EC2
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for EC2 rules that match the service but not a specific eventName. | N | Y |
| Associate | Associates an IAM instance profile with a running or stopped EC2 instance. | N | Y |
| Authorize | Adds outbound rules to a security group to allow traffic to the specified destination. | Y | Y |
| Authorize | Adds inbound rules to a security group to allow traffic from the specified source. | Y | Y |
| Create | Exports a running or stopped EC2 instance to an Amazon S3 bucket in OVA, VHD, or VMDK format. | Y | Y |
| Create | Creates an ED25519 or 2048-bit RSA key pair and stores the public key in EC2, returning the private key material. | Y | Y |
| Create | Creates a new network ACL in the specified VPC. | Y | Y |
| Create | Creates an entry (rule) in a network ACL with the specified rule number, protocol, and traffic action. | Y | Y |
| Create | Creates a route in a route table within a VPC, specifying the destination CIDR and target. | Y | Y |
| Create | Creates a route table for the specified VPC. | Y | Y |
| Create | Creates a security group in a specified VPC or for EC2-Classic. | Y | Y |
| Create | Stores an Amazon Machine Image (AMI) as a single object in an Amazon S3 bucket. | N | Y |
| Create | Creates a traffic mirror session that copies network traffic from a source network interface to a target. | Y | Y |
| Delete | Deletes one or more VPC flow logs. | Y | Y |
| Delete | Deletes the specified network ACL, which must not be associated with any subnets. | Y | Y |
| Delete | Deletes the specified ingress or egress entry (rule) from the specified network ACL. | Y | Y |
| Delete | Deletes the specified route from the specified route table. | Y | Y |
| Delete | Deletes the specified route table, which must not be associated with any subnet. | Y | Y |
| Describe | Describes one or more carrier gateways associated with a VPC. | Y | N |
| Describe | Describes the routes for a specified Client VPN endpoint. | Y | N |
| Describe | Describes one or more DHCP options sets in the account. | Y | N |
| Describe | Describes one or more Amazon Machine Images (AMIs) available to the account. | Y | Y |
| Describe | Describes the specified attribute of the specified EC2 instance. | Y | Y |
| Describe | Returns detailed information about one or more EC2 instances, including their state, type, network interfaces, and associated metadata. | Y | Y |
| Describe | Returns the AWS regions that are enabled for the caller's account, or all regions that are available to EC2. | Y | Y |
| Describe | Returns information about one or more EC2 security groups, including their inbound and outbound rules. | Y | Y |
| Describe | Describes the specified attribute of the specified EBS snapshot. | Y | Y |
| Describe | Describes the storage tier status of one or more EBS snapshots. | Y | N |
| Describe | Describes one or more transit gateway multicast domains. | Y | N |
| Describe | Describes the specified EBS volumes or all EBS volumes in the account. | Y | N |
| Describe | Describes the most recent volume modification request for the specified EBS volumes. | Y | N |
| Describe | Describes the connection notifications for VPC endpoints and VPC endpoint services. | Y | N |
| Describe | Returns information about one or more VPCs in the account, including their CIDR blocks, state, and associated attributes. | Y | Y |
| Disable | Disables default EBS encryption for EBS volumes created in the current account and Region. | Y | Y |
| Disassociate | Disassociates a subnet or gateway from a route table. | Y | Y |
| Enable | Enables access to the EC2 serial console for EC2 instances in the current account and Region. | Y | Y |
| Export | Exports an Amazon Machine Image (AMI) to an Amazon S3 bucket. | N | Y |
| Get | Retrieves the default KMS key ID used for EBS encryption in the current Region. | Y | N |
| Get | Retrieves the default EBS encryption setting for the current account and Region. | Y | N |
| Get | Retrieves the encrypted administrator password for a Windows instance. | Y | Y |
| Get | Gets information about the route table associations for the specified transit gateway route table. | Y | N |
| Import | Imports the public key from an RSA or ED25519 key pair that you created with a third-party tool. | Y | Y |
| Modify | Modifies the specified attribute of the specified AMI, such as launch permissions or description. | Y | Y |
| Modify | Modifies the specified attribute of the specified EC2 instance, such as instance type or user data. | Y | Y |
| Modify | Modifies the rules of a security group. | Y | Y |
| Modify | Adds or removes permission settings for the specified EBS snapshot, such as sharing it with other accounts. | Y | Y |
| Replace | Replaces an entry (rule) in a network ACL, changing subnet traffic filtering. | Y | Y |
| Replace | Replaces an existing route within a route table in a VPC. | Y | Y |
| Replace | Changes the route table associated with a given subnet, internet gateway, or virtual private gateway in a VPC. | Y | Y |
| Revoke | Removes outbound rules from a security group. | Y | Y |
| Revoke | Removes inbound rules from a security group. | Y | Y |
| Start | Starts one or more stopped EC2 instances, transitioning them to the running state. | Y | Y |
| Stop | Stops one or more running EC2 instances, transitioning them to the stopped state. | Y | Y |
| Accept | Accepts an Elastic IP address transfer. | N | N |
| Accept | Accepts a request to assign billing of the available capacity of a shared Capacity Reservation to your account. | N | N |
| Accept | Purchases Convertible Reserved Instance offerings described in the GetReservedInstancesExchangeQuote call. | N | N |
| Accept | Accepts a Transit Gateway attachment request for a Client VPN endpoint. | N | N |
| Accept | Accepts a request to associate subnets with a transit gateway multicast domain. | N | N |
| Accept | Accepts a transit gateway peering attachment request. | N | N |
| Accept | Accepts a request to attach a VPC to a transit gateway. | N | N |
| Accept | Accepts connection requests to your VPC endpoint service. | N | N |
| Accept | Accept a VPC peering connection request. | Y | Y |
| Advertise | Advertises an IPv4 or IPv6 address range that is provisioned for use with your Amazon Web Services resources through bring your own IP addresses (BYOIP). | N | N |
| Allocate | Acquires an Elastic IP address. | Y | N |
| Allocate | Allocates a Dedicated host to your account. | Y | N |
| Allocate | Allocate a CIDR from an IPAM pool. | Y | N |
| Apply | Applies a security group to the association between the target network and the Client VPN endpoint. | N | N |
| Assign | Assigns the specified IPv6 addresses to the specified network interface. | N | N |
| Assign | Assigns one or more secondary private IP addresses to the specified network interface. | Y | N |
| Assign | Assigns private IPv4 addresses to a private NAT gateway. | N | N |
| Associate | Associates an Elastic IP address with an instance or a network interface. | Y | N |
| Associate | Initiates a request to assign billing of the unused capacity of a shared Capacity Reservation to a consumer account that is consolidated under the same Amazon Web Services organizations payer account. | N | N |
| Associate | Associates a target network with a Client VPN endpoint. | N | N |
| Associate | Associates a set of DHCP options (that you've previously created) with the specified VPC, or associates no DHCP options with the VPC. | Y | N |
| Associate | Associates an Identity and Access Management (IAM) role with an Certificate Manager (ACM) certificate. | N | N |
| Associate | Associates one or more targets with an event window. | Y | Y |
| Associate | Associates your Autonomous System Number (ASN) with a BYOIP CIDR that you own in the same Amazon Web Services Region. | N | N |
| Associate | Associates an IPAM resource discovery with an Amazon VPC IPAM. | N | N |
| Associate | Associates Elastic IP addresses (EIPs) and private IPv4 addresses with a public NAT gateway. | N | N |
| Associate | Associates a route server with a VPC to enable dynamic route updates. | N | N |
| Associate | Associates a subnet with a route table. | Y | N |
| Associate | Associates a security group with another VPC in the same Region. | Y | N |
| Associate | Associates a CIDR block with your subnet. | N | N |
| Associate | Associates the specified subnets and transit gateway attachments with the specified transit gateway multicast domain. | N | N |
| Associate | Associates the specified transit gateway attachment with a transit gateway policy table. | N | N |
| Associate | Associates the specified attachment with the specified transit gateway route table. | Y | N |
| Associate | Associates a branch network interface with a trunk network interface. | N | N |
| Associate | Associates a CIDR block with your VPC. | Y | N |
| Attach | Links an EC2-Classic instance to a ClassicLink-enabled VPC through one or more of the VPC's security groups. | N | Y |
| Attach | Attaches a watermark to a non-public AMI. | N | N |
| Attach | Attaches an Internet gateway to a VPC, enabling connectivity between the Internet and the VPC. | Y | Y |
| Attach | Attaches a network interface to an instance. | Y | N |
| Attach | Attaches the specified Amazon Web Services Verified Access trust provider to the specified Amazon Web Services Verified Access instance. | N | N |
| Attach | Attaches an Amazon EBS volume to a running or stopped instance and exposes it to the instance with the specified device name. | Y | N |
| Attach | Attaches a virtual private gateway to a VPC. | Y | N |
| Authorize | Adds an ingress authorization rule to a Client VPN endpoint. | N | N |
| Bundle | Bundles an Amazon instance store-backed Windows instance. | N | Y |
| Cancel | Cancels a bundling operation for an instance store-backed Windows instance. | Y | N |
| Cancel | Cancels the specified Capacity Reservation, releases the reserved capacity, and changes the Capacity Reservation's state to cancelled. | Y | N |
| Cancel | Cancels one or more Capacity Reservation Fleets. | Y | N |
| Cancel | Cancels an active conversion task. | Y | N |
| Cancel | Cancels the generation of an account status report. | Y | N |
| Cancel | Cancels an active export task. | Y | N |
| Cancel | Removes your Amazon Web Services account from the launch permissions for the specified AMI. | Y | N |
| Cancel | Cancels an in-process import virtual machine or import snapshot task. | Y | N |
| Cancel | Cancels the specified Reserved Instance listing in the Reserved Instance Marketplace. | Y | N |
| Cancel | Cancels the specified Spot fleet requests. | Y | N |
| Cancel | Cancels one or more Spot Instance requests. | Y | Y |
| Confirm | Determines whether a product code is associated with an instance. | N | Y |
| Copy | Copies the specified Amazon FPGA Image (AFI) to the current Region. | N | Y |
| Copy | Initiates the copy of an AMI from the specified source region to the region in which the request was made. | Y | Y |
| Copy | Copies a point-in-time snapshot of an Amazon EBS volume and stores it in Amazon S3. | Y | N |
| Copy | Creates a crash-consistent, point-in-time copy of an existing Amazon EBS volume within the same Availability Zone. | N | N |
| Create | Creates a new data export configuration for EC2 Capacity Manager. | N | N |
| Create | Creates a new Capacity Reservation with the specified attributes. | N | N |
| Create | Create a new Capacity Reservation by splitting the capacity of the source Capacity Reservation. | N | N |
| Create | Generates a cancellation quote for a future-dated Capacity Reservation that is within its commitment duration. | N | N |
| Create | Creates a Capacity Reservation Fleet. | N | N |
| Create | Creates a carrier gateway. | N | N |
| Create | Creates a Client VPN endpoint. | N | N |
| Create | Adds a route to a network to a Client VPN endpoint. | N | N |
| Create | Creates a range of customer-owned IP addresses. | N | N |
| Create | Creates a pool of customer-owned IP (CoIP) addresses. | N | N |
| Create | Provides information to AWS about your VPN customer gateway device. | Y | Y |
| Create | Creates a default subnet with a size /20 IPv4 CIDR block in the specified Availability Zone in your default VPC. | N | N |
| Create | Creates a default VPC with a size /16 IPv4 CIDR block and a default subnet in each Availability Zone. | Y | N |
| Create | Delegates ownership of the Amazon EBS root volume for an Apple silicon Mac instance to an administrative user. | N | N |
| Create | Creates a set of DHCP options for your VPC. | Y | N |
| Create | [IPv6 only] Creates an egress-only internet gateway for your VPC. | Y | N |
| Create | Creates an EC2 Fleet that contains the configuration information for On-Demand Instances and Spot Instances. | N | N |
| Create | Creates one or more flow logs to capture IP traffic for a specific network interface, subnet, or VPC. | Y | N |
| Create | Creates an Amazon FPGA Image (AFI) from the specified design checkpoint (DCP). | N | Y |
| Create | Creates an Amazon EBS-backed AMI from an Amazon EBS-backed instance that is either running or stopped. | Y | Y |
| Create | Creates a report that shows how your image is used across other Amazon Web Services accounts. | N | N |
| Create | Creates an EC2 Instance Connect Endpoint. | N | N |
| Create | Creates an event window in which scheduled events for the associated Amazon EC2 instances can run. | Y | Y |
| Create | Creates an Internet gateway for use with a VPC. | Y | Y |
| Create | Creates an interruptible Capacity Reservation by specifying the number of unused instances you want to allocate from your source reservation. | N | N |
| Create | Create an IPAM. | Y | N |
| Create | Create a verification token. | N | N |
| Create | Creates an IPAM policy. | N | N |
| Create | Create an IP address pool for Amazon VPC IP Address Manager (IPAM). | Y | N |
| Create | Creates an IPAM prefix list resolver. | N | N |
| Create | Creates an IPAM prefix list resolver target. | N | N |
| Create | Creates an IPAM resource discovery. | Y | N |
| Create | Create an IPAM scope. | Y | N |
| Create | Creates a launch template. | Y | Y |
| Create | Creates a new version of a launch template. | Y | N |
| Create | Creates a static route for the specified local gateway route table. | N | N |
| Create | Creates a local gateway route table. | N | N |
| Create | Creates a local gateway route table virtual interface group association. | N | N |
| Create | Associates the specified VPC with the specified local gateway route table. | N | N |
| Create | Create a virtual interface for a local gateway. | N | N |
| Create | Create a local gateway virtual interface group. | N | N |
| Create | Creates a System Integrity Protection (SIP) modification task to configure the SIP settings for an x86 Mac instance or Apple silicon Mac instance. | N | N |
| Create | Creates a managed prefix list. | Y | N |
| Create | Creates a NAT gateway in the specified subnet. | Y | Y |
| Create | Creates a Network Access Scope. | Y | N |
| Create | Creates a path to analyze for reachability. | Y | N |
| Create | Creates a network interface in the specified subnet. | Y | N |
| Create | Grants an Amazon Web Services-authorized account permission to attach the specified network interface to an instance in their account. | Y | N |
| Create | Creates a placement group that you launch cluster instances into. | Y | N |
| Create | Creates a public IPv4 address pool. | N | N |
| Create | Replaces the EBS-backed root volume for a running instance with a new volume that is restored to the original root volume's launch state, that is restored to a specific snapshot taken from the original root volume, or that is restored from. | Y | N |
| Create | Creates a listing for Amazon EC2 Reserved Instances to be sold in the Reserved Instance Marketplace. | N | N |
| Create | Starts a task that restores an AMI from an Amazon S3 object that was previously created by using CreateStoreImageTask. | N | Y |
| Create | Creates a new route server to manage dynamic routing in a VPC. | N | N |
| Create | Creates a new endpoint for a route server in a specified subnet. | N | N |
| Create | Creates a new BGP peer for a specified route server endpoint. | N | N |
| Create | Creates a secondary network. | N | N |
| Create | Creates a secondary subnet in a secondary network. | N | N |
| Create | Creates a snapshot of an Amazon EBS volume and stores it in Amazon S3. | Y | N |
| Create | Creates crash-consistent snapshots of multiple EBS volumes attached to an Amazon EC2 instance. | Y | N |
| Create | Creates a datafeed for Spot Instances, enabling you to view Spot Instance usage logs. | N | N |
| Create | Creates a subnet in an existing VPC. | Y | N |
| Create | Creates a subnet CIDR reservation. | Y | N |
| Create | Adds or overwrites one or more tags for the specified EC2 resource or resources. | Y | N |
| Create | Creates a Traffic Mirror filter. | Y | Y |
| Create | Creates a Traffic Mirror filter rule. | Y | Y |
| Create | Creates a target for your Traffic Mirror session. | Y | Y |
| Create | Creates a transit gateway. | Y | N |
| Create | Creates a Connect attachment from a specified transit gateway attachment. | N | N |
| Create | Creates a Connect peer for a specified transit gateway Connect attachment between a transit gateway and an appliance. | N | N |
| Create | Creates a metering policy for a transit gateway to track and measure network traffic. | N | N |
| Create | Creates an entry in a transit gateway metering policy to define traffic measurement rules. | N | N |
| Create | Creates a multicast domain using the specified transit gateway. | N | N |
| Create | Requests a transit gateway peering attachment between the specified transit gateway (requester) and a peer transit gateway (accepter). | N | N |
| Create | Creates a transit gateway policy table. | N | N |
| Create | Creates a reference (route) to a prefix list in a specified transit gateway route table. | N | N |
| Create | Creates a static route for the specified transit gateway route table. | Y | N |
| Create | Creates a route table for the specified transit gateway. | Y | N |
| Create | Advertises a new transit gateway route table. | N | N |
| Create | Attaches the specified VPC to the specified transit gateway. | Y | N |
| Create | An Amazon Web Services Verified Access endpoint is where you define your application along with an optional endpoint-level access policy. | N | N |
| Create | An Amazon Web Services Verified Access group is a collection of Amazon Web Services Verified Access endpoints who's associated applications have similar security requirements. | N | N |
| Create | An Amazon Web Services Verified Access instance is a regional entity that evaluates application requests and grants access only when your security requirements are met. | N | N |
| Create | A trust provider is a third-party entity that creates, maintains, and manages identity information for users and devices. | N | N |
| Create | Creates an Amazon EBS volume that can be attached to an instance in the same Availability Zone. | Y | N |
| Create | Creates a VPC with the specified CIDR block. | Y | Y |
| Create | Create a VPC Block Public Access (BPA) exclusion. | N | N |
| Create | Creates a VPC Encryption Control configuration for a specified VPC. | N | N |
| Create | Creates a VPC endpoint for a specified AWS service. | Y | N |
| Create | Creates a connection notification for a specified VPC endpoint or VPC endpoint service. | N | N |
| Create | Creates a VPC endpoint service to which service consumers (Amazon Web Services accounts, users, and IAM roles) can connect. | N | N |
| Create | Requests a VPC peering connection between two VPCs: a requester VPC that you own and a peer VPC with which to create the connection. | Y | N |
| Create | Creates a VPN concentrator that aggregates multiple VPN connections to a transit gateway. | N | N |
| Create | Creates a VPN connection between an existing virtual private gateway and a VPN customer gateway. | Y | N |
| Create | Creates a static route associated with a VPN connection between an existing virtual private gateway and a VPN customer gateway. | N | N |
| Create | Creates a virtual private gateway. | Y | N |
| Delete | Deletes an existing Capacity Manager data export configuration. | Y | N |
| Delete | Deletes a carrier gateway. | Y | N |
| Delete | Deletes the specified Client VPN endpoint. | Y | N |
| Delete | Deletes a route from a Client VPN endpoint. | Y | N |
| Delete | Deletes a range of customer-owned IP addresses. | Y | N |
| Delete | Deletes a pool of customer-owned IP (CoIP) addresses. | Y | N |
| Delete | Deletes the specified customer gateway. | Y | Y |
| Delete | Deletes the specified set of DHCP options. | Y | N |
| Delete | Deletes an egress-only internet gateway. | Y | N |
| Delete | Deletes the specified EC2 Fleet request. | Y | N |
| Delete | Deletes the specified Amazon FPGA Image (AFI). | Y | N |
| Delete | Deletes the specified image usage report. | Y | N |
| Delete | Deletes the specified EC2 Instance Connect Endpoint. | Y | N |
| Delete | Deletes the specified event window. | Y | Y |
| Delete | Deletes the specified Internet gateway. | Y | Y |
| Delete | Delete an IPAM. | Y | N |
| Delete | Delete a verification token. | Y | N |
| Delete | Deletes an IPAM policy. | Y | N |
| Delete | Delete an IPAM pool. | Y | N |
| Delete | Deletes an IPAM prefix list resolver. | Y | N |
| Delete | Deletes an IPAM prefix list resolver target. | Y | N |
| Delete | Deletes an IPAM resource discovery. | Y | N |
| Delete | Delete the scope for an IPAM. | Y | N |
| Delete | Deletes the specified key pair, by removing the public key from Amazon EC2. | Y | N |
| Delete | Deletes a launch template. | Y | N |
| Delete | Deletes one or more versions of a launch template. | Y | N |
| Delete | Deletes the specified route from the specified local gateway route table. | Y | N |
| Delete | Deletes a local gateway route table. | Y | N |
| Delete | Deletes a local gateway route table virtual interface group association. | Y | N |
| Delete | Deletes the specified association between a VPC and local gateway route table. | Y | N |
| Delete | Deletes the specified local gateway virtual interface. | Y | N |
| Delete | Delete the specified local gateway interface group. | Y | N |
| Delete | Deletes the specified managed prefix list. | Y | N |
| Delete | Deletes the specified NAT gateway. | Y | N |
| Delete | Deletes the specified Network Access Scope. | Y | N |
| Delete | Deletes the specified Network Access Scope analysis. | Y | N |
| Delete | Deletes the specified network insights analysis. | Y | N |
| Delete | Deletes the specified path. | Y | N |
| Delete | Deletes the specified network interface. | Y | N |
| Delete | Deletes a permission for a network interface. | Y | N |
| Delete | Deletes the specified placement group. | Y | N |
| Delete | Delete a public IPv4 pool. | Y | N |
| Delete | Deletes the queued purchases for the specified Reserved Instances. | Y | N |
| Delete | Deletes the specified route server. | Y | N |
| Delete | Deletes the specified route server endpoint. | Y | N |
| Delete | Deletes the specified BGP peer from a route server. | Y | N |
| Delete | Deletes a secondary network. | Y | N |
| Delete | Deletes a secondary subnet. | Y | N |
| Delete | Deletes a security group. | Y | Y |
| Delete | Deletes the specified snapshot. | Y | N |
| Delete | Deletes the datafeed for Spot Instances. | Y | N |
| Delete | Deletes the specified subnet. | Y | N |
| Delete | Deletes a subnet CIDR reservation. | Y | N |
| Delete | Deletes the specified set of tags from the specified set of resources. | Y | N |
| Delete | Deletes the specified Traffic Mirror filter. | Y | Y |
| Delete | Deletes the specified Traffic Mirror rule. | Y | Y |
| Delete | Deletes the specified Traffic Mirror session. | Y | Y |
| Delete | Deletes the specified Traffic Mirror target. | Y | Y |
| Delete | Deletes the specified transit gateway. | Y | N |
| Delete | Deletes a Transit Gateway attachment for a Client VPN endpoint. | Y | N |
| Delete | Deletes the specified Connect attachment. | Y | N |
| Delete | Deletes the specified Connect peer. | Y | N |
| Delete | Deletes a transit gateway metering policy. | Y | N |
| Delete | Deletes an entry from a transit gateway metering policy. | Y | N |
| Delete | Deletes the specified transit gateway multicast domain. | Y | N |
| Delete | Deletes a transit gateway peering attachment. | Y | N |
| Delete | Deletes the specified transit gateway policy table. | Y | N |
| Delete | Deletes a reference (route) to a prefix list in a specified transit gateway route table. | Y | N |
| Delete | Deletes the specified route from the specified transit gateway route table. | Y | N |
| Delete | Deletes the specified transit gateway route table. | Y | N |
