

Description

Restores a volume from the Recycle Bin.

RevokeClientVpnIngress

#
Service
ec2

Description

Removes an ingress authorization rule from a Client VPN endpoint.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidClientVpnEndpointId.NotFound",
  "errorMessage": "The client-vpn-endpoint ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "8ccc8ce1-2ac4-4e48-9cdc-4152727f402f",
  "eventName": "RevokeClientVpnIngress",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "5f92deb8-82c7-47c8-8c70-241d9b527aae",
  "requestParameters": {
    "RevokeClientVpnIngressRequest": {
      "ClientVpnEndpointId": "dw-probe",
      "TargetNetworkCidr": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

RunInstances

#
Service
ec2

Description

Launches the specified number of instances using an AMI for which you have permissions.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "86eac0ac-8521-4126-aa32-a22f2b74d02e",
  "eventName": "RunInstances",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T11:55:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "95b435ce-68af-4a4b-b89c-f653d8946ebc",
  "requestParameters": {
    "blockDeviceMapping": {},
    "clientToken": "D37569A7-CF2F-4BD3-8DDE-F17AB408204D",
    "creditSpecification": {
      "cpuCredits": "unlimited"
    },
    "disableApiStop": false,
    "disableApiTermination": false,
    "ebsOptimized": false,
    "hibernationOptions": {
      "configured": false
    },
    "iamInstanceProfile": {
      "name": "stratus-red-team-ec2-steal-credentials-instance"
    },
    "instanceType": "t3.micro",
    "instancesSet": {
      "items": [
        {
          "imageId": "ami-029eb80bc237bec6f",
          "maxCount": 1,
          "minCount": 1
        }
      ]
    },
    "monitoring": {
      "enabled": false
    },
    "networkInterfaceSet": {
      "items": [
        {
          "deleteOnTermination": false,
          "deviceIndex": 0,
          "networkInterfaceId": "eni-076fa9fb98a2500a7"
        }
      ]
    },
    "tagSpecificationSet": {
      "items": [
        {
          "resourceType": "instance",
          "tags": [
            {
              "key": "StratusRedTeam",
              "value": "true"
            }
          ]
        }
      ]
    }
  },
  "responseElements": {
    "groupSet": {},
    "instancesSet": {
      "items": [
        {
          "amiLaunchIndex": 0,
          "architecture": "x86_64",
          "blockDeviceMapping": {},
          "capacityReservationSpecification": {
            "capacityReservationPreference": "open"
          },
          "clientToken": "D37569A7-CF2F-4BD3-8DDE-F17AB408204D",
          "cpuOptions": {
            "coreCount": 1,
            "threadsPerCore": 2
          },
          "currentInstanceBootMode": "legacy-bios",
          "ebsOptimized": false,
          "enaSupport": true,
          "enclaveOptions": {
            "enabled": false
          },
          "groupSet": {
            "items": [
              {
                "groupId": "sg-0b233157065b7d5e2"
              }
            ]
          },
          "hibernationOptions": {
            "configured": false
          },
          "hypervisor": "xen",
          "iamInstanceProfile": {
            "arn": "arn:aws:iam::123837392027:instance-profile/stratus-red-team-ec2-steal-credentials-instance",
            "id": "AIPATFQR7NSCT5GZF5JGF"
          },
          "imageId": "ami-029eb80bc237bec6f",
          "instanceId": "i-0dbc91f429e48eeed",
          "instanceState": {
            "code": 0,
            "name": "pending"
          },
          "instanceType": "t3.micro",
          "launchTime": 1688990121000,
          "maintenanceOptions": {
            "autoRecovery": "default"
          },
          "metadataOptions": {
            "httpEndpoint": "enabled",
            "httpProtocolIpv4": "enabled",
            "httpProtocolIpv6": "disabled",
            "httpPutResponseHopLimit": 1,
            "httpTokens": "optional",
            "instanceMetadataTags": "disabled",
            "state": "pending"
          },
          "monitoring": {
            "state": "disabled"
          },
          "networkInterfaceSet": {
            "items": [
              {
                "attachment": {
                  "attachTime": 1688990121000,
                  "attachmentId": "eni-attach-00cac81742e39b87a",
                  "deleteOnTermination": false,
                  "deviceIndex": 0,
                  "networkCardIndex": 0,
                  "status": "attaching"
                },
                "groupSet": {
                  "items": [
                    {
                      "groupId": "sg-0b233157065b7d5e2"
                    }
                  ]
                },
                "interfaceType": "interface",
                "ipv6AddressesSet": {},
                "macAddress": "12:c4:b6:95:a1:71",
                "networkInterfaceId": "eni-076fa9fb98a2500a7",
                "ownerId": "123837392027",
                "privateIpAddress": "10.0.1.10",
                "privateIpAddressesSet": {
                  "item": [
                    {
                      "primary": true,
                      "privateIpAddress": "10.0.1.10"
                    }
                  ]
                },
                "sourceDestCheck": true,
                "status": "in-use",
                "subnetId": "subnet-0ed352584ab4aa265",
                "tagSet": {},
                "vpcId": "vpc-06fe1a64761a0f720"
              }
            ]
          },
          "placement": {
            "availabilityZone": "us-east-1a",
            "tenancy": "default"
          },
          "privateDnsName": "ip-10-0-1-10.ec2.internal",
          "privateDnsNameOptions": {
            "enableResourceNameDnsAAAARecord": false,
            "enableResourceNameDnsARecord": false,
            "hostnameType": "ip-name"
          },
          "privateIpAddress": "10.0.1.10",
          "productCodes": {},
          "rootDeviceName": "/dev/xvda",
          "rootDeviceType": "ebs",
          "sourceDestCheck": true,
          "stateReason": {
            "code": "pending",
            "message": "pending"
          },
          "subnetId": "subnet-0ed352584ab4aa265",
          "tagSet": {
            "items": [
              {
                "key": "StratusRedTeam",
                "value": "true"
              }
            ]
          },
          "virtualizationType": "hvm",
          "vpcId": "vpc-06fe1a64761a0f720"
        }
      ]
    },
    "ownerId": "123837392027",
    "requestId": "95b435ce-68af-4a4b-b89c-f653d8946ebc",
    "reservationId": "r-0ac0088de73525c3c"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