| Delete | Advertises to the transit gateway that a transit gateway route table is deleted. | Y | N |
| Delete | Deletes the specified VPC attachment. | Y | N |
| Delete | Delete an Amazon Web Services Verified Access endpoint. | Y | N |
| Delete | Delete an Amazon Web Services Verified Access group. | Y | N |
| Delete | Delete an Amazon Web Services Verified Access instance. | Y | N |
| Delete | Delete an Amazon Web Services Verified Access trust provider. | Y | N |
| Delete | Deletes the specified Amazon EBS volume. | Y | N |
| Delete | Deletes the specified VPC. | Y | Y |
| Delete | Delete a VPC Block Public Access (BPA) exclusion. | Y | N |
| Delete | Deletes a VPC Encryption Control configuration. | Y | N |
| Delete | Deletes the specified VPC endpoint connection notifications. | Y | N |
| Delete | Deletes one or more specified VPC endpoints. | Y | N |
| Delete | Deletes the specified VPC endpoint service configurations. | Y | N |
| Delete | Deletes a VPC peering connection. | Y | N |
| Delete | Deletes the specified VPN concentrator. | Y | N |
| Delete | Deletes the specified VPN connection. | Y | N |
| Delete | Deletes the specified static route associated with a VPN connection between an existing virtual private gateway and a VPN customer gateway. | Y | N |
| Delete | Deletes the specified virtual private gateway. | Y | N |
| Deprovision | Releases the specified address range that you provisioned for use with your Amazon Web Services resources through bring your own IP addresses (BYOIP) and deletes the corresponding address pool. | N | N |
| Deprovision | Deprovisions your Autonomous System Number (ASN) from your Amazon Web Services account. | N | N |
| Deprovision | Deprovision a CIDR provisioned from an IPAM pool. | Y | N |
| Deprovision | Deprovision a CIDR from a public IPv4 pool. | N | N |
| Deregister | Deregisters the specified AMI. | Y | N |
| Deregister | Deregisters tag keys to prevent tags that have the specified tag keys from being included in scheduled event notifications for resources in the Region. | Y | Y |
| Deregister | Deregisters the specified members (network interfaces) from the transit gateway multicast group. | Y | N |
| Deregister | Deregisters the specified sources (network interfaces) from the transit gateway multicast group. | Y | N |
| Describe | Describes the specified attribute of your AWS account. | Y | N |
| Describe | Describes one or more of your Elastic IP addresses. | Y | N |
| Describe | Describes the attributes of the specified Elastic IP addresses. | Y | N |
| Describe | Describes an Elastic IP address transfer. | Y | N |
| Describe | Describes the longer ID format settings for all resource types in a specific Region. | Y | N |
| Describe | Describes one or more of the Availability Zones that are available to you. | Y | N |
| Describe | Describes the current Infrastructure Performance metric subscriptions. | Y | N |
| Describe | Describes one or more of your bundling tasks. | Y | N |
| Describe | Describes the IP address ranges that were provisioned for use with Amazon Web Services resources through through bring your own IP addresses (BYOIP). | Y | N |
| Describe | Describes the events for the specified Capacity Block extension during the specified time. | Y | N |
| Describe | Describes Capacity Block extension offerings available for purchase in the Amazon Web Services Region that you're currently using. | Y | N |
| Describe | Describes Capacity Block offerings available for purchase in the Amazon Web Services Region that you're currently using. | Y | N |
| Describe | Describes details about Capacity Blocks in the Amazon Web Services Region that you're currently using. | Y | N |
| Describe | Describes the availability of capacity for the specified Capacity blocks, or all of your Capacity Blocks. | Y | N |
| Describe | Describes one or more Capacity Manager data export configurations. | Y | N |
| Describe | Describes a request to assign the billing of the unused capacity of a Capacity Reservation. | Y | N |
| Describe | Describes one or more Capacity Reservation cancellation quotes. | Y | N |
| Describe | Describes one or more Capacity Reservation Fleets. | Y | N |
| Describe | Describes one or more of your Capacity Reservations. | Y | N |
| Describe | Describes a tree-based hierarchy that represents the physical host placement of your pending or active Capacity Reservations within an Availability Zone or Local Zone. | Y | N |
| Describe | Describes one or more of your linked EC2-Classic instances. | Y | N |
| Describe | Describes the authorization rules for a specified Client VPN endpoint. | Y | N |
| Describe | Describes active client connections and connections that have been terminated within the last 60 minutes for the specified Client VPN endpoint. | Y | N |
| Describe | Describes one or more Client VPN endpoints in the account. | Y | N |
| Describe | Describes the target networks associated with the specified Client VPN endpoint. | Y | N |
| Describe | Describes the specified customer-owned address pools or all of your customer-owned address pools. | Y | N |
| Describe | Describes one or more of your conversion tasks. | Y | N |
| Describe | Describes one or more of your VPN customer gateways. | Y | N |
| Describe | Describes the metadata of an account status report, including the status of the report. | Y | N |
| Describe | Describes your egress-only internet gateways. | Y | N |
| Describe | Amazon Elastic Graphics reached end of life on January 8, 2024. | Y | N |
| Describe | Describes the specified export image tasks or all of your export image tasks. | Y | N |
| Describe | Describes one or more of your export tasks. | Y | N |
| Describe | Describe details for Windows AMIs that are configured for Windows fast launch. | Y | N |
| Describe | Describes the state of fast snapshot restores for your snapshots. | Y | N |
| Describe | Describes the events for the specified EC2 Fleet during the specified time. | Y | N |
| Describe | Describes the running instances for the specified EC2 Fleet. | Y | N |
| Describe | Describes the specified EC2 Fleet or all of your EC2 Fleets. | Y | N |
| Describe | Describes one or more flow logs. | Y | N |
| Describe | Describes the specified attribute of the specified Amazon FPGA Image (AFI). | Y | N |
| Describe | Describes the Amazon FPGA Images (AFIs) available to you. | Y | N |
| Describe | Describes the Dedicated Host Reservations that are available to purchase. | Y | N |
| Describe | Describes Dedicated Host Reservations which are associated with Dedicated Hosts in your account. | Y | N |
| Describe | Describes one or more of your Dedicated hosts. | Y | N |
| Describe | Describes your IAM instance profile associations. | Y | N |
| Describe | Describes the ID format settings for resources for the specified IAM user, IAM role, or root user. | Y | N |
| Describe | Describes the ID format settings for your resources on a per-region basis, for example, to view which resource types are enabled for longer IDs. | Y | N |
| Describe | Describes the specified attribute of the specified AMI. | Y | N |
| Describe | Describes your Amazon Web Services resources that are referencing the specified images. | Y | N |
| Describe | Describes the entries in image usage reports, showing how your images are used across other Amazon Web Services accounts. | Y | N |
| Describe | Describes the configuration and status of image usage reports, filtered by report IDs or image IDs. | Y | N |
| Describe | Displays details about an import virtual machine or import snapshot tasks that are already created. | Y | N |
| Describe | Displays details about an import snapshot tasks that is already created. | Y | N |
| Describe | Describes the specified EC2 Instance Connect Endpoints or all EC2 Instance Connect Endpoints. | Y | N |
| Describe | Describes the credit option for CPU usage of the specified burstable performance instances. | Y | N |
| Describe | Describes the tag keys that are registered to appear in scheduled event notifications for resources in the current Region. | Y | N |
| Describe | Describes the specified event windows or all event windows. | Y | N |
| Describe | Describes the AMI that was used to launch an instance, even if the AMI is deprecated, deregistered, made private (no longer public or shared with your account), or not allowed. | Y | N |
| Describe | Describes the historical SQL Server High Availability states for Amazon EC2 instances that are enabled for Amazon EC2 High Availability for SQL Server monitoring. | Y | N |
| Describe | Describes the SQL Server High Availability states for Amazon EC2 instances that are enabled for Amazon EC2 High Availability for SQL Server monitoring. | Y | N |
| Describe | Describes the status of one or more instances, including any scheduled events. | Y | N |
| Describe | Describes a tree-based hierarchy that represents the physical host placement of your EC2 instances within an Availability Zone or Local Zone. | Y | N |
| Describe | Lists the instance types that are offered for the specified location. | Y | N |
| Describe | Describes the specified instance types. | Y | N |
| Describe | Describes one or more of your Internet gateways. | Y | N |
| Describe | Describes your Autonomous System Numbers (ASNs), their provisioning statuses, and the BYOIP CIDRs with which they are associated. | Y | N |
| Describe | Describe verification tokens. | Y | N |
| Describe | Describes one or more IPAM policies. | Y | N |
| Describe | Describes IPAM pool allocations. | Y | N |
| Describe | Get information about your IPAM pools. | Y | N |
| Describe | Describes one or more IPAM prefix list resolvers. | Y | N |
| Describe | Describes one or more IPAM prefix list resolver Targets. | Y | N |
| Describe | Describes IPAM resource discoveries. | Y | N |
| Describe | Describes resource discovery association with an Amazon VPC IPAM. | Y | N |
| Describe | Get information about your IPAM pools. | Y | N |
| Describe | Get information about your IPAM scopes. | Y | N |
| Describe | Describes your IPv6 address pools. | Y | N |
| Describe | Describes one or more of your key pairs. | Y | N |
| Describe | Describes one or more launch templates. | Y | N |
| Describe | Describes one or more versions of a specified launch template. | Y | N |
| Describe | Describes one or more local gateway route tables. | Y | N |
| Describe | Describes the associations between virtual interface groups and local gateway route tables. | Y | N |
| Describe | Describes the specified associations between VPCs and local gateway route tables. | Y | N |
| Describe | Describes one or more local gateways. | Y | N |
| Describe | Describes the specified local gateway virtual interface groups. | Y | N |
| Describe | Describes the specified local gateway virtual interfaces. | Y | N |
| Describe | Describes the lock status for a snapshot. | Y | N |
| Describe | Describes the specified EC2 Mac Dedicated Host or all of your EC2 Mac Dedicated Hosts. | Y | N |
| Describe | Describes a System Integrity Protection (SIP) modification task or volume ownership delegation task for an Amazon EC2 Mac instance. | Y | N |
| Describe | Describes your managed prefix lists and any Amazon Web Services-managed prefix lists. | Y | N |
| Describe | Describes your Elastic IP addresses that are being moved to the EC2-VPC platform, or that are being restored to the EC2-Classic platform. | Y | N |
| Describe | Describes one or more of the your NAT gateways. | Y | N |
| Describe | Describes one or more of your network ACLs. | Y | N |
| Describe | Describes the specified Network Access Scope analyses. | Y | N |
| Describe | Describes the specified Network Access Scopes. | Y | N |
| Describe | Describes one or more of your network insights analyses. | Y | N |
| Describe | Describes one or more of your paths. | Y | N |
| Describe | Describes a network interface attribute. | Y | N |
| Describe | Describes the permissions for your network interfaces. | Y | N |
| Describe | Describes one or more of your network interfaces. | Y | N |
| Describe | Describes the Outposts link aggregation groups (LAGs). | Y | N |
| Describe | Describes one or more of your placement groups. | Y | N |
| Describe | Describes available AWS services in a prefix list format, which includes the prefix list name and prefix list ID of the service and the IP address range for the service. | Y | N |
| Describe | Describes the ID format settings for the root user and all IAM roles and IAM users that have explicitly specified a longer ID (17-character ID) preference. | Y | N |
| Describe | Describes the specified IPv4 address pools. | Y | N |
| Describe | Describes a root volume replacement task. | Y | N |
| Describe | Describes one or more of the Reserved Instances that you purchased. | Y | N |
| Describe | Describes your account's Reserved Instance listings in the Reserved Instance Marketplace. | Y | N |
| Describe | Describes the modifications made to your Reserved Instances. | Y | N |
| Describe | Describes Reserved Instance offerings that are available for purchase. | Y | N |
| Describe | Describes one or more route server endpoints. | Y | N |
| Describe | Describes one or more route server peers. | Y | N |
| Describe | Describes one or more route servers. | Y | N |
| Describe | Describes one or more of your route tables. | Y | N |
| Describe | Finds available schedules that meet the specified criteria. | Y | N |
| Describe | Describes one or more of your Scheduled Instances. | Y | N |
| Describe | Describes one or more of your secondary interfaces. | Y | N |
| Describe | Describes one or more secondary networks. | Y | N |
| Describe | Describes one or more of your secondary subnets. | Y | N |
| Describe | [EC2-VPC only] Describes the VPCs on the other side of a VPC peering connection that are referencing the security groups you've specified in this request. | Y | Y |
| Describe | Describes one or more of your security group rules. | Y | Y |
| Describe | Describes security group VPC associations made with AssociateSecurityGroupVpc. | Y | N |
| Describe | Describes the Outpost service link virtual interfaces. | Y | N |
| Describe | Describes one or more of the Amazon EBS snapshots available to you. | Y | N |
| Describe | Describes the datafeed for Spot Instances. | Y | N |
| Describe | Describes the running instances for the specified Spot fleet. | Y | N |
| Describe | Describes the events for the specified Spot fleet request during the specified time. | Y | N |
| Describe | Describes your Spot fleet requests. | Y | N |
| Describe | Describes the Spot Instance requests that belong to your account. | Y | N |
| Describe | Describes the Spot Price history. | Y | N |
| Describe | [EC2-VPC only] Describes the stale security group rules for security groups in a specified VPC. | Y | N |
| Describe | Describes the progress of the AMI store tasks. | Y | N |
| Describe | Describes one or more of your subnets. | Y | Y |
| Describe | Describes one or more of the tags for your EC2 resources. | Y | N |
| Describe | Describe traffic mirror filters that determine the traffic that is mirrored. | Y | N |
| Describe | Describes one or more Traffic Mirror filters. | Y | N |
| Describe | Describes one or more Traffic Mirror sessions. | Y | N |
| Describe | Information about one or more Traffic Mirror targets. | Y | N |
| Describe | Describes one or more attachments between resources and transit gateways. | Y | N |
| Describe | Describes one or more Connect peers. | Y | N |
| Describe | Describes one or more Connect attachments. | Y | N |
| Describe | Describes one or more transit gateway metering policies. | Y | N |
| Describe | Describes your transit gateway peering attachments. | Y | N |
| Describe | Describes one or more transit gateway route policy tables. | Y | N |
| Describe | Describes one or more transit gateway route table advertisements. | Y | N |
| Describe | Describes one or more transit gateway route tables. | Y | N |
| Describe | Describes one or more transit gateways. | Y | N |
| Describe | Describes one or more VPC attachments. | Y | N |
| Describe | Describes one or more network interface trunk associations. | Y | N |
| Describe | Describes the specified Amazon Web Services Verified Access endpoints. | Y | N |
| Describe | Describes the specified Verified Access groups. | Y | N |
| Describe | Describes the specified Amazon Web Services Verified Access instances. | Y | N |
| Describe | Describes the specified Amazon Web Services Verified Access instances. | Y | N |
| Describe | Describes the specified Amazon Web Services Verified Access trust providers. | Y | N |
| Describe | Describes the specified attribute of the specified volume. | Y | N |
| Describe | Describes the status of the specified volumes. | Y | N |
| Describe | Describes the specified attribute of the specified VPC. | Y | N |
| Describe | Describe VPC Block Public Access (BPA) exclusions. | Y | N |
| Describe | Describe VPC Block Public Access (BPA) options. | Y | N |
| Describe | Describes the ClassicLink status of one or more VPCs. | Y | N |
| Describe | Describes the ClassicLink DNS support status of one or more VPCs. | Y | N |
| Describe | Describes one or more VPC Encryption Control configurations. | Y | N |
| Describe | Describes the VPC resources, VPC endpoint services, Amazon Lattice services, or service networks associated with the VPC endpoint. | Y | N |
| Describe | Describes the VPC endpoint connections to your VPC endpoint services, including any endpoints that are pending your acceptance. | Y | N |
| Describe | Describes one or more of your VPC endpoints. | Y | N |
| Describe | Describes the VPC endpoint service configurations in your account (your services). | Y | N |
| Describe | Describes the principals (service consumers) that are permitted to discover your VPC endpoint service. | Y | N |
| Describe | Describes all supported AWS services that can be specified when creating a VPC endpoint. | Y | N |
| Describe | Describes one or more of your VPC peering connections. | Y | N |
| Describe | Describes one or more of your VPN concentrators. | Y | N |
| Describe | Describes one or more of your VPN connections. | Y | N |
| Describe | Describes one or more of your virtual private gateways. | Y | N |
| Detach | Unlinks (detaches) a linked EC2-Classic instance from a VPC. | Y | Y |
| Detach | Removes a watermark from the specified AMI. | Y | N |
| Detach | Detaches an Internet gateway from a VPC, disabling connectivity between the Internet and the VPC. | Y | Y |
| Detach | Detaches a network interface from an instance. | Y | N |
| Detach | Detaches the specified Amazon Web Services Verified Access trust provider from the specified Amazon Web Services Verified Access instance. | Y | N |
| Detach | Detaches an Amazon EBS volume from an instance. | Y | N |
| Detach | Detaches a virtual private gateway from a VPC. | Y | N |
| Disable | Disables Elastic IP address transfer. | Y | N |
| Disable | Disables Allowed AMIs for your account in the specified Amazon Web Services Region. | Y | N |
| Disable | Disables Infrastructure Performance metric subscriptions. | Y | N |
| Disable | Disables EC2 Capacity Manager for your account. | Y | N |
| Disable | Discontinue Windows fast launch for a Windows AMI, and clean up existing pre-provisioned snapshots. | Y | N |
| Disable | Disables fast snapshot restores for the specified snapshots in the specified Availability Zones. | Y | N |
| Disable | Sets the AMI state to disabled and removes all launch permissions from the AMI. | Y | N |
| Disable | Disables block public access for AMIs at the account level in the specified Amazon Web Services Region. | Y | N |
| Disable | Cancels the deprecation of the specified AMI. | Y | N |
| Disable | Disables deregistration protection for an AMI. | Y | N |
| Disable | Disable Amazon EC2 instances running in an SQL Server High Availability cluster from SQL Server High Availability instance standby detection monitoring. | Y | N |
| Disable | Disable the IPAM account. | Y | N |
| Disable | Disables an IPAM policy. | Y | N |
| Disable | Disables route propagation from a route server to a specified route table. | Y | N |
| Disable | Disables access to the EC2 serial console of all instances for your account. | Y | N |
| Disable | Disables the block public access for snapshots setting at the account level for the specified Amazon Web Services Region. | Y | N |
| Disable | Disables the specified resource attachment from propagating routes to the specified propagation route table. | Y | N |
| Disable | Disables a virtual private gateway (VGW) from propagating routes to a specified route table of a VPC. | Y | N |
| Disable | Disables ClassicLink for a VPC. | Y | Y |
| Disable | Disables ClassicLink DNS support for a VPC. | Y | N |
| Disassociate | Disassociates an Elastic IP address from the instance or network interface it's associated with. | Y | N |
| Disassociate | Cancels a pending request to assign billing of the unused capacity of a Capacity Reservation to a consumer account, or revokes a request that has already been accepted. | Y | N |
| Disassociate | Disassociates a target network from the specified Client VPN endpoint. | Y | N |
| Disassociate | Disassociates an IAM role from an Certificate Manager (ACM) certificate. | Y | N |
| Disassociate | Disassociates an IAM instance profile from a running or stopped instance. | Y | Y |
| Disassociate | Disassociates one or more targets from an event window. | Y | Y |
| Disassociate | Remove the association between your Autonomous System Number (ASN) and your BYOIP CIDR. | Y | N |
| Disassociate | Disassociates a resource discovery from an Amazon VPC IPAM. | Y | N |
| Disassociate | Disassociates secondary Elastic IP addresses (EIPs) from a public NAT gateway. | Y | N |
| Disassociate | Disassociates a route server from a VPC. | Y | N |
| Disassociate | Disassociates a security group from a VPC. | Y | N |
| Disassociate | Disassociates a CIDR block from a subnet. | Y | N |
| Disassociate | Disassociates the specified subnets from the transit gateway multicast domain. | Y | N |
| Disassociate | Removes the association between an an attachment and a policy table. | Y | N |
| Disassociate | Disassociates a resource attachment from a transit gateway route table. | Y | N |
| Disassociate | Removes an association between a branch network interface with a trunk network interface. | Y | N |
| Disassociate | Disassociates a CIDR block from a VPC. | Y | N |
| Enable | Enables Elastic IP address transfer. | N | N |
| Enable | Enables Allowed AMIs for your account in the specified Amazon Web Services Region. | Y | N |
| Enable | Enables Infrastructure Performance subscriptions. | Y | N |
| Enable | Enables EC2 Capacity Manager for your account. | N | N |
| Enable | Enables EBS encryption by default for your account in the current Region. | Y | N |
| Enable | When you enable Windows fast launch for a Windows AMI, images are pre-provisioned, using snapshots to launch instances up to 65% faster. | N | N |
| Enable | Enables fast snapshot restores for the specified snapshots in the specified Availability Zones. | Y | N |
| Enable | Re-enables a disabled AMI. | Y | N |
| Enable | Enables block public access for AMIs at the account level in the specified Amazon Web Services Region. | Y | N |
| Enable | Enables deprecation of the specified AMI at the specified date and time. | Y | N |
| Enable | Enables deregistration protection for an AMI. | N | N |
| Enable | Enable Amazon EC2 instances running in an SQL Server High Availability cluster for SQL Server High Availability instance standby detection monitoring. | N | N |
| Enable | Enable an Organizations member account as the IPAM admin account. | N | N |
| Enable | Enables an IPAM policy. | N | N |
| Enable | Establishes a trust relationship between Reachability Analyzer and Organizations. | N | N |
| Enable | Defines which route tables the route server can update with routes. | N | N |
| Enable | Enables or modifies the block public access for snapshots setting at the account level for the specified Amazon Web Services Region. | Y | N |
| Enable | Enables the specified attachment to propagate routes to the specified propagation route table. | Y | N |
| Enable | Enables a virtual private gateway (VGW) to propagate routes to the specified route table of a VPC. | Y | N |
| Enable | Enables I/O operations for a volume that had I/O operations disabled because the data on the volume was potentially inconsistent. | Y | N |
| Enable | Enables a VPC for ClassicLink. | N | Y |
| Enable | Enables a VPC to support DNS hostname resolution for ClassicLink. | N | N |
| Export | Downloads the client certificate revocation list for the specified Client VPN endpoint. | N | N |
| Export | Downloads the contents of the Client VPN endpoint configuration file for the specified Client VPN endpoint. | N | N |
| Export | Exports routes from the specified transit gateway route table to the specified S3 bucket. | N | N |
| Export | Exports the client configuration for a Verified Access instance. | N | N |
| Get | Returns the currently negotiated security parameters for an active VPN tunnel, including IKE version, DH groups, encryption algorithms, and integrity algorithms. | Y | N |
| Get | Gets the current state of the Allowed AMIs setting and the list of Allowed AMIs criteria at the account level in the specified Region. | Y | N |
| Get | Returns the IAM roles that are associated with the specified ACM (ACM) certificate. | Y | N |
| Get | Gets information about the IPv6 CIDR block associations for a specified IPv6 address pool. | Y | N |
| Get | Gets network performance data. | Y | N |
| Get | Retrieves the current configuration and status of EC2 Capacity Manager for your account, including enablement status, Organizations access settings, and data ingestion status. | Y | N |
| Get | Retrieves capacity usage metrics for your EC2 resources. | Y | N |
| Get | Retrieves the available dimension values for capacity metrics within a specified time range. | Y | N |
| Get | Retrieves the tag keys that are currently being monitored by EC2 Capacity Manager. | Y | N |
| Get | Gets usage information about a Capacity Reservation. | Y | N |
| Get | Describes the allocations from the specified customer-owned address pool. | Y | N |
| Get | Gets the console output for the specified instance. | Y | N |
| Get | Retrieve a JPG-format screenshot of a running instance to help with troubleshooting. | Y | N |
| Get | Retrieves a summary of the account status report. | Y | N |
| Get | Describes the default credit option for CPU usage of a burstable performance instance family. | Y | N |
| Get | Gets the enabled IPAM policy. | Y | N |
| Get | Generates a CloudFormation template that streamlines and automates the integration of VPC flow logs with Amazon Athena. | Y | N |
| Get | Lists the resource groups to which a Capacity Reservation has been added. | Y | N |
| Get | Preview a reservation purchase with configurations that match those of your Dedicated Host. | Y | N |
| Get | Retrieves the ancestry chain of the specified AMI, tracing its lineage back to the root AMI. | Y | N |
| Get | Gets the current state of block public access for AMIs at the account level in the specified Amazon Web Services Region. | Y | N |
| Get | Gets the default instance metadata service (IMDS) settings that are set at the account level in the specified Amazon Web Services Region. | Y | N |
| Get | Gets the public endorsement key associated with the Nitro Trusted Platform Module (NitroTPM) for the specified instance. | Y | N |
| Get | Returns a list of instance types with the specified instance attributes. | Y | N |
| Get | A binary representation of the UEFI variable store. | Y | N |
| Get | Retrieve historical information about a CIDR within an IPAM scope. | Y | N |
| Get | Gets IPAM discovered accounts. | Y | N |
| Get | Gets the public IP addresses that have been discovered by IPAM. | Y | N |
| Get | Returns the resource CIDRs that are monitored as part of a resource discovery. | Y | N |
| Get | Gets the allocation rules for an IPAM policy. | Y | N |
| Get | Gets the Amazon Web Services Organizations targets for an IPAM policy. | Y | N |
| Get | Get a list of all the CIDR allocations in an IPAM pool. | Y | N |
| Get | Get the CIDRs provisioned to an IPAM pool. | Y | N |
| Get | Retrieves the CIDR selection rules for an IPAM prefix list resolver. | Y | N |
| Get | Retrieves the CIDR entries for a specific version of an IPAM prefix list resolver. | Y | N |
| Get | Retrieves version information for an IPAM prefix list resolver. | Y | N |
| Get | Returns resource CIDRs managed by IPAM in a given scope. | Y | N |
| Get | Retrieves the configuration data of the specified instance. | Y | N |
| Get | Gets information about the resources that are associated with the specified managed prefix list. | Y | N |
| Get | Gets information about the entries for a specified managed prefix list. | Y | N |
| Get | Retrieves the managed resource visibility configuration for the account. | Y | N |
| Get | Gets the findings for the specified Network Access Scope analysis. | Y | N |
| Get | Gets the content for the specified Network Access Scope. | Y | N |
| Get | Returns details about the values and term of your specified Convertible Reserved Instances. | Y | N |
| Get | Gets information about the associations for the specified route server. | Y | N |
| Get | Gets information about the route propagations for the specified route server. | Y | N |
| Get | Gets the routing database for the specified route server. | Y | N |
| Get | Gets security groups that can be associated by the Amazon Web Services account making the request with network interfaces in the specified VPC. | Y | N |
| Get | Retrieves the access status of your account to the EC2 serial console of all instances. | Y | N |
| Get | Gets the current state of block public access for snapshots setting for the account and Region. | Y | N |
| Get | Calculates the Spot placement score for a Region or Availability Zone based on the specified target capacity and compute requirements. | Y | N |
| Get | Gets information about the subnet CIDR reservations. | Y | N |
| Get | Lists the route tables to which the specified resource attachment propagates routes. | Y | N |
| Get | Retrieves the entries for a transit gateway metering policy. | Y | N |
| Get | Gets information about the associations for the transit gateway multicast domain. | Y | N |
| Get | Gets a list of the transit gateway policy table associations. | Y | N |
| Get | Returns a list of transit gateway policy table entries. | Y | N |
| Get | Gets information about the prefix list references in a specified transit gateway route table. | Y | N |
| Get | Gets information about the route table propagations for the specified transit gateway route table. | Y | N |
| Get | Get the Verified Access policy associated with the endpoint. | Y | N |
| Get | Gets the targets for the specified network CIDR endpoint for Verified Access. | Y | N |
| Get | Shows the contents of the Verified Access policy associated with the group. | Y | N |
| Get | Gets information about resources in a VPC that are blocking encryption enforcement. | Y | N |
| Get | Download an Amazon Web Services-provided sample configuration file to be used with the customer gateway device specified for your Site-to-Site VPN connection. | Y | N |
| Get | Obtain a list of customer gateway devices for which sample configuration files can be provided. | Y | N |
| Get | Get details of available tunnel endpoint maintenance. | Y | N |
| Import | Uploads a client certificate revocation list to the specified Client VPN endpoint. | N | N |
| Import | Import single or multi-volume disk images or Amazon EBS snapshots into an Amazon Machine Image (AMI). | N | Y |
| Import | Creates an import instance task using metadata from the specified disk image. | N | Y |
| Import | Import a disk into an Amazon Elastic Block Store (Amazon EBS) snapshot. | N | N |
| Import | Creates an import volume task using metadata from the specified disk image. | N | N |
| List | Lists one or more AMIs that are currently in the Recycle Bin. | Y | N |
| List | Lists one or more snapshots that are currently in the Recycle Bin. | Y | N |
| List | Lists one or more volumes that are currently in the Recycle Bin. | Y | N |
| Lock | Locks an Amazon EBS snapshot in either governance or compliance mode to protect it against accidental or malicious deletions for a specific duration. | Y | N |
| Modify | Modifies an attribute of the specified Elastic IP address. | Y | N |
| Modify | Changes the opt-in status of the specified zone group for your account. | Y | N |
| Modify | Modifies a Capacity Reservation's capacity, instance eligibility, and the conditions under which it is to be released. | Y | N |
| Modify | Modifies a Capacity Reservation Fleet. | Y | N |
| Modify | Modifies the specified Client VPN endpoint. | Y | N |
| Modify | Modifies the default credit option for CPU usage of burstable performance instances. | Y | N |
| Modify | Changes the default KMS key for EBS encryption by default for your account in this Region. | Y | N |
| Modify | Modifies the specified EC2 Fleet. | Y | N |
| Modify | Modifies the specified attribute of the specified Amazon FPGA Image (AFI). | Y | N |
| Modify | Modify the auto-placement setting of a Dedicated host. | Y | N |
| Modify | Modifies the ID format of a resource for a specified IAM user, IAM role, or the root user for an account; or all IAM users, IAM roles, and the root user for an account. | Y | N |
| Modify | Modifies the ID format for the specified resource on a per-region basis. | Y | N |
| Modify | Modifies the Capacity Reservation settings for a stopped instance. | Y | Y |
| Modify | Modifies the specified EC2 Instance Connect Endpoint. | Y | N |
| Modify | By default, all vCPUs for the instance type are active when you launch an instance. | Y | N |
| Modify | Modifies the credit option for CPU usage on a running or stopped burstable performance instance. | Y | Y |
| Modify | Modifies the start time for a scheduled Amazon EC2 instance event. | Y | Y |
| Modify | Modifies the specified event window. | Y | Y |
| Modify | Modifies the recovery behavior of your instance to disable simplified automatic recovery or set the recovery behavior to default. | Y | Y |
| Modify | Modifies the default instance metadata service (IMDS) settings at the account level in the specified Amazon Web Services Region. | Y | N |
| Modify | Modify the instance metadata parameters on a running or stopped instance. | Y | Y |
| Modify | Change the configuration of the network performance options for an existing instance. | Y | N |
| Modify | Set the instance affinity value for a specific stopped instance and modify the instance tenancy setting. | Y | Y |
| Modify | Modify the configurations of an IPAM. | Y | N |
| Modify | Modifies the allocation rules in an IPAM policy. | Y | N |
| Modify | Modify the configurations of an IPAM pool. | Y | N |
| Modify | Modifies the description of an IPAM pool allocation. | Y | N |
| Modify | Modifies an IPAM prefix list resolver. | Y | N |
| Modify | Modifies an IPAM prefix list resolver target. | Y | N |
| Modify | Modify a resource CIDR. | Y | N |
| Modify | Modifies a resource discovery. | Y | N |
| Modify | Modify an IPAM scope. | Y | N |
| Modify | Modifies a launch template. | Y | N |
| Modify | Modifies the specified local gateway route. | Y | N |
| Modify | Modifies the specified managed prefix list. | Y | N |
| Modify | Modifies the managed resource visibility configuration for the account. | Y | N |
| Modify | Modifies the specified network interface attribute. | Y | N |
| Modify | Modifies the options for instance hostnames for the specified instance. | Y | N |
| Modify | Modify public hostname options for a network interface. | Y | N |
| Modify | Modifies the Availability Zone, instance count, instance type, or network platform (EC2-Classic or EC2-VPC) of your Reserved Instances. | Y | N |
| Modify | Modifies the configuration of an existing route server. | Y | N |
| Modify | Archives an Amazon EBS snapshot. | Y | N |
| Modify | Modifies the specified Spot fleet request. | Y | N |
| Modify | Modifies a subnet attribute. | Y | N |
| Modify | Allows or restricts mirroring network services. | Y | Y |
| Modify | Modifies the specified Traffic Mirror rule. | Y | Y |
| Modify | Modifies a Traffic Mirror session. | Y | Y |
| Modify | Modifies the specified transit gateway. | Y | N |
| Modify | Modifies a transit gateway metering policy. | Y | N |
| Modify | Modifies a reference (route) to a prefix list in a specified transit gateway route table. | Y | N |
| Modify | Modifies the specified VPC attachment. | Y | N |
| Modify | Modifies the configuration of the specified Amazon Web Services Verified Access endpoint. | Y | N |
| Modify | Modifies the specified Amazon Web Services Verified Access endpoint policy. | Y | N |
| Modify | Modifies the specified Amazon Web Services Verified Access group configuration. | Y | N |
| Modify | Modifies the specified Amazon Web Services Verified Access group policy. | Y | N |
| Modify | Modifies the configuration of the specified Amazon Web Services Verified Access instance. | Y | N |
| Modify | Modifies the logging configuration for the specified Amazon Web Services Verified Access instance. | Y | N |
| Modify | Modifies the configuration of the specified Amazon Web Services Verified Access trust provider. | Y | N |
| Modify | You can modify several parameters of an existing EBS volume, including volume size, volume type, and IOPS capacity. | Y | N |
| Modify | Modifies a volume attribute. | Y | N |
| Modify | Modifies the specified attribute of the specified VPC. | Y | Y |
| Modify | Modify VPC Block Public Access (BPA) exclusions. | Y | N |
| Modify | Modify VPC Block Public Access (BPA) options. | Y | N |
| Modify | Modifies the encryption control configuration for a VPC. | Y | N |
| Modify | Modifies attributes of a specified VPC endpoint. | Y | N |
| Modify | Modifies a connection notification for VPC endpoint or VPC endpoint service. | Y | N |
| Modify | Modifies the attributes of the specified VPC endpoint service configuration. | Y | N |
| Modify | Modifies the payer responsibility for your VPC endpoint service. | Y | N |
| Modify | Modifies the permissions for your VPC endpoint service. | Y | N |
| Modify | Modifies the VPC peering connection options on one side of a VPC peering connection. | Y | N |
| Modify | Modifies the instance tenancy attribute of the specified VPC. | Y | N |
| Modify | Modifies the customer gateway or the target gateway of an Amazon Web Services Site-to-Site VPN connection. | Y | N |
| Modify | Modifies the connection options for your Site-to-Site VPN connection. | Y | N |
| Modify | Modifies the VPN tunnel endpoint certificate. | Y | N |
| Modify | Modifies the options for a VPN tunnel in an Amazon Web Services Site-to-Site VPN connection. | Y | N |
| Monitor | Enables monitoring for a running instance. | Y | Y |
| Move | Moves an Elastic IP address from the EC2-Classic platform to the EC2-VPC platform. | N | N |
| Move | Move a BYOIPv4 CIDR to IPAM from a public IPv4 pool. | N | N |
| Move | Move available capacity from a source Capacity Reservation to a destination Capacity Reservation. | N | N |
| Provision | Provisions an IPv4 or IPv6 address range for use with your Amazon Web Services resources through bring your own IP addresses (BYOIP) and creates a corresponding address pool. | N | N |
| Provision | Provisions your Autonomous System Number (ASN) for use in your Amazon Web Services account. | N | N |
| Provision | Provision a CIDR to an IPAM pool. | Y | N |
| Provision | Provision a CIDR to a public IPv4 pool. | N | N |
| Purchase | Purchase the Capacity Block for use with your account. | N | N |
| Purchase | Purchase the Capacity Block extension for use with your account. | N | N |
| Purchase | Purchase a reservation with configurations that match those of your Dedicated Host. | N | N |
| Purchase | Purchases a Reserved Instance for use with your account. | N | N |
| Purchase | Purchases one or more Scheduled Instances with the specified schedule. | N | N |
| Reboot | Requests a reboot of one or more instances. | Y | N |
| Register | Registers an AMI. | Y | N |
| Register | Registers a set of tag keys to include in scheduled event notifications for your resources. | Y | Y |
| Register | Registers members (network interfaces) with the transit gateway multicast group. | N | N |
| Register | Registers sources (network interfaces) with the specified transit gateway multicast group. | N | N |
| Reject | Rejects a request to assign billing of the available capacity of a shared Capacity Reservation to your account. | Y | N |
| Reject | Rejects a Transit Gateway attachment request for a Client VPN endpoint. | Y | N |
| Reject | Rejects a request to associate cross-account subnets with a transit gateway multicast domain. | Y | N |
| Reject | Rejects a transit gateway peering attachment request. | Y | N |
| Reject | Rejects a request to attach a VPC to a transit gateway. | Y | N |
| Reject | Rejects VPC endpoint connection requests to your VPC endpoint service. | Y | N |
| Reject | Rejects a VPC peering connection request. | Y | Y |
| Release | Releases the specified Elastic IP address. | Y | N |
| Release | When you no longer want to use a Dedicated host it can be released. | Y | N |
| Release | Release an allocation within an IPAM pool. | Y | N |
| Replace | Replaces an IAM instance profile for the specified running instance. | Y | N |
| Replace | Sets or replaces the criteria for Allowed AMIs. | N | N |
| Replace | Changes which network ACL a subnet is associated with. | Y | Y |
| Replace | Replaces the specified route in the specified transit gateway route table. | N | N |
| Replace | Trigger replacement of specified VPN tunnel. | N | N |
| Report | Submits feedback about the status of an instance. | Y | Y |
| Request | Creates a Spot fleet request. | N | N |
| Request | Creates a Spot Instance request. | Y | Y |
| Reset | Resets the attribute of the specified IP address. | Y | N |
| Reset | Resets the default KMS key for EBS encryption for your account in this Region to the Amazon Web Services managed KMS key for EBS. | Y | N |
| Reset | Resets the specified attribute of the specified Amazon FPGA Image (AFI) to its default value. | Y | N |
| Reset | Resets an attribute of an AMI to its default value. | Y | N |
| Reset | Resets an attribute of an instance to its default value. | Y | Y |
| Reset | Resets a network interface attribute. | Y | N |
| Reset | Resets permission settings for the specified snapshot. | Y | N |
| Restore | Restores an Elastic IP address that was previously moved to the EC2-VPC platform back to the EC2-Classic platform. | N | N |
| Restore | Restores an AMI from the Recycle Bin. | N | N |
| Restore | Restores the entries from a previous version of a managed prefix list to a new version of the prefix list. | Y | N |
| Restore | Restores a snapshot from the Recycle Bin. | N | N |
| Restore | Restores an archived Amazon EBS snapshot for use temporarily or permanently, or modifies the restore period or restore type for a snapshot that was previously temporarily restored. | N | N |
| Restore | Restores a volume from the Recycle Bin. | N | N |
| Revoke | Removes an ingress authorization rule from a Client VPN endpoint. | Y | N |
| Run | Launches the specified number of instances using an AMI for which you have permissions. | Y | Y |
| Run | Launches the specified Scheduled Instances. | N | Y |
| Search | Searches for routes in the specified local gateway route table. | Y | N |
| Search | Searches one or more transit gateway multicast groups and returns the group membership information. | Y | N |
| Search | Searches for routes in the specified transit gateway route table. | Y | N |
| Send | Sends a diagnostic interrupt to the specified Amazon EC2 instance to trigger a kernel panic (on Linux instances), or a blue screen/stop error (on Windows instances). | Y | N |
| Start | Generates an account status report. | N | N |
| Start | Starts analyzing the specified Network Access Scope. | Y | N |
| Start | Starts analyzing the specified path. | Y | N |
| Start | Initiates the verification process to prove that the service provider owns the private DNS name domain for the endpoint service. | N | N |
| Terminate | Terminates active Client VPN endpoint connections. | Y | N |
| Terminate | Shuts down one or more instances. | Y | Y |
| Unassign | Unassigns the specified IPv6 addresses or Prefix Delegation prefixes from a network interface. | N | N |
| Unassign | Unassigns one or more secondary private IP addresses from a network interface. | Y | N |
| Unassign | Unassigns secondary private IPv4 addresses from a private NAT gateway. | N | N |
| Unlock | Unlocks a snapshot that is locked in governance mode or that is locked in compliance mode but still in the cooling-off period. | Y | N |
| Unmonitor | Disables monitoring for a running instance. | Y | Y |
| Update | Activates or deactivates tag keys for monitoring by EC2 Capacity Manager. | N | N |
| Update | Updates the Organizations access setting for EC2 Capacity Manager. | Y | N |
| Update | Modifies the number of instances allocated to an interruptible reservation, allowing you to add more capacity or reclaim capacity to your source Capacity Reservation. | Y | N |
| Update | Updates the description of an egress (outbound) security group rule. | Y | N |
| Update | Updates the description of an ingress (inbound) security group rule. | Y | N |
| Withdraw | Stops advertising an address range that is provisioned as an address pool. | N | N |
| Bid | BidEvictedEvent recorded by CloudTrail for Amazon EC2. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Delete | DeleteVpcResourceDeletion recorded by CloudTrail for Amazon EC2. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Describe | DescribeVerifiedAccessInstanceWebAclAssociations recorded by CloudTrail for Amazon EC2. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Shared | SharedSnapshotVolumeCreated recorded by CloudTrail for Amazon EC2. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | Y | N |
| Associate | Associates an application status check with instances or tags. | N | N |
| Batch | Modifies multiple routing policy registrations in a single operation. | N | N |
| Create | Creates an application status check for monitoring the health of applications running on your instances. | N | N |
| Create | Creates an association between an IPAM and a Regional Internet Registry (RIR) for Resource Public Key Infrastructure (RPKI) management. | N | N |
| Create | Creates a routing policy registration and publishes Route Origin Authorizations (ROAs) to the RPKI for the specified CIDR prefix and ASNs. | N | N |
| Create | Creates an entry in a transit gateway policy table to route matching traffic to a specified route table. | N | N |
| Delete | Deletes an application status check. | N | N |
| Delete | Deletes an IPAM internet registry association. | N | N |
| Delete | Deletes a routing policy registration for a specified CIDR prefix. | N | N |
| Delete | Deletes the specified transit gateway policy table entry. | N | N |
| Describe | Describes the account-level VPC Encryption Control configuration for your account. | N | N |
| Describe | Describes the application status for the specified instances. | N | N |
| Describe | Describes the associations for one or more application status checks. | N | N |
| Describe | Describes one or more application status checks. | N | N |
| Describe | Describes one or more IPAM internet registry associations. | N | N |
| Disable | Disables suppression of application status checks for the specified instances. | N | N |
| Disassociate | Disassociates an application status check from instances or tags. | N | N |
| Enable | Suppresses application status checks for the specified instances. | N | N |
| Enable | Enables Resource Public Key Infrastructure (RPKI) on an existing IPAM internet registry association by providing BGP Public Key Infrastructure (BPKI) certificate details. | N | N |
| Get | Retrieves Border Gateway Protocol (BGP) routes discovered by IPAM resource discovery for a specified Region. | N | N |
| Get | Retrieves Autonomous System Numbers (ASNs) registered with an internet registry for an IPAM internet registry association. | N | N |
| Get | Retrieves IP address CIDRs registered with an internet registry for an IPAM internet registry association. | N | N |
| Get | Retrieves the current Route Origin Authorizations (ROAs) published to the RPKI for an IPAM internet registry association. | N | N |
| Get | Retrieves route protection findings for an IPAM. | N | N |
| Get | Retrieves the history of routing policy registration changes for an IPAM internet registry association. | N | N |
| Get | Retrieves routing policy registrations for an IPAM internet registry association. | N | N |
| Modify | Modifies the account-level VPC Encryption Control configuration. | N | N |
| Modify | Modifies an existing application status check. | N | N |
| Modify | Modifies an existing routing policy registration. | N | N |
| Modify | Modifies the specified transit gateway policy table entry. | N | N |
| Modify | Modifies the billing account for VPC endpoint usage/charges. | N | N |
any: EC2 (catch-all)
#Description
Catch-all entry for EC2 rules that match the service but not a specific eventName.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
AssociateIamInstanceProfile
#Description
Associates an IAM instance profile with a running or stopped EC2 instance.