Panther #

References #

RunScheduledInstances

#
Service
ec2

Description

Launches the specified Scheduled Instances.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

SearchLocalGatewayRoutes

#
Service
ec2

Description

Searches for routes in the specified local gateway route table.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidLocalGatewayRouteTableID.Malformed",
  "errorMessage": "The local-gateway-route-table ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "6721dc30-bb60-4b57-a7a7-fcf2e796c21f",
  "eventName": "SearchLocalGatewayRoutes",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "73787cf8-5e1f-45b9-977d-d609d53d53c1",
  "requestParameters": {
    "SearchLocalGatewayRoutesRequest": {
      "LocalGatewayRouteTableId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

SearchTransitGatewayMulticastGroups

#
Service
ec2

Description

Searches one or more transit gateway multicast groups and returns the group membership information.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidTransitGatewayMulticastDomainId.Malformed",
  "errorMessage": "Invalid Transit Gateway Multicast Domain id dw-probe.",
  "eventCategory": "Management",
  "eventID": "ebf744f8-eae3-4a3e-915e-45d0e339fce7",
  "eventName": "SearchTransitGatewayMulticastGroups",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "95faceaf-3feb-42f2-8b5d-cd39081ee7ce",
  "requestParameters": {
    "SearchTransitGatewayMulticastGroupsRequest": {
      "TransitGatewayMulticastDomainId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

SearchTransitGatewayRoutes

#
Service
ec2

Description

Searches for routes in the specified transit gateway route table.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidRouteTableId.Malformed",
  "errorMessage": "Invalid Transit Gateway Route Table id dw-probe.",
  "eventCategory": "Management",
  "eventID": "a858eb2a-5817-49b8-af80-c0d0cd8e5780",
  "eventName": "SearchTransitGatewayRoutes",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T18:43:20Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "86b2a10e-facc-4725-abd9-7454eeba27ea",
  "requestParameters": {
    "SearchTransitGatewayRoutesRequest": {
      "TransitGatewayRouteTableId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

SendDiagnosticInterrupt

#
Service
ec2

Description

Sends a diagnostic interrupt to the specified Amazon EC2 instance to trigger a kernel panic (on Linux instances), or a blue screen/stop error (on Windows instances).