CloudTrail management event, logged by default. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Common Indicators #
Field Kind Value Rules Vendors aws::errorCode (panther rule field)ne Client.DryRunOperation1 rule panther readOnly (panther rule field)is_null 1 rule panther Detection Rules #
Elastic #
AssociateIamInstanceProfile or ReplaceIamInstanceProfile may attach a more privileged role to a workload they control, enabling privilege escalation or lateral movement from the instance.T1078, T1078.004, T1548, T1548.005Panther #
T1578↳ also matches CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, BundleInstance, and 24 more
CreateInstanceExportTask
#Description
Exports a running or stopped EC2 instance to an Amazon S3 bucket in OVA, VHD, or VMDK format.
CloudTrail management event, logged by default. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "23a763b4-4a9c-4781-a670-9c160961f62dc",
"eventName": "CreateInstanceExportTask",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-02-28T14:36:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "b09f8e07-3a66-40ee-b8fe-cae9e380f8df",
"requestParameters": {
"description": "blah",
"exportToS3": {
"containerFormat": "ova",
"diskImageFormat": "vmdk",
"s3Bucket": "14b6a528b915b3c0270e0174982e5ed78052eafd.flaws.cloud",
"s3Prefix": "RHEL5"
},
"instanceId": "snap-2f6b292187c2304c2",
"targetEnvironment": "vmware"
},
"responseElements": null,
"sourceIPAddress": "0.102.218.8",
"userAgent": "aws-cli/1.11.56 Python/2.7.10 Darwin/16.4.0 botocore/1.5.19",
"userIdentity": {
"accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
Common Indicators #
Field Kind Value Rules Vendors readOnly (panther rule field)is_null 1 rule panther Detection Rules #
Sigma #
T1005, T1537Elastic #
T1005, T1119, T1530, T1537, T1567, T1567.002↳ also matches CreateStoreImageTask, ExportImage Panther #
T1578↳ also matches AssociateIamInstanceProfile, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, BundleInstance, and 24 more References #
CreateKeyPair
#Description
Creates an ED25519 or 2048-bit RSA key pair and stores the public key in EC2, returning the private key material.
CloudTrail management event, logged by default. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "ea9ba18b-6f28-42bd-9c6a-fc9e66b9adae",
"eventName": "CreateKeyPair",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-02-12T20:20:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "dbfde5b5-58b7-4452-90bc-7d0b6e9efefd",
"requestParameters": {
"keyName": "Default"
},
"responseElements": {
"keyFingerprint": "07:ac:63:2a:07:b7:e1:35:be:26:49:07:16:90:fe:e7:57:e0:2c:31",
"keyMaterial": "<sensitiveDataRemoved>",
"keyName": "Default"
},
"sourceIPAddress": "255.253.125.115",
"userAgent": "console.ec2.amazonaws.com",
"userIdentity": {
"accessKeyId": "ASIAIB6AB67SP5RKU9Z4",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:root",
"principalId": "811596193553",
"sessionContext": {
"attributes": {
"creationDate": "2017-02-12T19:57:05Z",
"mfaAuthenticated": "false"
}
},
"type": "Root"
}
}
Common Indicators #
Field Kind Value Rules Vendors source.as.organization.name (elastic rule field)is_not_null 1 rule elastic Detection Rules #
Elastic #
user_identity.arn suppresses repeated noise from the same principal while still surfacing the initial suspicious creation from an unusual egress label.T1021, T1021.004, T1098, T1552, T1552.004References #
CreateNetworkAcl
#Description
Creates a new network ACL in the specified VPC.
Example CloudTrail Event #
{
"awsRegion": "eu-central-1",
"eventCategory": "Management",
"eventID": "e6cfba5e-7b8d-413a-801c-e7d4f3843814",
"eventName": "CreateNetworkAcl",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-01-12T08:37:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "111111111111",
"requestID": "001b69eb-7486-48b5-a81b-45e08be4c7cb",
"requestParameters": {
"tagSpecificationSet": {
"items": [
{
"resourceType": "network-acl",
"tags": [
{
"key": "Name",
"value": "patrick-test"
}
]
}
]
},
"vpcId": "vpc-0e59cf66"
},
"responseElements": {
"networkAcl": {
"associationSet": {},
"entrySet": {
"items": [
{
"aclProtocol": "-1",
"cidrBlock": "0.0.0.0/0",
"egress": true,
"icmpTypeCode": {},
"portRange": {},
"ruleAction": "deny",
"ruleNumber": 32767
},
{
"aclProtocol": "-1",
"cidrBlock": "0.0.0.0/0",
"egress": false,
"icmpTypeCode": {},
"portRange": {},
"ruleAction": "deny",
"ruleNumber": 32767
}
]
},
"isDefault": false,
"networkAclId": "acl-078ccebebcbabe175",
"ownerId": "111111111111",
"tagSet": {
"items": [
{
"key": "Name",
"value": "patrick-test"
}
]
},
"vpcId": "vpc-0e59cf66"
},
"requestId": "001b69eb-7486-48b5-a81b-45e08be4c7cb"
},
"sourceIPAddress": "95.90.199.65",
"userAgent": "console.ec2.amazonaws.com",
"userIdentity": {
"accessKeyId": "ASIAYTOGP2RLF3F7BXZK",
"accountId": "111111111111",
"arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local",
"sessionContext": {
"attributes": {
"creationDate": "2021-01-12T08:36:15Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:role/okta_adm_role",
"principalId": "AROAIJIESMXKGCJRCTPR6",
"type": "Role",
"userName": "okta_adm_role"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1133, T1562, T1562.007, T1578, T1578.005↳ also matches CreateNetworkAclEntry Panther #
T1562↳ also matches CreateNetworkAclEntry, DeleteNetworkAcl, DeleteNetworkAclEntry, ReplaceNetworkAclEntry, ReplaceNetworkAclAssociation
References #
CreateNetworkAclEntry
#Description
Creates an entry (rule) in a network ACL with the specified rule number, protocol, and traffic action.
Example CloudTrail Event #
{
"awsRegion": "eu-central-1",
"eventCategory": "Management",
"eventID": "40b0e8a3-048f-4f44-a022-1ef26fade55e",
"eventName": "CreateNetworkAclEntry",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-01-12T09:26:21Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "111111111111",
"requestID": "cc527b25-0ec5-40f2-b09f-0c99bfada160",
"requestParameters": {
"aclProtocol": "6",
"cidrBlock": "0.0.0.0/0",
"egress": false,
"icmpTypeCode": {},
"networkAclId": "acl-078ccebebcbabe175",
"portRange": {
"from": 0,
"to": 65000
},
"ruleAction": "allow",
"ruleNumber": 40
},
"responseElements": {
"_return": true,
"requestId": "cc527b25-0ec5-40f2-b09f-0c99bfada160"
},
"sourceIPAddress": "95.90.199.65",
"userAgent": "console.ec2.amazonaws.com",
"userIdentity": {
"accessKeyId": "ASIAYTOGP2RLF3F7BXZK",
"accountId": "111111111111",
"arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local",
"sessionContext": {
"attributes": {
"creationDate": "2021-01-12T08:36:15Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:role/okta_adm_role",
"principalId": "AROAIJIESMXKGCJRCTPR6",
"type": "Role",
"userName": "okta_adm_role"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aclProtocol | eq | -1 | 2 rules | kusto, splunk |
egress | eq | false | 2 rules | kusto, splunk |
ruleAction | eq | allow | 2 rules | kusto, splunk |
event.outcome (elastic rule field) | in | success | 1 rule | elastic |
requestParameters.egress (splunk rule field) | eq | false | 1 rule | splunk |
requestParameters.ruleAction (splunk rule field) | eq | allow | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1686, T1686.001Elastic #
T1562, T1562.007↳ also matches ReplaceNetworkAclEntry T1133, T1562, T1562.007, T1578, T1578.005↳ also matches CreateNetworkAcl Splunk #
CreateNetworkAclEntry or…T1686, T1686.001↳ also matches ReplaceNetworkAclEntry CreateNetworkAclEntry or…T1686, T1686.001↳ also matches ReplaceNetworkAclEntry Kusto #
T1078, T1562, T1562.007↳ also matches CreateRouteTable, CreateInternetGateway, CreateNatGateway T1562, T1562.007↳ also matches ReplaceNetworkAclEntry Panther #
T1562↳ also matches CreateNetworkAcl, DeleteNetworkAcl, DeleteNetworkAclEntry, ReplaceNetworkAclEntry, ReplaceNetworkAclAssociation
References #
CreateRoute
#Description
Creates a route in a route table within a VPC, specifying the destination CIDR and target.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "6445452c-c6df-4ebf-a1ed-2890f5aa7107",
"eventName": "CreateRoute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "c78b8c19-af06-44ea-b707-60bb0c3124f9",
"requestParameters": {
"destinationCidrBlock": "0.0.0.0/0",
"gatewayId": "igw-02a84e4222d62e16b",
"routeTableId": "rtb-0c7c2f4aff3677054"
},
"responseElements": {
"_return": true,
"requestId": "c78b8c19-af06-44ea-b707-60bb0c3124f9"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1686, T1686.001Elastic #
T1578, T1578.005↳ also matches CreateRouteTable
References #
CreateRouteTable
#Description
Creates a route table for the specified VPC.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "dc024e51-15e4-4829-a971-7e17d4be43be",
"eventName": "CreateRouteTable",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "6448e604-a047-4564-ba7e-712d66db3d97",
"requestParameters": {
"tagSpecificationSet": {
"items": [
{
"resourceType": "route-table",
"tags": [
{
"key": "StratusRedTeam",
"value": "true"
},
{
"key": "Name",
"value": "stratus-red-team-ec2-steal-credentials-vpc-public"
}
]
}
]
},
"vpcId": "vpc-06fe1a64761a0f720"
},
"responseElements": {
"requestId": "6448e604-a047-4564-ba7e-712d66db3d97",
"routeTable": {
"associationSet": {},
"ownerId": "123837392027",
"propagatingVgwSet": {},
"routeSet": {
"items": [
{
"destinationCidrBlock": "10.0.0.0/16",
"gatewayId": "local",
"origin": "CreateRouteTable",
"state": "active"
}
]
},
"routeTableId": "rtb-0c7c2f4aff3677054",
"tagSet": {
"items": [
{
"key": "StratusRedTeam",
"value": "true"
},
{
"key": "Name",
"value": "stratus-red-team-ec2-steal-credentials-vpc-public"
}
]
},
"vpcId": "vpc-06fe1a64761a0f720"
}
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1578, T1578.005↳ also matches CreateRoute Kusto #
T1078, T1562, T1562.007↳ also matches CreateNetworkAclEntry, CreateInternetGateway, CreateNatGateway Panther #
T1048↳ also matches DeleteRouteTable, DisassociateRouteTable, ReplaceRoute, ReplaceRouteTableAssociation
References #
CreateSecurityGroup
#Description
Creates a security group in a specified VPC or for EC2-Classic.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"eventVersion": "1.11",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE"
},
"eventTime": "2026-07-28T20:58:33Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "CreateSecurityGroup",
"awsRegion": "us-west-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#ec2.create-security-group",
"requestParameters": {
"groupName": "dw-harn-ec2-eb786637",
"groupDescription": "dw harness",
"vpcId": "vpc-0cf63cfb072f7d61f"
},
"responseElements": {
"requestId": "35e65d8f-9426-418d-ae76-c7baf12b1899",
"_return": true,
"groupId": "sg-0200d267c43de2fbc",
"securityGroupArn": "arn:aws:ec2:us-west-1:123456789012:security-group/sg-0200d267c43de2fbc"
},
"requestID": "35e65d8f-9426-418d-ae76-c7baf12b1899",
"eventID": "254b9453-647c-4c63-8b0b-2f973bdfa5d0",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com"
}
}
Detection Rules #
Elastic #
T1133, T1562, T1562.007, T1578, T1578.005↳ also matches AuthorizeSecurityGroupEgress, AuthorizeSecurityGroupIngress, ModifyInstanceAttribute, ModifySecurityGroupRules, RevokeSecurityGroupEgress, RevokeSecurityGroupIngress Panther #
T1562↳ also matches AuthorizeSecurityGroupEgress, AuthorizeSecurityGroupIngress T1562↳ also matches AuthorizeSecurityGroupEgress, AuthorizeSecurityGroupIngress, RevokeSecurityGroupEgress, RevokeSecurityGroupIngress, DeleteSecurityGroup
CreateStoreImageTask
#Description
Stores an Amazon Machine Image (AMI) as a single object in an Amazon S3 bucket.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aws::errorCode (panther rule field) | ne | Client.DryRunOperation | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1005, T1119, T1530, T1537, T1567, T1567.002↳ also matches CreateInstanceExportTask, ExportImage Panther #
T1204↳ also matches CopyFpgaImage, CopyImage, CreateFpgaImage, CreateImage, CreateRestoreImageTask, ImportImage
CreateTrafficMirrorSession
#Description
Creates a traffic mirror session that copies network traffic from a source network interface to a target.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation. User: arn:aws:iam::123456789012:user/TrailDiscover is not authorized to perform: ec2:CreateTrafficMirrorSession on resource: arn:aws:ec2:us-east-1:192374575148:traffic-mirror-filter/* because no identity-based policy allows the ec2:CreateTrafficMirrorSession action. Encoded authorization failure message: HJhYRHfNmRnmfLwYuoFYYZia0G-FhUf1Oe4osxJuO86JpVIhw6gMXS67RWasoBwP-srKZVJlihD_HC-wnUUlfHeRNPYlaR6WI289aN31GSE5oBu-EkL7jhf_8-7j_oCqrQ6Xwr37C7Cfdpr4Cyxw-JrxKOUYMTyMFRY3YRgcke2e_9QzAxnjr3C7ioQQMTEpI0dEN9M3x3YKWUbmddXMXKQAqs2eNGf9b6ISCtTBjIeV8rE0oOtOUZx8cS3CavD7aLJE4L9DZEBllFcSzNVq17mznRPC8l3_n6P0UusmdalelhW2KjCCKqjCSPVZ-T9mGGd4q4Q4s35nVPS2KI8R8Vlx6rV88yomFpQk_Ld6THhUkrp3Tpf6TswCLWRZlxElw-JlsCod9N0jANT2T2wkWVuCB-bf5fSqS7cJwJ3Jt1-EBr3ZviQdZHNLeYi5yQsEP0XdVHounoK7oE59wcEyclDehhUTkUluGrfTVdXKkoDUuy4qDebk5Hbax4d_PG-04HhPGJhJfrxfEWBdy3nrL8Mji-aLCA",
"eventCategory": "Management",
"eventID": "bdc6cf73-0710-4815-9cbc-e2944665d9ff",
"eventName": "CreateTrafficMirrorSession",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2024-08-18T14:29:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.09",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "82310870-1409-41fe-b9a0-9283f159824f",
"requestParameters": {
"CreateTrafficMirrorSessionRequest": {
"ClientToken": "32617bdc-4512-4f42-a69f-3da62c6692c6",
"Description": "TrailDiscoverDescription",
"NetworkInterfaceId": "eni-070203f901EXAMPLE",
"PacketLength": 25,
"SessionNumber": 1,
"TrafficMirrorFilterId": "tmf-04812ff784EXAMPLE",
"TrafficMirrorTargetId": "tmt-07f75d8feeEXAMPLE"
}
},
"responseElements": null,
"sourceIPAddress": "0.0.0.0",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "aws-cli/2.17.32 md/awscrt#0.21.2 ua/2.0 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.11.9 md/pyimpl#CPython exec-env/grimoire_2955cdaf-7deb-4516-932b-b6aebaa38515 cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#ec2.create-traffic-mirror-session",
"userIdentity": {
"accessKeyId": "AKIA****************",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/TrailDiscover",
"principalId": "AROA****************:User",
"type": "IAMUser",
"userName": "TrailDiscover"
}
}
Detection Rules #
Elastic #
T1020, T1040, T1074, T1537Panther #
T1040↳ also matches CreateTrafficMirrorFilter, CreateTrafficMirrorFilterRule, CreateTrafficMirrorTarget, DeleteTrafficMirrorFilter, DeleteTrafficMirrorFilterRule, DeleteTrafficMirrorSession, and 4 more References #
DeleteFlowLogs
#Description
Deletes one or more VPC flow logs.
CloudTrail management event, logged by default. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "de58d903-38d7-4f30-a84b-b79d858e8376",
"eventName": "DeleteFlowLogs",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:02:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "bd26b4b4-133e-4610-8be1-9c5d645bb2ee",
"requestParameters": {
"DeleteFlowLogsRequest": {
"FlowLogId": {
"content": "fl-064ed3a785e4a37ef",
"tag": 1
}
}
},
"responseElements": {
"DeleteFlowLogsResponse": {
"requestId": "bd26b4b4-133e-4610-8be1-9c5d645bb2ee",
"unsuccessful": "",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "stratus-red-team_20f9795b-aa02-4c8e-bad6-bd338ec09f59",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Common Indicators #
Field Kind Value Rules Vendors aws::errorCode (sigma rule field)eq success1 rule sigma Detection Rules #
Sigma #
Elastic #
T1562, T1562.008Kusto #
T1070T1562, T1562.008T1562, T1562.008YARA-L #
T1562Panther #
T1562.008T1562↳ also matches DisableEbsEncryptionByDefault References #
DeleteNetworkAcl
#Description
Deletes the specified network ACL, which must not be associated with any subnets.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidNetworkAclId.Malformed",
"errorMessage": "The network-acl ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "4c24ae67-78fd-4274-b675-434aa51abbf2",
"eventName": "DeleteNetworkAcl",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:21Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6e26e5aa-c75c-4c1c-a2f9-7d4f4a3de07d",
"requestParameters": {
"networkAclId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1562, T1562.007↳ also matches DeleteNetworkAclEntry Panther #
T1562↳ also matches CreateNetworkAcl, CreateNetworkAclEntry, DeleteNetworkAclEntry, ReplaceNetworkAclEntry, ReplaceNetworkAclAssociation
DeleteNetworkAclEntry
#Description
Deletes the specified ingress or egress entry (rule) from the specified network ACL.
Example CloudTrail Event #
{
"awsRegion": "eu-central-1",
"eventCategory": "Management",
"eventID": "b9e05770-e9b0-4ba1-91e8-6537097e06e7",
"eventName": "DeleteNetworkAclEntry",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-01-12T09:26:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "111111111111",
"requestID": "607474bb-836b-46be-be4a-351ebbef67d6",
"requestParameters": {
"egress": false,
"networkAclId": "acl-078ccebebcbabe175",
"ruleNumber": 40
},
"responseElements": {
"_return": true,
"requestId": "607474bb-836b-46be-be4a-351ebbef67d6"
},
"sourceIPAddress": "95.90.199.65",
"userAgent": "console.ec2.amazonaws.com",
"userIdentity": {
"accessKeyId": "ASIAYTOGP2RLF3F7BXZK",
"accountId": "111111111111",
"arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local",
"sessionContext": {
"attributes": {
"creationDate": "2021-01-12T08:36:15Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:role/okta_adm_role",
"principalId": "AROAIJIESMXKGCJRCTPR6",
"type": "Role",
"userName": "okta_adm_role"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
egress (splunk rule field) | eq | false | 1 rule | splunk |
requestParameters.egress (splunk rule field) | eq | false | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1562, T1562.007↳ also matches DeleteNetworkAcl Splunk #
T1686, T1686.001T1686, T1686.001Panther #
T1562↳ also matches CreateNetworkAcl, CreateNetworkAclEntry, DeleteNetworkAcl, ReplaceNetworkAclEntry, ReplaceNetworkAclAssociation
References #
DeleteRoute
#Description
Deletes the specified route from the specified route table.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "ffd9d334-1e18-4c5e-9ccf-e31d440f3dec",
"eventName": "DeleteRoute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:08:05Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "cf090fc5-3d06-4571-a6cc-7c8de1229399",
"requestParameters": {
"destinationCidrBlock": "0.0.0.0/0",
"routeTableId": "rtb-08838187a84b2f5bf"
},
"responseElements": {
"_return": true,
"requestId": "cf090fc5-3d06-4571-a6cc-7c8de1229399"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1578, T1578.005↳ also matches DeleteRouteTable, DisassociateRouteTable, ReplaceRoute, ReplaceRouteTableAssociation
References #
DeleteRouteTable
#Description
Deletes the specified route table, which must not be associated with any subnet.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "9c924999-9fc4-4d24-8c17-e68efd788af4",
"eventName": "DeleteRouteTable",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:08:07Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "ba265499-24f7-4fa0-984f-5f5ee5d848e6",
"requestParameters": {
"routeTableId": "rtb-01a1e48796093c514"
},
"responseElements": {
"_return": true,
"requestId": "ba265499-24f7-4fa0-984f-5f5ee5d848e6"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1578, T1578.005↳ also matches DeleteRoute, DisassociateRouteTable, ReplaceRoute, ReplaceRouteTableAssociation Panther #
T1048↳ also matches CreateRouteTable, DisassociateRouteTable, ReplaceRoute, ReplaceRouteTableAssociation
References #
DescribeCarrierGateways
#Description
Describes one or more carrier gateways associated with a VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "a5acbb96-64bc-4b58-9a49-03ed3ec45d88",
"eventName": "DescribeCarrierGateways",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-10-02T15:48:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "e92ac6bf-2623-4651-a4f5-a9232b591632",
"requestParameters": {
"DescribeCarrierGatewaysRequest": ""
},
"responseElements": null,
"sourceIPAddress": "253.237.6.192",
"userAgent": "aws-cli/1.18.146 Python/3.8.4 Linux/5.7.0-kali1-amd64 botocore/1.18.5",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeClientVpnRoutes
#Description
Describes the routes for a specified Client VPN endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.DryRunOperation",
"errorMessage": "Request would have succeeded, but DryRun flag is set.",
"eventID": "f1e789a6-a761-4614-9f1a-cc9e4fee45db",
"eventName": "DescribeClientVpnRoutes",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-05-19T17:44:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "2d3a06b9-5a2c-4d18-8a9f-616c91717ce9",
"requestParameters": {
"DescribeClientVpnRoutesRequest": {
"ClientVpnEndpointId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "255.251.4.254",
"userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeDhcpOptions
#Description
Describes one or more DHCP options sets in the account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "a93a1a71-0a8f-46bb-bec3-2b2e3702f180",
"eventName": "DescribeDhcpOptions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:13:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "b417ae75-09b7-44b2-aded-e11041a4ae81",
"requestParameters": {
"dhcpOptionsSet": {},
"filterSet": {},
"maxResults": 1000
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCSUD2OWV6",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:13:16Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeImages
#Description
Describes one or more Amazon Machine Images (AMIs) available to the account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "9b77e3e5-b2a1-4274-a0f9-8f642f0ae426",
"eventName": "DescribeImages",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:06:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "6723987a-8e90-4a4d-9f8a-102e30df02de",
"requestParameters": {
"executableBySet": {},
"filterSet": {
"items": [
{
"name": "name",
"valueSet": {
"items": [
{
"value": "amzn2-ami-hvm-*-x86_64-ebs"
}
]
}
}
]
},
"imagesSet": {},
"includeDeprecated": false,
"ownersSet": {
"items": [
{
"owner": "amazon"
}
]
}
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/4.67.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.261 (go1.19.8; linux; amd64) stratus-red-team_bc31c885-5ea0-4a6e-8bec-b6b10058bc44 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1580
References #
DescribeInstanceAttribute
#Description
Describes the specified attribute of the specified EC2 instance.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "61374265-b590-4f81-b09d-295ccc1a7de1",
"eventName": "DescribeInstanceAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:33Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "82290b81-0e4f-4b01-b60b-aeace3a4c8fd",
"requestParameters": {
"attribute": "instanceInitiatedShutdownBehavior",
"instanceId": "i-0dbc91f429e48eeed"
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1552, T1552.005, T1580
References #
DescribeInstances
#Description
Returns detailed information about one or more EC2 instances, including their state, type, network interfaces, and associated metadata.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "b5b603c2-7b7f-41d9-8932-f87be2fc78d6",
"eventName": "DescribeInstances",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:13:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "ca74d893-b2e1-452a-9851-0ea9294dcb49",
"requestParameters": {
"filterSet": {
"items": [
{
"name": "instance-state-name",
"valueSet": {
"items": [
{
"value": "running"
}
]
}
}
]
},
"instancesSet": {},
"maxResults": 1000
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCSUD2OWV6",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:13:16Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Esql.cloud_region_count_distinct (elastic rule field) | ge | 10 | 1 rule | elastic |
Esql.event_count (elastic rule field) | ge | 10 | 1 rule | elastic |
aws::userIdentity.arn (elastic rule field) | is_not_null | | 1 rule | elastic |
source.as.number (elastic rule field) | in | 9009 | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
DescribeInstances API calls in more than 10 regions within a 30-second window. This could indicate a potential threat actor attempting to discover the AWS infrastructure across multiple regions using compromised credentials or a compromised instance. Adversaries may use this information to identify potential targets for further exploitation or to gain a better understanding of the target's infrastructure.T1580List*/Describe* patterns are intentionally omitted to reduce noise. Hosting ASNs are heavily dual-use; validate source.as.number in your data and extend event.action only when your baseline allows it.T1526, T1580↳ also matches DescribeRegions, DescribeSecurityGroups, DescribeVpcs
References #
DescribeRegions
#Description
Returns the AWS regions that are enabled for the caller's account, or all regions that are available to EC2.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "768ef4f1-4721-40e0-82d7-5504605a380b",
"eventName": "DescribeRegions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:13:21Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "5ae4a7b8-8972-46a0-bee8-a1d0f4a42995",
"requestParameters": {
"allRegions": true,
"regionSet": {}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:102.0) Gecko/20100101 Firefox/102.0",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCXBBR47W6",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:13:16Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aws::userIdentity.arn (elastic rule field) | is_not_null | | 1 rule | elastic |
source.as.number (elastic rule field) | in | 9009 | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
List*/Describe* patterns are intentionally omitted to reduce noise. Hosting ASNs are heavily dual-use; validate source.as.number in your data and extend event.action only when your baseline allows it.T1526, T1580↳ also matches DescribeInstances, DescribeSecurityGroups, DescribeVpcs
References #
DescribeSecurityGroups
#Description
Returns information about one or more EC2 security groups, including their inbound and outbound rules.
Example CloudTrail Event #
{
"eventVersion": "1.11",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE"
},
"eventTime": "2026-07-28T20:58:37Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "DescribeSecurityGroups",
"awsRegion": "us-west-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/n,Z,E,C,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#ec2.describe-security-groups",
"requestParameters": {
"securityGroupSet": {},
"securityGroupIdSet": {
"items": [
{
"groupId": "sg-0200d267c43de2fbc"
}
]
},
"filterSet": {}
},
"responseElements": null,
"requestID": "f04bdef2-c53f-4d23-891f-e8985aee8427",
"eventID": "f3497cf7-0b5b-4b9c-8606-7c5501702693",
"readOnly": true,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aws::userIdentity.arn (elastic rule field) | is_not_null | | 1 rule | elastic |
source.as.number (elastic rule field) | in | 9009 | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
List*/Describe* patterns are intentionally omitted to reduce noise. Hosting ASNs are heavily dual-use; validate source.as.number in your data and extend event.action only when your baseline allows it.T1526, T1580↳ also matches DescribeInstances, DescribeRegions, DescribeVpcs Panther #
T1518↳ also matches DescribeSecurityGroupReferences, DescribeSecurityGroupRules, DescribeSubnets
DescribeSnapshotAttribute
#Description
Describes the specified attribute of the specified EBS snapshot.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventCategory": "Management",
"eventID": "d37285d0-239e-4538-ac85-88c5991c5648",
"eventName": "DescribeSnapshotAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-01-12T09:28:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "111111111111",
"requestID": "0ddf29d3-18c0-42f2-9eae-bec31b8ce549",
"requestParameters": {
"attributeType": "CREATE_VOLUME_PERMISSION",
"snapshotId": "snap-0645a5c03e1a975db"
},
"responseElements": null,
"sourceIPAddress": "204.107.141.240",
"userAgent": "Boto3/1.10.32 Python/3.6.8 Linux/3.10.0-1062.18.1.el7.x86_64 Botocore/1.13.32",
"userIdentity": {
"accessKeyId": "ASIAYTOGP2RLP6F5ACON",
"accountId": "111111111111",
"arn": "arn:aws:sts::111111111111:assumed-role/okta_ro_role/botocore-session-1610443391",
"principalId": "AROAIJN34TPOD7C3TZWUU:botocore-session-1610443391",
"sessionContext": {
"attributes": {
"creationDate": "2021-01-12T09:23:12Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:role/okta_ro_role",
"principalId": "AROAIJN34TPOD7C3TZWUU",
"type": "Role",
"userName": "okta_ro_role"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Splunk #
T1537↳ also matches ModifySnapshotAttribute
References #
DescribeSnapshotTierStatus
#Description
Describes the storage tier status of one or more EBS snapshots.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "836a322f-11fb-41f7-8272-9bb859e6a926",
"eventName": "DescribeSnapshotTierStatus",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "5e9ae186-ef08-4de0-981e-dd7b94b8e68c",
"requestParameters": {
"DescribeSnapshotTierStatusRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeTransitGatewayMulticastDomains
#Description
Describes one or more transit gateway multicast domains.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "60485-5d74-4871-8c9a-dbf7b5d3582d",
"eventName": "DescribeTransitGatewayMulticastDomains",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-06-10T05:33:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "e0078a3c-a69b-48b6-a029-28bf79f4a16f",
"requestParameters": {
"DescribeTransitGatewayMulticastDomainsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeVolumes
#Description
Describes the specified EBS volumes or all EBS volumes in the account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "29d37c53-9ab1-4702-8d11-0171eef6a77a",
"eventName": "DescribeVolumes",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:27:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "eedef094-959c-4622-b910-d411eeac345c",
"requestParameters": {
"filterSet": {},
"maxResults": 1000,
"volumeSet": {}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCVDQK5XKV",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeVolumesModifications
#Description
Describes the most recent volume modification request for the specified EBS volumes.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "01df144b-e838-4f5b-8675-a40529a6b344",
"eventName": "DescribeVolumesModifications",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-07-07T15:55:06Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "43633774-1f66-404c-8816-7324e34ac161",
"requestParameters": {
"DescribeVolumesModificationsRequest": {
"MaxResults": 1000
}
},
"responseElements": null,
"sourceIPAddress": "167.98.108.182",
"userAgent": "console.ec2.amazonaws.com",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI37YFF5PNWP",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/sean",
"principalId": "AIDA3TLZJI375TCG5FSRI",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:56:28Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "sean"
}
}
References #
DescribeVpcEndpointConnectionNotifications
#Description
Describes the connection notifications for VPC endpoints and VPC endpoint services.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "233c2756-f647-4128-bb73-176bfba6327b",
"eventName": "DescribeVpcEndpointConnectionNotifications",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-10-17T20:11:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "ab35edeb-dfb0-49c0-b377-dcbbcd5be9f4",
"requestParameters": {
"DescribeVpcEndpointConnectionNotificationsRequest": {}
},
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeVpcs
#Description
Returns information about one or more VPCs in the account, including their CIDR blocks, state, and associated attributes.
Example CloudTrail Event #
{
"eventVersion": "1.11",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE"
},
"eventTime": "2026-07-28T20:58:31Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "DescribeVpcs",
"awsRegion": "us-west-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/n,Z,E,C,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#ec2.describe-vpcs",
"requestParameters": {
"vpcSet": {},
"filterSet": {
"items": [
{
"name": "isDefault",
"valueSet": {
"items": [
{
"value": "true"
}
]
}
}
]
}
},
"responseElements": null,
"requestID": "f4bb2659-877f-4199-8872-ed3e7d11f7c7",
"eventID": "062f0dd4-20bf-49e3-b194-b598a8cd72e3",
"readOnly": true,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
source.as.number (elastic rule field) | in | 9009 | 1 rule | elastic |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
List*/Describe* patterns are intentionally omitted to reduce noise. Hosting ASNs are heavily dual-use; validate source.as.number in your data and extend event.action only when your baseline allows it.T1526, T1580↳ also matches DescribeInstances, DescribeRegions, DescribeSecurityGroups
DisableEbsEncryptionByDefault
#Description
Disables default EBS encryption for EBS volumes created in the current account and Region.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "0ad6b464-f2c5-4aa4-8a00-f4eeeb2319b0",
"eventName": "DisableEbsEncryptionByDefault",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:43:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "33810299-5768-4cb3-a200-3142f2c59930",
"requestParameters": {
"DisableEbsEncryptionByDefaultRequest": ""
},
"responseElements": {
"DisableEbsEncryptionByDefaultResponse": {
"ebsEncryptionByDefault": false,
"requestId": "33810299-5768-4cb3-a200-3142f2c59930",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Sigma #
T1486, T1565Elastic #
T1565, T1565.001, T1578, T1578.005Panther #
T1486, T1565T1562↳ also matches DeleteFlowLogs
DisassociateRouteTable
#Description
Disassociates a subnet or gateway from a route table.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "93487b25-01bb-410b-aa05-57565fca5172",
"eventName": "DisassociateRouteTable",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:08:05Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "b31ac506-39c4-45f7-8f4f-2ec4c591e881",
"requestParameters": {
"associationId": "rtbassoc-06c42ea03f0967f18"
},
"responseElements": {
"_return": true,
"associationState": {
"state": "disassociating"
},
"requestId": "b31ac506-39c4-45f7-8f4f-2ec4c591e881"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1578, T1578.005↳ also matches DeleteRoute, DeleteRouteTable, ReplaceRoute, ReplaceRouteTableAssociation Panther #
T1048↳ also matches CreateRouteTable, DeleteRouteTable, ReplaceRoute, ReplaceRouteTableAssociation
References #
EnableSerialConsoleAccess
#Description
Enables access to the EC2 serial console for EC2 instances in the current account and Region.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "2e2ce75c-8a37-47c1-8056-f56502adace4",
"eventName": "EnableSerialConsoleAccess",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:43:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "02003b33-61fe-435b-be78-9643837ac48c",
"requestParameters": {
"EnableSerialConsoleAccessRequest": ""
},
"responseElements": {
"EnableSerialConsoleAccessResponse": {
"requestId": "02003b33-61fe-435b-be78-9643837ac48c",
"serialConsoleAccessEnabled": true,
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Elastic #
T1562, T1562.001, T1578, T1578.005
ExportImage
#Description
Exports an Amazon Machine Image (AMI) to an Amazon S3 bucket.
CloudTrail management event, logged by default. No sample available (sample_count=0); event_class grounded from the AWS API reference (this is a control-plane operation that initiates an export task). Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Elastic #
T1005, T1119, T1530, T1537, T1567, T1567.002↳ also matches CreateInstanceExportTask, CreateStoreImageTask
GetEbsDefaultKmsKeyId
#Description
Retrieves the default KMS key ID used for EBS encryption in the current Region.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "068e39b3-a0f9-4047-83f9-51ab1796a488",
"eventName": "GetEbsDefaultKmsKeyId",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-05-19T17:44:18Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "54a851283-7d31-4ebe-b4f4-e1b2407f4b8a",
"requestParameters": {
"GetEbsDefaultKmsKeyIdRequest": ""
},
"responseElements": null,
"sourceIPAddress": "255.251.4.254",
"userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetEbsEncryptionByDefault
#Description
Retrieves the default EBS encryption setting for the current account and Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventCategory": "Management",
"eventID": "db7028ca-6e33-4502-a166-b548f996bf6d",
"eventName": "GetEbsEncryptionByDefault",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-01-12T08:37:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "111111111111",
"requestID": "22bbe5a2-251a-4170-9909-6cc6b9ae7fbb",
"requestParameters": {
"GetEbsEncryptionByDefaultRequest": ""
},
"responseElements": null,
"sourceIPAddress": "config.amazonaws.com",
"userAgent": "config.amazonaws.com",
"userIdentity": {
"accountId": "111111111111",
"arn": "arn:aws:sts::111111111111:assumed-role/config-role-us-west-2/configLambdaExecution",
"invokedBy": "config.amazonaws.com",
"principalId": "AROAIQ3J3AWJKHZRVZC62:configLambdaExecution",
"sessionContext": {
"attributes": {
"creationDate": "2021-01-12T08:37:19Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:role/service-role/config-role-us-west-2",
"principalId": "AROAIQ3J3AWJKHZRVZC62",
"type": "Role",
"userName": "config-role-us-west-2"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
References #
GetPasswordData
#Description
Retrieves the encrypted administrator password for a Windows instance.
CloudTrail management event, logged by default. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation. Encoded authorization failure message: 1Qju1r-MUd3Ls-t7y4w4lpDtgZ-SW3htXqO4UWyYc3RRm71l29ME4w3IIewWhVC8ebqeZswLhkaNtKJcthIjmcqywqV1VgZqs4N-GL8hiyqyOvRy9rmG-ngQIz_Kcpi0mGOOCMd6TWGim0j6xYTiUVvdWURwLDOA5tPeD3lbCq13-0U29FMpt9V4D3RP_gUQ0gWAED4heCGuWygNHtwkM7kapWT0U_reDDIrpM6BANEpBV8hUZ0DM3Pd8arpnHnzQ93N0PZ8Agcw049fARhceT4yM1xMJw8T_iDnU2sgAJvj22MhubJf0Ni0jkEG3OyumbfAa-P7dlqGXT6Qj5FxVSnNOXfmowCbAgQWd9iJuNNpBt6HuYcUhNVhBOGaqNdsFLSqontKFUCCJoOQnBnV4xnIfVEXOUNUZyp8vg6tKI7ieoB71iiIjvLBB7SlSr9raQxnVLu8iPNDEpfLNlDBcFqlZ2PByaW21xKcLRqBFYJchBVhImo_ICrk8-Y_hisEL1L7IAiZASUYyRp5Xsm_uVY6GDIBaQfaegL7ZTOpMvs3OMd3oHW9uJkkp5ButArvKh4TNHwtW2OVkg",
"eventCategory": "Management",
"eventID": "fbd91225-39aa-4c00-822c-9f0b96e7758f",
"eventName": "GetPasswordData",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:54:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "466cd3e7-0a68-4487-851f-d41c9145180f",
"requestParameters": {
"instanceId": "i-durz4ux740gjqvcm"
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "stratus-red-team_39f95f43-cd2f-4beb-b69e-be60b6fe1f57",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCWLLE7IWW",
"accountId": "123837392027",
"arn": "arn:aws:sts::123837392027:assumed-role/stratus-red-team-ec2-get-password-data-role/aws-go-sdk-1688990082523310002",
"principalId": "AROATFQR7NSCWWVLB7BES:aws-go-sdk-1688990082523310002",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T11:54:47Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:role/stratus-red-team-ec2-get-password-data-role",
"principalId": "AROATFQR7NSCWWVLB7BES",
"type": "Role",
"userName": "stratus-red-team-ec2-get-password-data-role"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
Common Indicators #
Field Kind Value Rules Vendors aws::errorCode (elastic rule field)eq client.unauthorizedoperation1 rule elastic aws::userIdentity.type (elastic rule field)eq assumedrole1 rule elastic Detection Rules #
Sigma #
T1555Elastic #
GetPassword to access the administrator password of an EC2 instance. Adversaries may use this API call to escalate privileges or move laterally within EC2 instances.T1078, T1078.004, T1552, T1552.005Splunk #
T1110, T1110.001, T1586, T1586.003T1110, T1110.001, T1586, T1586.003YARA-L #
T1555Panther #
T1555References #
GetTransitGatewayRouteTableAssociations
#Description
Gets information about the route table associations for the specified transit gateway route table.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "f4cd8da2-af3d-4b72-94f4-3a66822b40d0",
"eventName": "GetTransitGatewayRouteTableAssociations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-05-19T17:44:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "72a841bf-9080-464e-8e0b-424d9975aa74",
"requestParameters": {
"GetTransitGatewayRouteTableAssociationsRequest": {
"TransitGatewayRouteTableId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "255.251.4.254",
"userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
ImportKeyPair
#Description
Imports the public key from an RSA or ED25519 key pair that you created with a third-party tool.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "84583c7-6829-4f84-b2d8-641fc3245b60",
"eventName": "ImportKeyPair",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-07-12T13:32:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "be0e5d91-ffca-431f-8cf7-c318f71ade28",
"requestParameters": {
"keyName": "p0wn3d",
"publicKeyMaterial": "YzNOb0xYSnpZU0JCUVVGQlFqTk9lbUZETVhsak1rVkJRVUZCUkVGUlFVSkJRVUZEUVZGRVRHVlNiRkpvTldWemRUTjJiemszTWxGbVNYY3pLelpzVTJ0NGNqUm1abVp4Y0dWd1JuTnFiRkZyZG1OM1NrVlNUR0pFWWs5QmEzQkVaVFJGWmxOaFEyVm9TbmxHWjBoTVRYbDVNMkpwYzJKeGJXUlVlbTUzZFhoRk1rMDRZWEI2Tkc1MmRtcENVVFJ2YWt4TFprRlllVFI1VERGb1lWTkJSVkJMYjFBeE1YRnBkRlo1UWtzcldFbEdMMWwxWlhwdFNscEhlR2hGTVZjMEwydDBUMnRoUVZaRGJqaHJXU3REVERaSlJqaFVlRkIxVFRWUFkwUk5PR1J3UkU0NVptZFBVbXh5Y0dsWmF6ZDNObnBYTWpoQmJWcHBkazVrV2xCREsxVlRWWEJJU25ZMk1GY3lSMUZ2Vm1KTGVHZGhTbXhyWTNGV2N6RnBWRGxqVW1aalVXSXllaXR0YkhNMEsxZHlNWEYwWjNaU04wMUdiblpwVW0xUGMzVm5kM1l6WVVSTFZUSjZUbnAwY1V4MFpFWTVTR2d3YUdWNlYyOUllbWQxUnpWVWJTOU1VV3A1WWtaVVdTOWlPSGxSTld0YVVVRnVTMnRNZFdWamMwOUpSalpUWlVaeGNtWnJOM3BaUVZaQ2VGaFVUV1kzYkdOWGNVcFlObEZJZGtvd1ptMW5VWFJVVVhBMWJrVjVVbTVTYjI1UGF5OTFkMEl6VVRVMlQwMVpXVGRxYVRRM1QyVXJha3RJVldJdk5FMVJMMVUzY1RSUVMxTlRObmhRUVRWU2RXOVNSbXhqZW5wSVpWWnFRVFIzVFZOTGEzZHJNRFZWUmtWb1ptVlRibVZoWnl0M1EyODBlbWxMZFV0aVpIaEJWRWRaWlhCQlQxZFhNakZyTUZOeWIwbFdUSGxCTVhZMmVGSk5heko0VjJOdmVYcEVaRVpzV1ZOSFdYQlRNVFpJTW5sUE0xRmhSSGRvT1VOc1YxZ3pWbmxLUlVoYVYwOHdUbnBhYURCRVJuTm1SelZCUzJRMk5sZFdXbFpIVEdoV1kyNWlOWFpLUVdsbVVFcDVPR280TVZJclJUZHBXVFZxUnpSeFVGWkVlQzk1VEVWbVJUTnBVbmd5VEdWbk9WQTVTV3BsTlZsMmFteFRhMDU1YnpaUU5FSnlMelJPYzA5TlNEbFBRbTFsU1ZWUWNDOWFOV1EyY21jM1VESTBkVVp3VUhjOVBTQm1iR0YzY3k1amJHOTFaQW89"
},
"responseElements": null,
"sourceIPAddress": "62.252.86.211",
"userAgent": "aws-cli/1.10.59 Python/2.7.10 Darwin/16.6.0 botocore/1.4.49",
"userIdentity": {
"accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
Detection Rules #
Sigma #
T1078References #
ModifyImageAttribute
#Description
Modifies the specified attribute of the specified AMI, such as launch permissions or description.