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "d8f6f8f4-9f1a-4bd3-b799-2e10fe236268",
  "eventName": "SendDiagnosticInterrupt",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:40:28Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "66fa8743-8716-4721-a6f4-bce5f825d736",
  "requestParameters": {
    "SendDiagnosticInterruptRequest": {
      "InstanceId": "i-0a4c8f9124bcc1a50"
    }
  },
  "responseElements": {
    "SendDiagnosticInterruptResponse": {
      "requestId": "66fa8743-8716-4721-a6f4-bce5f825d736",
      "return": true,
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

StartDeclarativePoliciesReport

#
Service
ec2

Description

Generates an account status report.

StartNetworkInsightsAccessScopeAnalysis

#
Service
ec2

Description

Starts analyzing the specified Network Access Scope.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "002ed03e-885e-4694-8797-d1d4c5d7d398",
  "eventName": "StartNetworkInsightsAccessScopeAnalysis",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:46:02Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ffa606dc-571b-4b3c-91a6-0c340a1a960b",
  "requestParameters": {
    "StartNetworkInsightsAccessScopeAnalysisRequest": {
      "ClientToken": "b07a8413102f487c941db2ead4e53531",
      "NetworkInsightsAccessScopeId": "nis-09c07334f0c179e68"
    }
  },
  "responseElements": {
    "StartNetworkInsightsAccessScopeAnalysisResponse": {
      "networkInsightsAccessScopeAnalysis": {
        "analyzedEniCount": 0,
        "networkInsightsAccessScopeAnalysisArn": "arn:aws:ec2:us-west-1:123456789012:network-insights-access-scope-analysis/nisa-0dc1124eef8e941c8",
        "networkInsightsAccessScopeAnalysisId": "nisa-0dc1124eef8e941c8",
        "networkInsightsAccessScopeId": "nis-09c07334f0c179e68",
        "startDate": "2026-06-29T22:46:02.441Z",
        "status": "running"
      },
      "requestId": "ffa606dc-571b-4b3c-91a6-0c340a1a960b",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

StartNetworkInsightsAnalysis

#
Service
ec2

Description

Starts analyzing the specified path.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "4e866585-4cee-4ffd-a377-6740540dde92",
  "eventName": "StartNetworkInsightsAnalysis",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:46:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c0bfa94c-4b09-4502-9a04-d011a011fe1e",
  "requestParameters": {
    "StartNetworkInsightsAnalysisRequest": {
      "ClientToken": "5d89911309d44553bdd2883074b59ef1",
      "NetworkInsightsPathId": "nip-01e67beb8a4227dca",
      "TagSpecification": {
        "ResourceType": "network-insights-analysis",
        "Tag": [
          {
            "Key": "Name",
            "Value": "dwfix-ec2-d393e412",
            "tag": 1
          },
          {
            "Key": "dwfix",
            "Value": "1",
            "tag": 2
          }
        ],
        "tag": 1
      }
    }
  },
  "responseElements": {
    "StartNetworkInsightsAnalysisResponse": {
      "networkInsightsAnalysis": {
        "networkInsightsAnalysisArn": "arn:aws:ec2:us-west-1:123456789012:network-insights-analysis/nia-0ef9b1ad4688807e9",
        "networkInsightsAnalysisId": "nia-0ef9b1ad4688807e9",
        "networkInsightsPathId": "nip-01e67beb8a4227dca",
        "startDate": "2026-06-29T22:46:01.170Z",
        "status": "running",
        "tagSet": {
          "item": [
            {
              "key": "dwfix",
              "value": "1"
            },
            {
              "key": "Name",
              "value": "dwfix-ec2-d393e412"
            }
          ]
        }
      },
      "requestId": "c0bfa94c-4b09-4502-9a04-d011a011fe1e",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

StartVpcEndpointServicePrivateDnsVerification

#
Service
ec2

Description

Initiates the verification process to prove that the service provider owns the private DNS name domain for the endpoint service.