CloudTrail management event, logged by default. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "8fe3095f-909c-41f5-a769-00b9ec6e95df",
"eventName": "ModifyImageAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:11:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "9a32473d-7495-4050-aa14-572331ab538d",
"requestParameters": {
"attributeType": "launchPermission",
"imageId": "ami-0aa1d83d0b0985c86",
"launchPermission": {
"add": {
"items": [
{
"userId": "012345678901"
}
]
}
}
},
"responseElements": {
"_return": true,
"requestId": "9a32473d-7495-4050-aa14-572331ab538d"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "stratus-red-team_b47d6b97-21d3-4b01-8937-6f0c23cb2d4b",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Common Indicators #
Field Kind Value Rules Vendors aws::requestParameters (elastic rule field)contains add=1 rule elastic Detection Rules #
Elastic #
T1537Splunk #
T1537YARA-L #
T1537↳ also matches ModifySnapshotAttribute References #
ModifyInstanceAttribute
#Description
Modifies the specified attribute of the specified EC2 instance, such as instance type or user data.
CloudTrail management event, logged by default. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "1bb6c2f9-b96b-485d-92ad-380e4be8b1b1",
"eventName": "ModifyInstanceAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:08:05Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "6920dcec-599d-43ff-8718-060e4ca65a2a",
"requestParameters": {
"disableApiTermination": {
"value": false
},
"instanceId": "i-0dbc91f429e48eeed"
},
"responseElements": {
"_return": true,
"requestId": "6920dcec-599d-43ff-8718-060e4ca65a2a"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Common Indicators #
Field Kind Value Rules Vendors aws::userIdentity.type (elastic rule field)ne awsservice1 rule elastic readOnly (panther rule field)is_null 1 rule panther Detection Rules #
Sigma #
Elastic #
ModifyInstanceAttribute with user data, followed by stop and start. Adversaries may update userData and cycle instance state so malicious scripts execute as root on Linux or as the system context on Windows. This rule correlates successful StopInstances, StartInstances, and ModifyInstanceAttribute events that reference userData within a five-minute window, grouped by instance, user.name, account, source IP, and user agent. A hit requires exactly three distinct API names in that bucket.T1059, T1059.009, T1578↳ also matches StartInstances, StopInstances T1133, T1562, T1562.007, T1578, T1578.005↳ also matches AuthorizeSecurityGroupEgress, AuthorizeSecurityGroupIngress, CreateSecurityGroup, ModifySecurityGroupRules, RevokeSecurityGroupEgress, RevokeSecurityGroupIngress Kusto #
T1059↳ also matches CreateLaunchTemplate YARA-L #
T1037Panther #
T1059T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, StartInstances, StopInstances, AssociateInstanceEventWindow, BundleInstance, and 24 more References #
ModifySecurityGroupRules
#Description
Modifies the rules of a security group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidGroupId.Malformed",
"errorMessage": "Invalid id: \"dw-probe\"",
"eventCategory": "Management",
"eventID": "3c366502-f456-49ff-997d-a17a03b76096",
"eventName": "ModifySecurityGroupRules",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:21Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c6abadad-be41-41f2-b579-e900640d2fa9",
"requestParameters": {
"ModifySecurityGroupRulesRequest": {
"GroupId": "dw-probe",
"SecurityGroupRule": {
"SecurityGroupRuleId": "dw-probe",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1133, T1562, T1562.007, T1578, T1578.005↳ also matches AuthorizeSecurityGroupEgress, AuthorizeSecurityGroupIngress, CreateSecurityGroup, ModifyInstanceAttribute, RevokeSecurityGroupEgress, RevokeSecurityGroupIngress
ModifySnapshotAttribute
#Description
Adds or removes permission settings for the specified EBS snapshot, such as sharing it with other accounts.
CloudTrail management event, logged by default. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "3ad01b1d-ebc1-4830-994b-9210534ab9f2",
"eventName": "ModifySnapshotAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:11:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "f088a80d-123f-419d-9970-51fb5ee592b3",
"requestParameters": {
"attributeType": "CREATE_VOLUME_PERMISSION",
"createVolumePermission": {
"remove": {
"items": [
{
"userId": "012345678912"
}
]
}
},
"snapshotId": "snap-083d3b857c13988bc"
},
"responseElements": {
"_return": true,
"requestId": "f088a80d-123f-419d-9970-51fb5ee592b3"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "stratus-red-team_8bec4cee-9e27-423f-a9af-2e0b8f6407f3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Common Indicators #
Field Kind Value Rules Vendors aws::requestParameters (elastic rule field)contains attributetype=create_volume_permission2 rules elastic aws::requestParameters (elastic rule field)contains add=1 rule elastic Detection Rules #
Sigma #
T1537Elastic #
T1537T1485, T1490, T1578, T1578.005Splunk #
T1537T1537T1537↳ also matches DescribeSnapshotAttribute YARA-L #
T1537↳ also matches ModifyImageAttribute Panther #
T1537References #
ReplaceNetworkAclEntry
#Description
Replaces an entry (rule) in a network ACL, changing subnet traffic filtering.
Example CloudTrail Event #
{
"awsRegion": "eu-central-1",
"eventCategory": "Management",
"eventID": "46fe04b8-d007-4933-8bb8-c8b65c1121fa",
"eventName": "ReplaceNetworkAclEntry",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-01-12T08:49:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "111111111111",
"requestID": "97b40da9-9291-4a92-8e9e-892b6887ffc9",
"requestParameters": {
"aclProtocol": "-1",
"cidrBlock": "0.0.0.0/0",
"egress": false,
"icmpTypeCode": {},
"networkAclId": "acl-078ccebebcbabe175",
"portRange": {},
"ruleAction": "allow",
"ruleNumber": 20
},
"responseElements": {
"_return": true,
"requestId": "97b40da9-9291-4a92-8e9e-892b6887ffc9"
},
"sourceIPAddress": "95.90.199.65",
"userAgent": "console.ec2.amazonaws.com",
"userIdentity": {
"accessKeyId": "ASIAYTOGP2RLF3F7BXZK",
"accountId": "111111111111",
"arn": "arn:aws:sts::111111111111:assumed-role/okta_adm_role/pbareiss@splunk.local",
"principalId": "AROAIJIESMXKGCJRCTPR6:pbareiss@splunk.local",
"sessionContext": {
"attributes": {
"creationDate": "2021-01-12T08:36:15Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:role/okta_adm_role",
"principalId": "AROAIJIESMXKGCJRCTPR6",
"type": "Role",
"userName": "okta_adm_role"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aclProtocol | eq | -1 | 2 rules | kusto, splunk |
egress | eq | false | 2 rules | kusto, splunk |
ruleAction | eq | allow | 2 rules | kusto, splunk |
event.outcome (elastic rule field) | in | success | 1 rule | elastic |
requestParameters.egress (splunk rule field) | eq | false | 1 rule | splunk |
requestParameters.ruleAction (splunk rule field) | eq | allow | 1 rule | splunk |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1562, T1562.007↳ also matches CreateNetworkAclEntry Splunk #
CreateNetworkAclEntry or…T1686, T1686.001↳ also matches CreateNetworkAclEntry CreateNetworkAclEntry or…T1686, T1686.001↳ also matches CreateNetworkAclEntry Kusto #
T1562, T1562.007↳ also matches CreateNetworkAclEntry Panther #
T1562↳ also matches CreateNetworkAcl, CreateNetworkAclEntry, DeleteNetworkAcl, DeleteNetworkAclEntry, ReplaceNetworkAclAssociation
References #
ReplaceRoute
#Description
Replaces an existing route within a route table in a VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "e3375d69-4b28-4ff6-9666-66827aab6d05",
"eventName": "ReplaceRoute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:59:22Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "3d677f6d-dede-423a-8b82-56888201c93f",
"requestParameters": {
"destinationCidrBlock": "0.0.0.0/0",
"gatewayId": "igw-0dbea4ea3477eb902",
"routeTableId": "rtb-0ddfb417e20642f73"
},
"responseElements": {
"_return": true,
"requestId": "3d677f6d-dede-423a-8b82-56888201c93f"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1578, T1578.005↳ also matches DeleteRoute, DeleteRouteTable, DisassociateRouteTable, ReplaceRouteTableAssociation Panther #
T1048↳ also matches CreateRouteTable, DeleteRouteTable, DisassociateRouteTable, ReplaceRouteTableAssociation
ReplaceRouteTableAssociation
#Description
Changes the route table associated with a given subnet, internet gateway, or virtual private gateway in a VPC.
Example CloudTrail Event #
{
"eventVersion": "1.11",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE"
},
"eventTime": "2026-07-28T20:58:49Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "ReplaceRouteTableAssociation",
"awsRegion": "us-west-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#ec2.replace-route-table-association",
"requestParameters": {
"associationId": "rtbassoc-0c6f61e58e08fd22b",
"routeTableId": "rtb-0ec9cda21de307a6b"
},
"responseElements": {
"requestId": "1dc9f17c-400f-4780-a4f8-5df00e02d775",
"newAssociationId": "rtbassoc-0e791b0a24b6d08c2",
"associationState": {
"state": "associated"
}
},
"requestID": "1dc9f17c-400f-4780-a4f8-5df00e02d775",
"eventID": "8bd1155a-a61a-4f1e-9a1f-b29bfe42e377",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
T1578, T1578.005↳ also matches DeleteRoute, DeleteRouteTable, DisassociateRouteTable, ReplaceRoute Panther #
T1048↳ also matches CreateRouteTable, DeleteRouteTable, DisassociateRouteTable, ReplaceRoute
RevokeSecurityGroupEgress
#Description
Removes outbound rules from a security group.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "d2dedbf2-62a8-4362-bcad-aa1670e80c0f",
"eventName": "RevokeSecurityGroupEgress",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:10:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "5fbf4781-20ed-475e-94b4-0159c242c255",
"requestParameters": {
"groupId": "sg-04cfb7a4712d75b00",
"ipPermissions": {
"items": [
{
"fromPort": 0,
"groups": {},
"ipProtocol": "-1",
"ipRanges": {
"items": [
{
"cidrIp": "0.0.0.0/0"
}
]
},
"ipv6Ranges": {},
"prefixListIds": {},
"toPort": 0
}
]
}
},
"responseElements": {
"_return": true,
"requestId": "5fbf4781-20ed-475e-94b4-0159c242c255"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_2142a106-933f-4595-ad51-0ff5dfff60b7 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Sigma #
T1190↳ also matches AuthorizeSecurityGroupEgress, AuthorizeSecurityGroupIngress, RevokeSecurityGroupIngress Elastic #
T1133, T1562, T1562.007, T1578, T1578.005↳ also matches AuthorizeSecurityGroupEgress, AuthorizeSecurityGroupIngress, CreateSecurityGroup, ModifyInstanceAttribute, ModifySecurityGroupRules, RevokeSecurityGroupIngress Kusto #
T1562, T1562.007↳ also matches AuthorizeSecurityGroupEgress, AuthorizeSecurityGroupIngress, RevokeSecurityGroupIngress Panther #
T1562↳ also matches AuthorizeSecurityGroupEgress, AuthorizeSecurityGroupIngress, CreateSecurityGroup, RevokeSecurityGroupIngress, DeleteSecurityGroup
References #
RevokeSecurityGroupIngress
#Description
Removes inbound rules from a security group.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "8733f811-267d-4c46-8e5b-000fe7c6a9f2",
"eventName": "RevokeSecurityGroupIngress",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:11:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "d7ba453f-54ce-4c38-98a1-01757c45994e",
"requestParameters": {
"cidrIp": "0.0.0.0/0",
"fromPort": 22,
"groupId": "sg-04cfb7a4712d75b00",
"ipPermissions": {},
"ipProtocol": "tcp",
"toPort": 22
},
"responseElements": {
"_return": true,
"requestId": "d7ba453f-54ce-4c38-98a1-01757c45994e"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "stratus-red-team_4277e8d8-8ab5-4267-a2da-439e2df93964",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Sigma #
T1190↳ also matches AuthorizeSecurityGroupEgress, AuthorizeSecurityGroupIngress, RevokeSecurityGroupEgress Elastic #
T1133, T1562, T1562.007, T1578, T1578.005↳ also matches AuthorizeSecurityGroupEgress, AuthorizeSecurityGroupIngress, CreateSecurityGroup, ModifyInstanceAttribute, ModifySecurityGroupRules, RevokeSecurityGroupEgress Kusto #
T1562, T1562.007↳ also matches AuthorizeSecurityGroupEgress, AuthorizeSecurityGroupIngress, RevokeSecurityGroupEgress Panther #
T1562↳ also matches AuthorizeSecurityGroupEgress, AuthorizeSecurityGroupIngress, CreateSecurityGroup, RevokeSecurityGroupEgress, DeleteSecurityGroup References #
StartInstances
#Description
Starts one or more stopped EC2 instances, transitioning them to the running state.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "177b7f6d-b28d-4d45-a1fd-cf4c4ca49d65",
"eventName": "StartInstances",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-07-07T17:31:05Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "797507667711",
"requestID": "6ace67aa-1ddd-4af1-a5ec-a17a0d9db71c",
"requestParameters": {
"instancesSet": {
"items": [
{
"instanceId": "i-0c13b9b6d209978fc"
}
]
}
},
"responseElements": {
"instancesSet": {
"items": [
{
"currentState": {
"code": 16,
"name": "running"
},
"instanceId": "i-0c13b9b6d209978fc",
"previousState": {
"code": 16,
"name": "running"
}
}
]
},
"requestId": "6ace67aa-1ddd-4af1-a5ec-a17a0d9db71c"
},
"sourceIPAddress": "3.142.206.200",
"userAgent": "Boto3/1.17.24 Python/3.6.13 Linux/4.19.0-17-cloud-amd64 Botocore/1.20.98 Resource",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI37S4KUWNVD",
"accountId": "797507667711",
"arn": "arn:aws:sts::797507667711:assumed-role/Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG/1625678983.751919",
"principalId": "AROA3TLZJI37S6HPJWVJ2:1625678983.751919",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T17:29:43Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:role/Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG",
"principalId": "AROA3TLZJI37S6HPJWVJ2",
"type": "Role",
"userName": "Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aws::userIdentity.type (elastic rule field) | ne | awsservice | 1 rule | elastic |
readOnly (panther rule field) | is_null | | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
ModifyInstanceAttribute with user data, followed by stop and start. Adversaries may update userData and cycle instance state so malicious scripts execute as root on Linux or as the system context on Windows. This rule correlates successful StopInstances, StartInstances, and ModifyInstanceAttribute events that reference userData within a five-minute window, grouped by instance, user.name, account, source IP, and user agent. A hit requires exactly three distinct API names in that bucket.T1059, T1059.009, T1578↳ also matches ModifyInstanceAttribute, StopInstances Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StopInstances, AssociateInstanceEventWindow, BundleInstance, and 24 more
References #
StopInstances
#Description
Stops one or more running EC2 instances, transitioning them to the stopped state.
CloudTrail management event, logged by default. Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidInstanceID.NotFound",
"errorMessage": "The instance ID 'i-aa2d3b42e5c6e801a' does not exist",
"eventID": "dc0dfe91-d710-44c7-9329-582a892fa67d",
"eventName": "StopInstances",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-04-07T08:41:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "23840-7c24-4527-895e-95133564543b",
"requestParameters": {
"force": false,
"instancesSet": {
"items": [
{
"instanceId": "i-aa2d3b42e5c6e801a"
}
]
}
},
"responseElements": null,
"sourceIPAddress": "253.246.250.252",
"userAgent": "aws-cli/1.11.72 Python/2.7.10 Darwin/15.6.0 botocore/1.5.35",
"userIdentity": {
"accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
Common Indicators #
Field Kind Value Rules Vendors aws::userIdentity.type (elastic rule field)ne awsservice1 rule elastic readOnly (panther rule field)is_null 1 rule panther Detection Rules #
Elastic #
ModifyInstanceAttribute with user data, followed by stop and start. Adversaries may update userData and cycle instance state so malicious scripts execute as root on Linux or as the system context on Windows. This rule correlates successful StopInstances, StartInstances, and ModifyInstanceAttribute events that reference userData within a five-minute window, grouped by instance, user.name, account, source IP, and user agent. A hit requires exactly three distinct API names in that bucket.T1059, T1059.009, T1578↳ also matches ModifyInstanceAttribute, StartInstances Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, AssociateInstanceEventWindow, BundleInstance, and 24 more References #
AcceptAddressTransfer
#Description
Accepts an Elastic IP address transfer.
AcceptCapacityReservationBillingOwnership
#Description
Accepts a request to assign billing of the available capacity of a shared Capacity Reservation to your account.
AcceptReservedInstancesExchangeQuote
#Description
Purchases Convertible Reserved Instance offerings described in the GetReservedInstancesExchangeQuote call.
AcceptTransitGatewayClientVpnAttachment
#Description
Accepts a Transit Gateway attachment request for a Client VPN endpoint.
AcceptTransitGatewayMulticastDomainAssociations
#Description
Accepts a request to associate subnets with a transit gateway multicast domain.
AcceptTransitGatewayPeeringAttachment
#Description
Accepts a transit gateway peering attachment request.
AcceptTransitGatewayVpcAttachment
#Description
Accepts a request to attach a VPC to a transit gateway.
AcceptVpcEndpointConnections
#Description
Accepts connection requests to your VPC endpoint service.
AcceptVpcPeeringConnection
#Description
Accept a VPC peering connection request.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "Client.MissingParameter",
"errorMessage": "The request must contain the parameter vpcPeeringConnectionId",
"eventID": "1a15843b-adb2-4d39-8461-ce2708d95fb0",
"eventName": "AcceptVpcPeeringConnection",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2019-11-17T04:57:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "25a99520-381c-431f-b22e-b74a16171dac",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "8.103.248.255",
"userAgent": "aws-cli/1.14.44 Python/3.6.8 Linux/4.4.0-039049-Microsoft botocore/1.8.48",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches AttachClassicLinkVpc, CreateVpc, DeleteVpc, DetachClassicLinkVpc, DisableVpcClassicLink, EnableVpcClassicLink, ModifyVpcAttribute, RejectVpcPeeringConnection
References #
AdvertiseByoipCidr
#Description
Advertises an IPv4 or IPv6 address range that is provisioned for use with your Amazon Web Services resources through bring your own IP addresses (BYOIP).
AllocateAddress
#Description
Acquires an Elastic IP address.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "a4ff516f-8f9a-4c36-9700-b31a883c1a6e",
"eventName": "AllocateAddress",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "c6671a81-468c-41e2-abd5-0ec843ee0db3",
"requestParameters": {
"domain": "vpc",
"tagSpecificationSet": {
"items": [
{
"resourceType": "elastic-ip",
"tags": [
{
"key": "StratusRedTeam",
"value": "true"
},
{
"key": "Name",
"value": "stratus-red-team-ec2-steal-credentials-vpc-us-east-1a"
}
]
}
]
}
},
"responseElements": {
"allocationId": "eipalloc-08a083beb7e83dbc0",
"domain": "vpc",
"networkBorderGroup": "us-east-1",
"publicIp": "3.225.16.109",
"publicIpv4Pool": "amazon",
"requestId": "c6671a81-468c-41e2-abd5-0ec843ee0db3"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
AllocateHosts
#Description
Allocates a Dedicated host to your account.