TerminateClientVpnConnections

#
Service
ec2

Description

Terminates active Client VPN endpoint connections.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidClientVpnEndpointId.NotFound",
  "errorMessage": "The client-vpn-endpoint ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "f945207d-45e5-4ec6-9d3d-6b06a54688d2",
  "eventName": "TerminateClientVpnConnections",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:09Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "cd74fe20-51ac-4941-ab59-c17f66c929ab",
  "requestParameters": {
    "TerminateClientVpnConnectionsRequest": {
      "ClientVpnEndpointId": "dw-probe"
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

TerminateInstances

#
Service
ec2

Description

Shuts down one or more instances.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "2d893b1d-e8f2-499b-a558-cb927d9b48ea",
  "eventName": "TerminateInstances",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2023-07-10T12:08:06Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "df4f910a-c4dd-49eb-ab07-6d96fc5c142a",
  "requestParameters": {
    "instancesSet": {
      "items": [
        {
          "instanceId": "i-0dbc91f429e48eeed"
        }
      ]
    }
  },
  "responseElements": {
    "instancesSet": {
      "items": [
        {
          "currentState": {
            "code": 32,
            "name": "shutting-down"
          },
          "instanceId": "i-0dbc91f429e48eeed",
          "previousState": {
            "code": 16,
            "name": "running"
          }
        }
      ]
    },
    "requestId": "df4f910a-c4dd-49eb-ab07-6d96fc5c142a"
  },
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.2"
  },
  "userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
  "userIdentity": {
    "accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

References #

UnassignIpv6Addresses

#
Service
ec2

Description

Unassigns the specified IPv6 addresses or Prefix Delegation prefixes from a network interface.

UnassignPrivateIpAddresses

#
Service
ec2

Description

Unassigns one or more secondary private IP addresses from a network interface.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "09fb2211-e234-4537-ab1d-48623bc2554e",
  "eventName": "UnassignPrivateIpAddresses",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:45:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e5ed6bf6-735c-4d17-8050-791521e66f54",
  "requestParameters": {
    "ipv4Prefixes": {},
    "networkInterfaceId": "eni-025f9aaa17cd9ff32",
    "privateIpAddressesSet": {
      "items": [
        {
          "privateIpAddress": "10.0.1.174"
        }
      ]
    }
  },
  "responseElements": {
    "_return": true,
    "requestId": "e5ed6bf6-735c-4d17-8050-791521e66f54"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UnassignPrivateNatGatewayAddress

#
Service
ec2

Description

Unassigns secondary private IPv4 addresses from a private NAT gateway.

UnlockSnapshot

#
Service
ec2

Description

Unlocks a snapshot that is locked in governance mode or that is locked in compliance mode but still in the cooling-off period.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "839ffd6e-1e29-4db7-a76f-e3a8825cc963",
  "eventName": "UnlockSnapshot",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:42:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "7a9c7e4c-7d2c-403f-944b-08f6c6034e78",
  "requestParameters": {
    "UnlockSnapshotRequest": {
      "SnapshotId": "snap-0c0fb4e5cd0eee943"
    }
  },
  "responseElements": {
    "UnlockSnapshotResponse": {
      "requestId": "7a9c7e4c-7d2c-403f-944b-08f6c6034e78",
      "snapshotId": "snap-0c0fb4e5cd0eee943",
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UnmonitorInstances

#
Service
ec2

Description

Disables monitoring for a running instance.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "f1713fbc-0362-4aba-b8f3-954c886c4561",
  "eventName": "UnmonitorInstances",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:59:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6990c7dd-4a7e-4d90-9431-b70a5f1d5716",
  "requestParameters": {
    "instancesSet": {
      "items": [
        {
          "instanceId": "i-08333cf57d87fa023"
        }
      ]
    }
  },
  "responseElements": {
    "instancesSet": {
      "items": [
        {
          "instanceId": "i-08333cf57d87fa023",
          "monitoring": {
            "state": "disabling"
          }
        }
      ]
    },
    "requestId": "6990c7dd-4a7e-4d90-9431-b70a5f1d5716"
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Panther #

UpdateCapacityManagerMonitoredTagKeys

#
Service
ec2

Description

Activates or deactivates tag keys for monitoring by EC2 Capacity Manager.

UpdateCapacityManagerOrganizationsAccess

#
Service
ec2

Description

Updates the Organizations access setting for EC2 Capacity Manager.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.CapacityManager.Disabled",
  "errorMessage": "Capacity Manager isn't enabled for this account.",
  "eventCategory": "Management",
  "eventID": "c07cf71d-b3fd-48cf-8abb-c60898897785",
  "eventName": "UpdateCapacityManagerOrganizationsAccess",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "e95ca93d-0f57-4adc-931f-833f1edd374c",
  "requestParameters": {
    "UpdateCapacityManagerOrganizationsAccessRequest": {
      "ClientToken": "106fd254-33fc-4c0a-876a-7e5d35c0d150",
      "OrganizationsAccess": false
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateInterruptibleCapacityReservationAllocation

#
Service
ec2

Description

Modifies the number of instances allocated to an interruptible reservation, allowing you to add more capacity or reclaim capacity to your source Capacity Reservation.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "errorCode": "Client.InvalidCapacityReservationId.Malformed",
  "errorMessage": "The capacity-reservation ID 'dw-probe' is malformed",
  "eventCategory": "Management",
  "eventID": "4b44c059-62a5-447f-943c-596f9a7bfb7d",
  "eventName": "UpdateInterruptibleCapacityReservationAllocation",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T19:23:10Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "611eb9d1-8d1b-44dd-898a-5e979937bd6d",
  "requestParameters": {
    "UpdateInterruptibleCapacityReservationAllocationRequest": {
      "CapacityReservationId": "dw-probe",
      "TargetInstanceCount": 1
    }
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateSecurityGroupRuleDescriptionsEgress

#
Service
ec2

Description

Updates the description of an egress (outbound) security group rule.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "da6f2f02-4740-48c4-bb93-6f7e11909d36",
  "eventName": "UpdateSecurityGroupRuleDescriptionsEgress",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:39:59Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "50b66335-eaf8-4f00-b9b1-4c00e65e4a6e",
  "requestParameters": {
    "UpdateSecurityGroupRuleDescriptionsEgressRequest": {
      "GroupId": "sg-0cfd1af7bf967b6fc",
      "SecurityGroupRuleDescription": {
        "Description": "HTTPS outbound",
        "SecurityGroupRuleId": "sgr-0cc755a3be3a3211b",
        "tag": 1
      }
    }
  },
  "responseElements": {
    "UpdateSecurityGroupRuleDescriptionsEgressResponse": {
      "requestId": "50b66335-eaf8-4f00-b9b1-4c00e65e4a6e",
      "return": true,
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

UpdateSecurityGroupRuleDescriptionsIngress

#
Service
ec2

Description

Updates the description of an ingress (inbound) security group rule.

Example CloudTrail Event #

{
  "awsRegion": "us-west-1",
  "eventCategory": "Management",
  "eventID": "829ee1ed-2b7f-4ac6-a88f-54b0cc63209e",
  "eventName": "UpdateSecurityGroupRuleDescriptionsIngress",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2026-06-29T22:39:58Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "6b07bb66-6961-4fc7-a4fc-dd267e624210",
  "requestParameters": {
    "UpdateSecurityGroupRuleDescriptionsIngressRequest": {
      "GroupId": "sg-0cfd1af7bf967b6fc",
      "SecurityGroupRuleDescription": {
        "Description": "SSH from private network",
        "SecurityGroupRuleId": "sgr-0977291ab4f93ff0b",
        "tag": 1
      }
    }
  },
  "responseElements": {
    "UpdateSecurityGroupRuleDescriptionsIngressResponse": {
      "requestId": "6b07bb66-6961-4fc7-a4fc-dd267e624210",
      "return": true,
      "xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
    }
  },
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

WithdrawByoipCidr

#
Service
ec2

Description

Stops advertising an address range that is provisioned as an address pool.