Example CloudTrail Event #
{
"awsRegion": "eu-central-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "0f1a55f6-8037-47c9-a18e-acbe82d028ec",
"eventName": "AllocateHosts",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2019-11-29T15:27:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "be142301d-3728-4735-b9d7-41e8b8622c8d",
"requestParameters": {
"AllocateHostsRequest": {
"AvailabilityZone": "us-west-2",
"InstanceType": "ec2-bucket",
"Quantity": 5
}
},
"responseElements": null,
"sourceIPAddress": "7.253.56.8",
"userAgent": "aws-cli/1.16.283 Python/3.8.0 Linux/5.3.13-arch1-1 botocore/1.13.19",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
AllocateIpamPoolCidr
#Description
Allocate a CIDR from an IPAM pool.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "be4066de-94e9-4b39-bc18-43f93feaa6b8",
"eventName": "AllocateIpamPoolCidr",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:48:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "180726fb-9a1f-4ea0-bf7d-6eeed0a63e84",
"requestParameters": {
"AllocateIpamPoolCidrRequest": {
"ClientToken": "01735761-51a6-4431-8f95-b22a07933940",
"IpamPoolId": "ipam-pool-0b5795c40ef5b6d99",
"NetmaskLength": 24
}
},
"responseElements": {
"AllocateIpamPoolCidrResponse": {
"ipamPoolAllocation": {
"cidr": "10.99.0.0/24",
"ipamPoolAllocationId": "ipam-pool-alloc-08d34d8a8aa0b4bfbaabdfc4faf06af7d",
"resourceOwner": 123456789012,
"resourceType": "custom"
},
"requestId": "180726fb-9a1f-4ea0-bf7d-6eeed0a63e84",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ApplySecurityGroupsToClientVpnTargetNetwork
#Description
Applies a security group to the association between the target network and the Client VPN endpoint.
AssignIpv6Addresses
#Description
Assigns the specified IPv6 addresses to the specified network interface.
AssignPrivateIpAddresses
#Description
Assigns one or more secondary private IP addresses to the specified network interface.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "ad0c4a96-134c-491d-944b-a69b82e5e7ba",
"eventName": "AssignPrivateIpAddresses",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:45:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "155fa9a2-f153-46ef-a2d5-a2f85534a71e",
"requestParameters": {
"ipv4Prefixes": {},
"networkInterfaceId": "eni-025f9aaa17cd9ff32",
"privateIpAddressesSet": {},
"secondaryPrivateIpAddressCount": 1
},
"responseElements": {
"_return": true,
"assignedIpv4PrefixSet": {},
"assignedPrivateIpAddressesSet": {
"assignedPrivateIpAddressSetType": [
{
"privateIpAddress": "10.0.1.174"
}
]
},
"networkInterfaceId": "eni-025f9aaa17cd9ff32",
"requestId": "155fa9a2-f153-46ef-a2d5-a2f85534a71e"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
AssignPrivateNatGatewayAddress
#Description
Assigns private IPv4 addresses to a private NAT gateway.
AssociateAddress
#Description
Associates an Elastic IP address with an instance or a network interface.
Example CloudTrail Event #
{
"awsRegion": "eu-central-1",
"eventCategory": "Management",
"eventID": "efada543-5dac-4f94-b096-88220d344e2f",
"eventName": "AssociateAddress",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-01-12T08:37:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "111111111111",
"requestID": "605dde78-b714-4c16-b2e2-61b76cfe2375",
"requestParameters": {
"allocationId": "eipalloc-e0d96cc5",
"instanceId": "i-0d0e3add0666f1aba"
},
"responseElements": {
"_return": true,
"associationId": "eipassoc-01cb5aa4d99f385a5",
"requestId": "605dde78-b714-4c16-b2e2-61b76cfe2375"
},
"sourceIPAddress": "95.90.199.65",
"userAgent": "aws-sdk-go/1.36.7 (go1.15.5; darwin; amd64) APN/1.0 HashiCorp/1.0 Terraform/0.14.4 (+https://www.terraform.io)",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLJ2OYSF6E",
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:user/patrick_cli",
"principalId": "AIDAYTOGP2RLNALZHZ6KX",
"type": "IAMUser",
"userName": "patrick_cli"
}
}
References #
AssociateCapacityReservationBillingOwner
#Description
Initiates a request to assign billing of the unused capacity of a shared Capacity Reservation to a consumer account that is consolidated under the same Amazon Web Services organizations payer account.
AssociateClientVpnTargetNetwork
#Description
Associates a target network with a Client VPN endpoint.
AssociateDhcpOptions
#Description
Associates a set of DHCP options (that you've previously created) with the specified VPC, or associates no DHCP options with the VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "8f88b9d0-c8df-4a8b-a157-9dc5f8995e10",
"eventName": "AssociateDhcpOptions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:40:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d16a5bce-ebe5-420f-be5d-e3aef4d5a4bd",
"requestParameters": {
"dhcpOptionsId": "dopt-04bc4cfc118aff25e",
"vpcId": "vpc-00c0dad452596a616"
},
"responseElements": {
"_return": true,
"requestId": "d16a5bce-ebe5-420f-be5d-e3aef4d5a4bd"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
AssociateEnclaveCertificateIamRole
#Description
Associates an Identity and Access Management (IAM) role with an Certificate Manager (ACM) certificate.
AssociateInstanceEventWindow
#Description
Associates one or more targets with an event window.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "0d2060bc-f98d-4d90-ac0f-511320613b5d",
"eventName": "AssociateInstanceEventWindow",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:40:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e8ba6499-10e0-46cd-8eda-5741c5a11986",
"requestParameters": {
"AssociateInstanceEventWindowRequest": {
"AssociationTarget": {
"InstanceId": {
"content": "i-0a4c8f9124bcc1a50",
"tag": 1
}
},
"InstanceEventWindowId": "iew-0812df4e4314df613"
}
},
"responseElements": {
"AssociateInstanceEventWindowResponse": {
"instanceEventWindow": {
"associationTarget": {
"dedicatedHostIdSet": "",
"instanceIdSet": {
"item": "i-0a4c8f9124bcc1a50"
},
"tagSet": ""
},
"instanceEventWindowId": "iew-0812df4e4314df613",
"name": "dwfix-ec2-d393e412-iew",
"state": "associating",
"timeRangeSet": {
"item": {
"endHour": 7,
"endWeekDay": "monday",
"startHour": 3,
"startWeekDay": "monday"
}
}
},
"requestId": "e8ba6499-10e0-46cd-8eda-5741c5a11986",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
readOnly (panther rule field) | is_null | | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, BundleInstance, and 24 more
AssociateIpamByoasn
#Description
Associates your Autonomous System Number (ASN) with a BYOIP CIDR that you own in the same Amazon Web Services Region.
AssociateIpamResourceDiscovery
#Description
Associates an IPAM resource discovery with an Amazon VPC IPAM.
AssociateNatGatewayAddress
#Description
Associates Elastic IP addresses (EIPs) and private IPv4 addresses with a public NAT gateway.
AssociateRouteServer
#Description
Associates a route server with a VPC to enable dynamic route updates.
AssociateRouteTable
#Description
Associates a subnet with a route table.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "a8126719-8ca9-43a1-9c1c-4fddd2bef9a8",
"eventName": "AssociateRouteTable",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "baeec94d-10e0-455c-8a97-c17cec60fd66",
"requestParameters": {
"routeTableId": "rtb-0c7c2f4aff3677054",
"subnetId": "subnet-01ed430875cff578d"
},
"responseElements": {
"associationId": "rtbassoc-0b911e98f29251a51",
"associationState": {
"state": "associated"
},
"requestId": "baeec94d-10e0-455c-8a97-c17cec60fd66"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
AssociateSecurityGroupVpc
#Description
Associates a security group with another VPC in the same Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "841bcc2b-a9d2-49cd-bf3d-5ec0183d84af",
"eventName": "AssociateSecurityGroupVpc",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:39:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "37f0c994-2a00-4feb-a44b-bba672a6ca67",
"requestParameters": {
"AssociateSecurityGroupVpcRequest": {
"GroupId": "sg-0cfd1af7bf967b6fc",
"VpcId": "vpc-0fd8eff23767cf1e5"
}
},
"responseElements": {
"AssociateSecurityGroupVpcResponse": {
"requestId": "37f0c994-2a00-4feb-a44b-bba672a6ca67",
"state": "associating",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
AssociateSubnetCidrBlock
#Description
Associates a CIDR block with your subnet.
AssociateTransitGatewayMulticastDomain
#Description
Associates the specified subnets and transit gateway attachments with the specified transit gateway multicast domain.
AssociateTransitGatewayPolicyTable
#Description
Associates the specified transit gateway attachment with a transit gateway policy table.
AssociateTransitGatewayRouteTable
#Description
Associates the specified attachment with the specified transit gateway route table.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "d8a1daf0-c8f3-491e-aefb-fcdbd13080f6",
"eventName": "AssociateTransitGatewayRouteTable",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:47:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c7aceb67-cf03-4ae5-8fe6-1459114c817a",
"requestParameters": {
"AssociateTransitGatewayRouteTableRequest": {
"TransitGatewayAttachmentId": "tgw-attach-08d8a09ccdcb3d355",
"TransitGatewayRouteTableId": "tgw-rtb-0f5c12c8b5c90a1a1"
}
},
"responseElements": {
"AssociateTransitGatewayRouteTableResponse": {
"association": {
"resourceId": "vpc-00c0dad452596a616",
"resourceType": "vpc",
"state": "associating",
"transitGatewayAttachmentId": "tgw-attach-08d8a09ccdcb3d355",
"transitGatewayRouteTableId": "tgw-rtb-0f5c12c8b5c90a1a1"
},
"requestId": "c7aceb67-cf03-4ae5-8fe6-1459114c817a",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
AssociateTrunkInterface
#Description
Associates a branch network interface with a trunk network interface.
AssociateVpcCidrBlock
#Description
Associates a CIDR block with your VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "dce0ccb0-e48b-4db4-b187-f78fa95dd22e",
"eventName": "AssociateVpcCidrBlock",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:39:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "cef3a6c9-8d5a-4cbe-8bac-d290334631b8",
"requestParameters": {
"AssociateVpcCidrBlockRequest": {
"CidrBlock": "10.1.0.0/16",
"VpcId": "vpc-00c0dad452596a616"
}
},
"responseElements": {
"AssociateVpcCidrBlockResponse": {
"cidrBlockAssociation": {
"associationId": "vpc-cidr-assoc-05797b2675bca50e1",
"cidrBlock": "10.1.0.0/16",
"cidrBlockState": {
"state": "associating"
}
},
"requestId": "cef3a6c9-8d5a-4cbe-8bac-d290334631b8",
"vpcId": "vpc-00c0dad452596a616",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
AttachClassicLinkVpc
#Description
Links an EC2-Classic instance to a ClassicLink-enabled VPC through one or more of the VPC's security groups.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches AcceptVpcPeeringConnection, CreateVpc, DeleteVpc, DetachClassicLinkVpc, DisableVpcClassicLink, EnableVpcClassicLink, ModifyVpcAttribute, RejectVpcPeeringConnection
AttachImageWatermark
#Description
Attaches a watermark to a non-public AMI.
AttachInternetGateway
#Description
Attaches an Internet gateway to a VPC, enabling connectivity between the Internet and the VPC.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "2b4e0526-7813-410b-b6a5-366704c3b0d3",
"eventName": "AttachInternetGateway",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "b095e717-86e3-4b4b-9f2b-42d319ba95c9",
"requestParameters": {
"internetGatewayId": "igw-02a84e4222d62e16b",
"vpcId": "vpc-06fe1a64761a0f720"
},
"responseElements": {
"_return": true,
"requestId": "b095e717-86e3-4b4b-9f2b-42d319ba95c9"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches CreateCustomerGateway, CreateInternetGateway, DeleteCustomerGateway, DeleteInternetGateway, DetachInternetGateway
References #
AttachNetworkInterface
#Description
Attaches a network interface to an instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.AttachmentLimitExceeded",
"errorMessage": "Device index 2 exceeds the limit for t3.micro",
"eventCategory": "Management",
"eventID": "547b135a-b17e-4651-a15b-ae52196862a5",
"eventName": "AttachNetworkInterface",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:45:56Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f089ddb8-5583-4dcd-87ef-e87a5c7e8633",
"requestParameters": {
"deviceIndex": 2,
"instanceId": "i-0a4c8f9124bcc1a50",
"networkInterfaceId": "eni-025f9aaa17cd9ff32"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
AttachVerifiedAccessTrustProvider
#Description
Attaches the specified Amazon Web Services Verified Access trust provider to the specified Amazon Web Services Verified Access instance.
AttachVolume
#Description
Attaches an Amazon EBS volume to a running or stopped instance and exposes it to the instance with the specified device name.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "eacfe628-253d-425e-ba32-17d1d36c2ffc",
"eventName": "AttachVolume",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-07-07T17:31:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "797507667711",
"requestID": "16f946c8-83ce-49b3-86c4-3b57f23eea38",
"requestParameters": {
"deleteOnTermination": false,
"device": "/dev/sdf",
"instanceId": "i-0c13b9b6d209978fc",
"volumeId": "vol-0f760d9398c64e477"
},
"responseElements": {
"attachTime": 1625679062578,
"deleteOnTermination": false,
"device": "/dev/sdf",
"instanceId": "i-0c13b9b6d209978fc",
"requestId": "16f946c8-83ce-49b3-86c4-3b57f23eea38",
"status": "attaching",
"volumeId": "vol-0f760d9398c64e477"
},
"sourceIPAddress": "3.142.206.200",
"userAgent": "Boto3/1.17.24 Python/3.6.13 Linux/4.19.0-17-cloud-amd64 Botocore/1.20.98",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI37S4KUWNVD",
"accountId": "797507667711",
"arn": "arn:aws:sts::797507667711:assumed-role/Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG/1625678983.751919",
"principalId": "AROA3TLZJI37S6HPJWVJ2:1625678983.751919",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T17:29:43Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:role/Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG",
"principalId": "AROA3TLZJI37S6HPJWVJ2",
"type": "Role",
"userName": "Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
References #
AttachVpnGateway
#Description
Attaches a virtual private gateway to a VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "87701e6c-d68d-498d-bec4-17930ecb1492",
"eventName": "AttachVpnGateway",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:46:04Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "fca35204-3649-4883-9c6e-c3083fa14707",
"requestParameters": {
"vpcId": "vpc-00c0dad452596a616",
"vpnGatewayId": "vgw-03b7415aef1ba49a5"
},
"responseElements": {
"attachment": {
"state": "attaching",
"vpcId": "vpc-00c0dad452596a616"
},
"requestId": "fca35204-3649-4883-9c6e-c3083fa14707"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
BundleInstance
#Description
Bundles an Amazon instance store-backed Windows instance.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
readOnly (panther rule field) | is_null | | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
CancelBundleTask
#Description
Cancels a bundling operation for an instance store-backed Windows instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidInstanceID.Malformed",
"errorMessage": "Invalid id: \"dw-probe\"",
"eventCategory": "Management",
"eventID": "7a886e2b-6fb7-46a9-b37b-cc6cafa46bfe",
"eventName": "CancelBundleTask",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:21Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "cf00540e-439b-4b99-aa76-0dfe1cd6bb95",
"requestParameters": {
"bundleId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CancelCapacityReservation
#Description
Cancels the specified Capacity Reservation, releases the reserved capacity, and changes the Capacity Reservation's state to cancelled.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidCapacityReservationId.Malformed",
"errorMessage": "The capacity-reservation ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "37993a1c-14d7-4919-952c-82968d85a7eb",
"eventName": "CancelCapacityReservation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:21Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "bdfdfc32-df6a-4d66-8cc9-b2ea1ce66627",
"requestParameters": {
"CancelCapacityReservationRequest": {
"CapacityReservationId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CancelCapacityReservationFleets
#Description
Cancels one or more Capacity Reservation Fleets.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidCapacityReservationFleetId.Malformed",
"errorMessage": "The capacity-reservation-fleet ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "00390e66-11ca-4bb9-ba82-2d3a09025fbf",
"eventName": "CancelCapacityReservationFleets",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:22Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "67b124e8-8596-40ba-aed7-9013766103f7",
"requestParameters": {
"CancelCapacityReservationFleetsRequest": {
"CapacityReservationFleetId": {
"content": "dw-probe",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CancelConversionTask
#Description
Cancels an active conversion task.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidConversionTaskId",
"errorMessage": "Parameter conversion-task-id (dw-probe) has an invalid format.",
"eventCategory": "Management",
"eventID": "1da55b23-18e4-4620-97d3-9d8fe2537c90",
"eventName": "CancelConversionTask",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:22Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9ad4be26-60cc-4582-92d8-5db21639fa27",
"requestParameters": {
"conversionTaskId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CancelDeclarativePoliciesReport
#Description
Cancels the generation of an account status report.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidDeclarativePoliciesReportId.Malformed",
"errorMessage": "The declarative-policies-report ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "0585f329-2e92-4250-af93-bea1c280456e",
"eventName": "CancelDeclarativePoliciesReport",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:22Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d43064f8-8dd1-4322-ac80-10bea32656ab",
"requestParameters": {
"CancelDeclarativePoliciesReportRequest": {
"ReportId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CancelExportTask
#Description
Cancels an active export task.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidID",
"errorMessage": "The ID 'dw-probe' is not valid",
"eventCategory": "Management",
"eventID": "95d2ae81-478b-4d12-ac18-4640e87d7d8c",
"eventName": "CancelExportTask",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:22Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4f70769a-bae6-4c54-9518-d111821da65c",
"requestParameters": {
"exportTaskId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CancelImageLaunchPermission
#Description
Removes your Amazon Web Services account from the launch permissions for the specified AMI.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidAMIID.Malformed",
"errorMessage": "The image ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "58a062f1-0b6c-4c68-b74a-17583e2629a3",
"eventName": "CancelImageLaunchPermission",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2c1f0275-a5e9-4d0c-b73b-143c29416d7d",
"requestParameters": {
"CancelImageLaunchPermissionRequest": {
"ImageId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CancelImportTask
#Description
Cancels an in-process import virtual machine or import snapshot task.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidConversionTaskId.Malformed",
"errorMessage": "Missing the task ID.",
"eventCategory": "Management",
"eventID": "23184087-6e32-43fd-b7d9-405db9bf0d7b",
"eventName": "CancelImportTask",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:45:16Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d39a3c74-cfea-4258-b5aa-4ddf42d0a8af",
"requestParameters": {
"CancelImportTaskRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CancelReservedInstancesListing
#Description
Cancels the specified Reserved Instance listing in the Reserved Instance Marketplace.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidInput",
"errorMessage": "1 validation error detected: Value 'dw-probe' at 'reservedInstanceListingId' failed to satisfy constraint: Member must satisfy regular expression pattern: \\w{8}(-\\w{4}){3}-\\w{12}",
"eventCategory": "Management",
"eventID": "8868a6f9-17af-4264-a48f-33e20ecbdf4b",
"eventName": "CancelReservedInstancesListing",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "47d9cb61-63f5-4fdf-8623-5ef51baa02e6",
"requestParameters": {
"reservedInstancesListingId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CancelSpotFleetRequests
#Description
Cancels the specified Spot fleet requests.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "1 validation error detected: Value '[dw-probe]' at 'spotFleetRequestId' failed to satisfy constraint: Member must satisfy constraint: [Member must satisfy regular expression pattern: ^(sfr|fleet)-[a-z0-9-]{36}\\b]",
"eventCategory": "Management",
"eventID": "e60c8329-8f60-4141-ae81-607b5758d62a",
"eventName": "CancelSpotFleetRequests",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "66d22131-b273-4d78-a668-7817ce668a55",
"requestParameters": {
"CancelSpotFleetRequestsRequest": {
"SpotFleetRequestId": {
"content": "dw-probe",
"tag": 1
},
"TerminateInstances": false
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CancelSpotInstanceRequests
#Description
Cancels one or more Spot Instance requests.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidSpotInstanceRequestID.Malformed",
"errorMessage": "Invalid id :\"dw-probe\" (expecting \"sir-...\")",
"eventCategory": "Management",
"eventID": "f1fac11c-6a48-44ee-beae-6c222f18f168",
"eventName": "CancelSpotInstanceRequests",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5e6dc90b-8193-40db-9397-4880962b9cd6",
"requestParameters": {
"spotInstanceRequestIdSet": {
"items": [
{
"spotInstanceRequestId": "dw-probe"
}
]
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
readOnly (panther rule field) | is_null | | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
ConfirmProductInstance
#Description
Determines whether a product code is associated with an instance.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
CopyFpgaImage
#Description
Copies the specified Amazon FPGA Image (AFI) to the current Region.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aws::errorCode (panther rule field) | ne | Client.DryRunOperation | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1204↳ also matches CreateStoreImageTask, CopyImage, CreateFpgaImage, CreateImage, CreateRestoreImageTask, ImportImage
CopyImage
#Description
Initiates the copy of an AMI from the specified source region to the region in which the request was made.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "d71c9a70-e919-4641-86b2-874c5cb234af",
"eventName": "CopyImage",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-01-26T19:22:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "068366-1818-4dc9-a12a-c474b5df3937",
"requestParameters": {
"name": "flaws",
"sourceImageId": "snap-83d15d668fb2941db",
"sourceRegion": "us-west-2"
},
"responseElements": null,
"sourceIPAddress": "34.254.7.53",
"userAgent": "aws-cli/1.14.20 Python/3.6.4 Darwin/17.3.0 botocore/1.8.24",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aws::errorCode (panther rule field) | ne | Client.DryRunOperation | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1204↳ also matches CreateStoreImageTask, CopyFpgaImage, CreateFpgaImage, CreateImage, CreateRestoreImageTask, ImportImage
References #
CopySnapshot
#Description
Copies a point-in-time snapshot of an Amazon EBS volume and stores it in Amazon S3.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "b6b212431-df2c-47ed-b77d-3dda61348d9d",
"eventName": "CopySnapshot",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-02-27T23:23:36Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "355e3f18-d1dd-4c1e-9f68-74df84d49b59",
"requestParameters": {
"description": "copying",
"destinationRegion": "us-west-2",
"presignedUrl": "https://ec2.us-west-2.amazonaws.com/?SourceRegion=us-west-2&SourceSnapshotId=snap-4fd281251b99202a3&Version=2015-04-15&Description=copying&Action=CopySnapshot&DestinationRegion=us-west-2&X-Amz-Algorithm=AWS4-HMAC-SHA256&X-Amz-Expires=3600&X-Amz-Credential=AKIA1ZBTOEKWKVHP6GHZ%2F172111%2Fus-west-2%2Fec2%2Faws4_request&X-Amz-SignedHeaders=host&X-Amz-Date=172111T50193Z&X-Amz-Signature=0f1eceb8733c78738443f70c6554022809f27d81ccce39ece8a5d6e0ae59bdd9",
"sourceRegion": "us-west-2",
"sourceSnapshotId": "snap-4fd281251b99202a3"
},
"responseElements": null,
"sourceIPAddress": "3.239.132.95",
"userAgent": "aws-cli/1.7.36 Python/2.7.11 Linux/4.4.0-34-generic",
"userIdentity": {
"accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
CopyVolumes
#Description
Creates a crash-consistent, point-in-time copy of an existing Amazon EBS volume within the same Availability Zone.