BidEvictedEvent

#
Service
ec2

Description

BidEvictedEvent recorded by CloudTrail for Amazon EC2. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "267a19c7-d2d3-49fb-8be6-ca04ee3da7b9",
  "eventSource": "ec2.amazonaws.com",
  "eventName": "BidEvictedEvent",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "69033b72-9327-3cf2-909f-ffeb40c5e6c9",
  "userAgent": "ec2.amazonaws.com"
}

DeleteVpcResourceDeletion

#
Service
ec2

Description

DeleteVpcResourceDeletion recorded by CloudTrail for Amazon EC2. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "300f48f8-1120-41d9-b3f8-f39589129f8c",
  "eventSource": "ec2.amazonaws.com",
  "eventName": "DeleteVpcResourceDeletion",
  "awsRegion": "ca-central-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "c10241c5-6832-3a1e-a8b4-5f623bbb1e6c",
  "userAgent": "ec2.amazonaws.com",
  "resources": [
    {
      "accountId": "123456789012",
      "type": "AWS::EC2::NetworkAcl",
      "ARN": "arn:aws:ec2:ca-central-1:123456789012:network-acl/EXAMPLE"
    },
    {
      "accountId": "123456789012",
      "type": "AWS::EC2::RouteTable",
      "ARN": "arn:aws:ec2:ca-central-1:123456789012:route-table/EXAMPLE"
    },
    {
      "accountId": "123456789012",
      "type": "AWS::EC2::SecurityGroup",
      "ARN": "arn:aws:ec2:ca-central-1:123456789012:security-group/EXAMPLE"
    }
  ]
}

DescribeVerifiedAccessInstanceWebAclAssociations

#
Service
ec2

Description

DescribeVerifiedAccessInstanceWebAclAssociations recorded by CloudTrail for Amazon EC2. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "ce3226ef-a11e-4a42-a89e-0db7469c22a5",
  "eventSource": "ec2.amazonaws.com",
  "eventName": "DescribeVerifiedAccessInstanceWebAclAssociations",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "ab0aeb00-ad0f-4c88-b15e-0cf79e15a967",
  "userAgent": "wafv2.amazonaws.com"
}

SharedSnapshotVolumeCreated

#
Service
ec2

Description

SharedSnapshotVolumeCreated recorded by CloudTrail for Amazon EC2. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

{
  "awsRegion": "eu-central-1",
  "eventCategory": "Management",
  "eventID": "3963cccd-8d83-4f30-8235-8e10d0a4aa4e",
  "eventName": "SharedSnapshotVolumeCreated",
  "eventSource": "ec2.amazonaws.com",
  "eventTime": "2021-01-12T08:24:01Z",
  "eventType": "AwsServiceEvent",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "111111111111",
  "requestParameters": null,
  "responseElements": null,
  "serviceEventDetails": {
    "snapshotId": "snap-00878c546b2e4f927"
  },
  "sharedEventID": "1a81e8db-b141-4c9c-bf6c-37b9d47b971a",
  "sourceIPAddress": "ec2.amazonaws.com",
  "userAgent": "ec2.amazonaws.com",
  "userIdentity": {
    "accountId": "111111111111",
    "invokedBy": "ec2.amazonaws.com"
  }
}

References #

AssociateApplicationStatusCheck

#
Service
ec2

Description

Associates an application status check with instances or tags.

BatchModifyIpamRoutingPolicyRegistrations

#
Service
ec2

Description

Modifies multiple routing policy registrations in a single operation.

CreateApplicationStatusCheck

#
Service
ec2

Description

Creates an application status check for monitoring the health of applications running on your instances.

CreateIpamInternetRegistryAssociation

#
Service
ec2

Description

Creates an association between an IPAM and a Regional Internet Registry (RIR) for Resource Public Key Infrastructure (RPKI) management.

CreateIpamRoutingPolicyRegistration

#
Service
ec2

Description

Creates a routing policy registration and publishes Route Origin Authorizations (ROAs) to the RPKI for the specified CIDR prefix and ASNs.

CreateTransitGatewayPolicyTableEntry

#
Service
ec2

Description

Creates an entry in a transit gateway policy table to route matching traffic to a specified route table.

DeleteApplicationStatusCheck

#
Service
ec2

Description

Deletes an application status check.

DeleteIpamInternetRegistryAssociation

#
Service
ec2

Description

Deletes an IPAM internet registry association.

DeleteIpamRoutingPolicyRegistration

#
Service
ec2

Description

Deletes a routing policy registration for a specified CIDR prefix.

DeleteTransitGatewayPolicyTableEntry

#
Service
ec2

Description

Deletes the specified transit gateway policy table entry.

DescribeAccountVpcEncryptionControl

#
Service
ec2

Description

Describes the account-level VPC Encryption Control configuration for your account.

DescribeApplicationStatus

#
Service
ec2

Description

Describes the application status for the specified instances.

DescribeApplicationStatusCheckAssociations

#
Service
ec2

Description

Describes the associations for one or more application status checks.

DescribeApplicationStatusChecks

#
Service
ec2

Description

Describes one or more application status checks.

DescribeIpamInternetRegistryAssociations

#
Service
ec2

Description

Describes one or more IPAM internet registry associations.

DisableApplicationStatusCheckSuppression

#
Service
ec2

Description

Disables suppression of application status checks for the specified instances.

DisassociateApplicationStatusCheck

#
Service
ec2

Description

Disassociates an application status check from instances or tags.

EnableApplicationStatusCheckSuppression

#
Service
ec2

Description

Suppresses application status checks for the specified instances.

EnableIpamInternetRegistryAssociation

#
Service
ec2

Description

Enables Resource Public Key Infrastructure (RPKI) on an existing IPAM internet registry association by providing BGP Public Key Infrastructure (BPKI) certificate details.

GetIpamDiscoveredRoutes

#
Service
ec2

Description

Retrieves Border Gateway Protocol (BGP) routes discovered by IPAM resource discovery for a specified Region.

GetIpamInternetRegistryAssociationAsns

#
Service
ec2

Description

Retrieves Autonomous System Numbers (ASNs) registered with an internet registry for an IPAM internet registry association.

GetIpamInternetRegistryAssociationCidrs

#
Service
ec2

Description

Retrieves IP address CIDRs registered with an internet registry for an IPAM internet registry association.

GetIpamRouteOriginAuthorizations

#
Service
ec2

Description

Retrieves the current Route Origin Authorizations (ROAs) published to the RPKI for an IPAM internet registry association.

GetIpamRouteProtectionFindings

#
Service
ec2

Description

Retrieves route protection findings for an IPAM.

GetIpamRoutingPolicyRegistrationDeltas

#
Service
ec2

Description

Retrieves the history of routing policy registration changes for an IPAM internet registry association.

GetIpamRoutingPolicyRegistrations

#
Service
ec2

Description

Retrieves routing policy registrations for an IPAM internet registry association.

ModifyAccountVpcEncryptionControl

#
Service
ec2

Description

Modifies the account-level VPC Encryption Control configuration.

ModifyApplicationStatusCheck

#
Service
ec2

Description

Modifies an existing application status check.

ModifyIpamRoutingPolicyRegistration

#
Service
ec2

Description

Modifies an existing routing policy registration.

ModifyTransitGatewayPolicyTableEntry

#
Service
ec2

Description

Modifies the specified transit gateway policy table entry.

ModifyVpcEndpointPayerResponsibility

#
Service
ec2

Description

Modifies the billing account for VPC endpoint usage/charges.