CreateCapacityManagerDataExport
#Description
Creates a new data export configuration for EC2 Capacity Manager.
CreateCapacityReservation
#Description
Creates a new Capacity Reservation with the specified attributes.
CreateCapacityReservationBySplitting
#Description
Create a new Capacity Reservation by splitting the capacity of the source Capacity Reservation.
CreateCapacityReservationCancellationQuote
#Description
Generates a cancellation quote for a future-dated Capacity Reservation that is within its commitment duration.
CreateCapacityReservationFleet
#Description
Creates a Capacity Reservation Fleet.
CreateCarrierGateway
#Description
Creates a carrier gateway.
CreateClientVpnEndpoint
#Description
Creates a Client VPN endpoint.
CreateClientVpnRoute
#Description
Adds a route to a network to a Client VPN endpoint.
CreateCoipCidr
#Description
Creates a range of customer-owned IP addresses.
CreateCoipPool
#Description
Creates a pool of customer-owned IP (CoIP) addresses.
CreateCustomerGateway
#Description
Provides information to AWS about your VPN customer gateway device.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "0cabba5e-aabf-47bc-b521-8b0011f722da",
"eventName": "CreateCustomerGateway",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:46:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "64cec76d-0b1f-490b-9372-97cfd2adf293",
"requestParameters": {
"bgpAsn": 65000,
"ipAddress": "1.2.3.4",
"tagSpecificationSet": {
"items": [
{
"resourceType": "customer-gateway",
"tags": [
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
},
{
"key": "dwfix",
"value": "1"
}
]
}
]
},
"type": "ipsec.1"
},
"responseElements": {
"customerGateway": {
"bgpAsn": 65000,
"customerGatewayId": "cgw-04a9f55555b346fed",
"ipAddress": "1.2.3.4",
"state": "available",
"tagSet": {
"items": [
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
},
{
"key": "dwfix",
"value": "1"
}
]
},
"type": "ipsec.1"
},
"requestId": "64cec76d-0b1f-490b-9372-97cfd2adf293"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches AttachInternetGateway, CreateInternetGateway, DeleteCustomerGateway, DeleteInternetGateway, DetachInternetGateway
CreateDefaultSubnet
#Description
Creates a default subnet with a size /20 IPv4 CIDR block in the specified Availability Zone in your default VPC.
CreateDefaultVpc
#Description
Creates a default VPC with a size /16 IPv4 CIDR block and a default subnet in each Availability Zone.
Example CloudTrail Event #
{
"awsRegion": "ap-northeast-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "645598b92-f4ed-486a-9f23-995199a8c64",
"eventName": "CreateDefaultVpc",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-04-16T06:59:22Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "c4e40e01-0455-42b3-a35b-8c47f9fd7151",
"requestParameters": {
"CreateDefaultVpcRequest": {}
},
"responseElements": null,
"sourceIPAddress": "155.63.17.217",
"userAgent": "Boto3/1.7.4 Python/2.7.12 Linux/4.4.0-119-generic Botocore/1.10.4",
"userIdentity": {
"accessKeyId": "ASIAGD2JRX0V6RJGWR59",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"sessionContext": {
"attributes": {
"creationDate": "2018-04-16T06:59:20Z",
"mfaAuthenticated": "false"
}
},
"type": "IAMUser",
"userName": "backup"
}
}
References #
CreateDelegateMacVolumeOwnershipTask
#Description
Delegates ownership of the Amazon EBS root volume for an Apple silicon Mac instance to an administrative user.
CreateDhcpOptions
#Description
Creates a set of DHCP options for your VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "d4bb67e1-9a7e-4faa-b719-d00c14c0bd26",
"eventName": "CreateDhcpOptions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:59:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a7e080d1-deb6-4e10-b48e-c1aa83e6882c",
"requestParameters": {
"dhcpConfigurationSet": {
"items": [
{
"key": "domain-name-servers",
"valueSet": {
"items": [
{
"value": "AmazonProvidedDNS"
}
]
}
}
]
}
},
"responseElements": {
"dhcpOptions": {
"dhcpConfigurationSet": {
"items": [
{
"key": "domain-name-servers",
"valueSet": {
"items": [
{
"value": "AmazonProvidedDNS"
}
]
}
}
]
},
"dhcpOptionsId": "dopt-0ea629e1ced764e60",
"ownerId": "123456789012",
"tagSet": {}
},
"requestId": "a7e080d1-deb6-4e10-b48e-c1aa83e6882c"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateEgressOnlyInternetGateway
#Description
[IPv6 only] Creates an egress-only internet gateway for your VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "c189c6ef-c216-4ade-b131-c87a115e0117",
"eventName": "CreateEgressOnlyInternetGateway",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:39:56Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9a93e065-12ea-48cf-b7e1-a68143758ddd",
"requestParameters": {
"CreateEgressOnlyInternetGatewayRequest": {
"TagSpecification": {
"ResourceType": "egress-only-internet-gateway",
"Tag": [
{
"Key": "Name",
"Value": "dwfix-ec2-d393e412",
"tag": 1
},
{
"Key": "dwfix",
"Value": "1",
"tag": 2
}
],
"tag": 1
},
"VpcId": "vpc-00c0dad452596a616"
}
},
"responseElements": {
"CreateEgressOnlyInternetGatewayResponse": {
"egressOnlyInternetGateway": {
"attachmentSet": {
"item": {
"state": "attached",
"vpcId": "vpc-00c0dad452596a616"
}
},
"egressOnlyInternetGatewayId": "eigw-03694f0561cfaf667",
"tagSet": {
"item": [
{
"key": "dwfix",
"value": "1"
},
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
}
]
}
},
"requestId": "9a93e065-12ea-48cf-b7e1-a68143758ddd",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateFleet
#Description
Creates an EC2 Fleet that contains the configuration information for On-Demand Instances and Spot Instances.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "341440fc-40b5-3df9-a2a1-14a67f96b841",
"eventSource": "ec2.amazonaws.com",
"eventName": "CreateFleet",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "93e1ef8b-5291-4004-8bad-426436c135c6",
"userAgent": "aws-sdk-go-v2/1.42.0 ua/2.1 os/linux lang/go#1.26.3 md/GOOS#linux md/GOARCH#arm64 exec-env/AWS_ECS_FARGATE api/ec2#1.307.0 app/APN_1.1-pc_2b9joblhmcbhnqakspwshptlz$ m/z",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com"
}
}
CreateFlowLogs
#Description
Creates one or more flow logs to capture IP traffic for a specific network interface, subnet, or VPC.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "a3fbe842-f8df-4bb3-accf-1407cc925cbd",
"eventName": "CreateFlowLogs",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:02:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "353ea5d4-f889-46d4-a632-ed784656dda4",
"requestParameters": {
"CreateFlowLogsRequest": {
"DeliverLogsPermissionArn": "arn:aws:iam::123837392027:role/stratus-red-team-remove-flow-logs-role",
"LogDestination": "arn:aws:logs:us-east-1:123837392027:log-group:/stratus-red-team/vpc-flow-logs",
"LogDestinationType": "cloud-watch-logs",
"MaxAggregationInterval": 600,
"ResourceId": {
"content": "vpc-0255d384b4b458b46",
"tag": 1
},
"ResourceType": "VPC",
"TagSpecification": {
"ResourceType": "vpc-flow-log",
"Tag": {
"Key": "StratusRedTeam",
"Value": true,
"tag": 1
},
"tag": 1
},
"TrafficType": "REJECT"
}
},
"responseElements": {
"CreateFlowLogsResponse": {
"clientToken": "oueUIFMk93wJinrrwc0QUGz+O0GaqjxHhhquvXQ1UQc=",
"flowLogIdSet": {
"item": "fl-064ed3a785e4a37ef"
},
"requestId": "353ea5d4-f889-46d4-a632-ed784656dda4",
"unsuccessful": "",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_20f9795b-aa02-4c8e-bad6-bd338ec09f59 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
CreateFpgaImage
#Description
Creates an Amazon FPGA Image (AFI) from the specified design checkpoint (DCP).
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aws::errorCode (panther rule field) | ne | Client.DryRunOperation | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1204↳ also matches CreateStoreImageTask, CopyFpgaImage, CopyImage, CreateImage, CreateRestoreImageTask, ImportImage
CreateImage
#Description
Creates an Amazon EBS-backed AMI from an Amazon EBS-backed instance that is either running or stopped.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "9c3f2709-3739-4fae-b9a0-eba022562f93",
"eventName": "CreateImage",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-01-23T10:33:22Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "c6a8e00d-575a-46d0-b251-32883f483a4",
"requestParameters": {
"blockDeviceMapping": {
"items": [
{
"deviceName": "/dev/sda1",
"ebs": {
"deleteOnTermination": true
}
}
]
},
"description": "framecon stuff",
"instanceId": "i-546b27df737a621a2",
"name": "framecon AMI",
"noReboot": true
},
"responseElements": null,
"sourceIPAddress": "166.140.209.2",
"userAgent": "Boto3/1.4.4 Python/2.7.12 Linux/4.13.0-31-generic Botocore/1.7.12",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aws::errorCode (panther rule field) | ne | Client.DryRunOperation | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1204↳ also matches CreateStoreImageTask, CopyFpgaImage, CopyImage, CreateFpgaImage, CreateRestoreImageTask, ImportImage
References #
CreateImageUsageReport
#Description
Creates a report that shows how your image is used across other Amazon Web Services accounts.
CreateInstanceConnectEndpoint
#Description
Creates an EC2 Instance Connect Endpoint.
CreateInstanceEventWindow
#Description
Creates an event window in which scheduled events for the associated Amazon EC2 instances can run.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f0063dcb-17f2-4e3c-9fdc-7c55e71944a9",
"eventName": "CreateInstanceEventWindow",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:40:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "356cc375-5198-4c0d-80ca-8bc0d9bda072",
"requestParameters": {
"CreateInstanceEventWindowRequest": {
"Name": "dwfix-ec2-d393e412-iew",
"TagSpecification": {
"ResourceType": "instance-event-window",
"Tag": [
{
"Key": "Name",
"Value": "dwfix-ec2-d393e412",
"tag": 1
},
{
"Key": "dwfix",
"Value": "1",
"tag": 2
}
],
"tag": 1
},
"TimeRange": {
"EndHour": 6,
"EndWeekDay": "sunday",
"StartHour": 2,
"StartWeekDay": "sunday",
"tag": 1
}
}
},
"responseElements": {
"CreateInstanceEventWindowResponse": {
"instanceEventWindow": {
"instanceEventWindowId": "iew-0812df4e4314df613",
"name": "dwfix-ec2-d393e412-iew",
"state": "creating",
"tagSet": {
"item": [
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
},
{
"key": "dwfix",
"value": "1"
}
]
},
"timeRangeSet": {
"item": {
"endHour": 6,
"endWeekDay": "sunday",
"startHour": 2,
"startWeekDay": "sunday"
}
}
},
"requestId": "356cc375-5198-4c0d-80ca-8bc0d9bda072",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
CreateInternetGateway
#Description
Creates an Internet gateway for use with a VPC.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "e40431f7-07bc-4d9a-a5cb-07e28107babb",
"eventName": "CreateInternetGateway",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "b23138bd-d869-4268-8c79-df643cafc60e",
"requestParameters": {
"tagSpecificationSet": {
"items": [
{
"resourceType": "internet-gateway",
"tags": [
{
"key": "StratusRedTeam",
"value": "true"
},
{
"key": "Name",
"value": "stratus-red-team-ec2-steal-credentials-vpc"
}
]
}
]
}
},
"responseElements": {
"internetGateway": {
"association": {},
"attachmentSet": {},
"internetGatewayId": "igw-02a84e4222d62e16b",
"ownerId": "123837392027",
"tagSet": {
"items": [
{
"key": "StratusRedTeam",
"value": "true"
},
{
"key": "Name",
"value": "stratus-red-team-ec2-steal-credentials-vpc"
}
]
}
},
"requestId": "b23138bd-d869-4268-8c79-df643cafc60e"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1562, T1562.007↳ also matches CreateNetworkAclEntry, CreateRouteTable, CreateNatGateway Panther #
T1562↳ also matches AttachInternetGateway, CreateCustomerGateway, DeleteCustomerGateway, DeleteInternetGateway, DetachInternetGateway
References #
CreateInterruptibleCapacityReservationAllocation
#Description
Creates an interruptible Capacity Reservation by specifying the number of unused instances you want to allocate from your source reservation.
CreateIpam
#Description
Create an IPAM.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "5bf80a39-8c10-402c-9b59-2aabbb1944b8",
"eventName": "CreateIpam",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:40:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1ffa677c-4ffa-4db4-aa2b-2c85d472089d",
"requestParameters": {
"CreateIpamRequest": {
"ClientToken": "a24c7535-db37-4724-8eb3-36a19933a582",
"Description": "dwfix-ec2-d393e412 ipam",
"OperatingRegion": {
"RegionName": "us-west-1",
"tag": 1
},
"TagSpecification": {
"ResourceType": "ipam",
"Tag": [
{
"Key": "Name",
"Value": "dwfix-ec2-d393e412",
"tag": 1
},
{
"Key": "dwfix",
"Value": "1",
"tag": 2
}
],
"tag": 1
}
}
},
"responseElements": {
"CreateIpamResponse": {
"ipam": {
"defaultResourceDiscoveryAssociationId": "ipam-res-disco-assoc-07136081da90123d9",
"defaultResourceDiscoveryId": "ipam-res-disco-0ee5af4d14e72767e",
"description": "dwfix-ec2-d393e412 ipam",
"enablePrivateGua": false,
"ipamArn": "arn:aws:ec2::123456789012:ipam/ipam-081be5e3bac006e10",
"ipamId": "ipam-081be5e3bac006e10",
"ipamRegion": "us-west-1",
"meteredAccount": "ipam-owner",
"operatingRegionSet": {
"item": {
"regionName": "us-west-1"
}
},
"ownerId": "123456789012",
"privateDefaultScopeId": "ipam-scope-08c25ba7a8986b987",
"publicDefaultScopeId": "ipam-scope-0fecdb0cfd16681d6",
"resourceDiscoveryAssociationCount": 1,
"scopeCount": 2,
"state": "create-in-progress",
"tagSet": {
"item": [
{
"key": "dwfix",
"value": "1"
},
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
}
]
},
"tier": "advanced"
},
"requestId": "1ffa677c-4ffa-4db4-aa2b-2c85d472089d",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateIpamExternalResourceVerificationToken
#Description
Create a verification token.
CreateIpamPolicy
#Description
Creates an IPAM policy.
CreateIpamPool
#Description
Create an IP address pool for Amazon VPC IP Address Manager (IPAM).
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "9a35e468-25dc-46a5-8533-c8ac93e6cfe2",
"eventName": "CreateIpamPool",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:47:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "33c10310-d282-4ccf-b7b7-e28ebbe348f6",
"requestParameters": {
"CreateIpamPoolRequest": {
"AddressFamily": "ipv4",
"ClientToken": "1b57fc37-a8be-404e-81a5-78bdf9617b30",
"Description": "dwfix-ec2-d393e412 ipam pool",
"IpamScopeId": "ipam-scope-08c25ba7a8986b987",
"Locale": "us-west-1",
"TagSpecification": {
"ResourceType": "ipam-pool",
"Tag": [
{
"Key": "Name",
"Value": "dwfix-ec2-d393e412",
"tag": 1
},
{
"Key": "dwfix",
"Value": "1",
"tag": 2
}
],
"tag": 1
}
}
},
"responseElements": {
"CreateIpamPoolResponse": {
"ipamPool": {
"addressFamily": "ipv4",
"autoImport": false,
"description": "dwfix-ec2-d393e412 ipam pool",
"ipamArn": "arn:aws:ec2::123456789012:ipam/ipam-081be5e3bac006e10",
"ipamPoolArn": "arn:aws:ec2::123456789012:ipam-pool/ipam-pool-0b5795c40ef5b6d99",
"ipamPoolId": "ipam-pool-0b5795c40ef5b6d99",
"ipamRegion": "us-west-1",
"ipamScopeArn": "arn:aws:ec2::123456789012:ipam-scope/ipam-scope-08c25ba7a8986b987",
"ipamScopeType": "private",
"locale": "us-west-1",
"ownerId": "123456789012",
"poolDepth": 1,
"state": "create-in-progress",
"tagSet": {
"item": [
{
"key": "dwfix",
"value": "1"
},
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
}
]
}
},
"requestId": "33c10310-d282-4ccf-b7b7-e28ebbe348f6",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateIpamPrefixListResolver
#Description
Creates an IPAM prefix list resolver.
CreateIpamPrefixListResolverTarget
#Description
Creates an IPAM prefix list resolver target.
CreateIpamResourceDiscovery
#Description
Creates an IPAM resource discovery.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.ResourceLimitExceeded",
"errorMessage": "You've reached the limit for resource discoveries. You have created 1 resource discoveries, and you are limited to 1.",
"eventCategory": "Management",
"eventID": "00f11cf2-f2af-4294-ac05-bd2098214b8b",
"eventName": "CreateIpamResourceDiscovery",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:48:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b09571e8-4a2d-480a-9961-9f7c8699265a",
"requestParameters": {
"CreateIpamResourceDiscoveryRequest": {
"ClientToken": "865ec5a5-e33a-4b6d-bbe9-f74dc9b41eca",
"Description": "dwfix-ec2-d393e412 ipam-rd",
"OperatingRegion": {
"RegionName": "us-west-1",
"tag": 1
},
"TagSpecification": {
"ResourceType": "ipam-resource-discovery",
"Tag": [
{
"Key": "Name",
"Value": "dwfix-ec2-d393e412",
"tag": 1
},
{
"Key": "dwfix",
"Value": "1",
"tag": 2
}
],
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateIpamScope
#Description
Create an IPAM scope.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f7753d35-9267-4860-aa16-e792fd6bc7ca",
"eventName": "CreateIpamScope",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:47:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5ef1f200-f2fb-4405-a61e-6302e766b484",
"requestParameters": {
"CreateIpamScopeRequest": {
"ClientToken": "0ab45157-3186-46d0-afd2-1e2a754a50fb",
"Description": "dwfix-ec2-d393e412 ipam scope",
"IpamId": "ipam-081be5e3bac006e10",
"TagSpecification": {
"ResourceType": "ipam-scope",
"Tag": [
{
"Key": "Name",
"Value": "dwfix-ec2-d393e412",
"tag": 1
},
{
"Key": "dwfix",
"Value": "1",
"tag": 2
}
],
"tag": 1
}
}
},
"responseElements": {
"CreateIpamScopeResponse": {
"ipamScope": {
"description": "dwfix-ec2-d393e412 ipam scope",
"ipamArn": "arn:aws:ec2::123456789012:ipam/ipam-081be5e3bac006e10",
"ipamRegion": "us-west-1",
"ipamScopeArn": "arn:aws:ec2::123456789012:ipam-scope/ipam-scope-047dd4ad39a6ae5a6",
"ipamScopeId": "ipam-scope-047dd4ad39a6ae5a6",
"ipamScopeType": "private",
"isDefault": false,
"ownerId": "123456789012",
"poolCount": 0,
"state": "create-in-progress",
"tagSet": {
"item": [
{
"key": "dwfix",
"value": "1"
},
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
}
]
}
},
"requestId": "5ef1f200-f2fb-4405-a61e-6302e766b484",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateLaunchTemplate
#Description
Creates a launch template.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f1066d2a-8172-49dd-904a-b4d3050cbc6a",
"eventName": "CreateLaunchTemplate",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:59:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "863e9eae-8d8d-405f-a6a7-e312043b9d6b",
"requestParameters": {
"CreateLaunchTemplateRequest": {
"ClientToken": "4f9a8b07-d3eb-4d23-a1b9-0786357dc185",
"LaunchTemplateData": {
"ImageId": "ami-03993477bf043c1d1",
"InstanceType": "t3.micro"
},
"LaunchTemplateName": "dwfix-lt"
}
},
"responseElements": {
"CreateLaunchTemplateResponse": {
"launchTemplate": {
"createTime": "2026-06-29T19:59:23.000Z",
"createdBy": "arn:aws:iam::123456789012:user/sample-user",
"defaultVersionNumber": 1,
"latestVersionNumber": 1,
"launchTemplateId": "lt-0e15e74d047fa83a3",
"launchTemplateName": "dwfix-lt",
"operator": {
"managed": false
}
},
"requestId": "863e9eae-8d8d-405f-a6a7-e312043b9d6b",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1059↳ also matches ModifyInstanceAttribute
CreateLaunchTemplateVersion
#Description
Creates a new version of a launch template.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "1004fdd3-503d-4248-bd65-27d346bb776c",
"eventName": "CreateLaunchTemplateVersion",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:59:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "cb1ba550-8485-42a2-ae90-00e114e99a80",
"requestParameters": {
"CreateLaunchTemplateVersionRequest": {
"ClientToken": "a26975ae-f502-480f-8e7d-f22cb2af8df3",
"LaunchTemplateData": {
"ImageId": "ami-03993477bf043c1d1",
"InstanceType": "t3.small"
},
"LaunchTemplateId": "lt-0e15e74d047fa83a3"
}
},
"responseElements": {
"CreateLaunchTemplateVersionResponse": {
"launchTemplateVersion": {
"createTime": "2026-06-29T19:59:23.000Z",
"createdBy": "arn:aws:iam::123456789012:user/sample-user",
"defaultVersion": false,
"launchTemplateData": {
"imageId": "ami-03993477bf043c1d1",
"instanceType": "t3.small"
},
"launchTemplateId": "lt-0e15e74d047fa83a3",
"launchTemplateName": "dwfix-lt",
"operator": {
"managed": false
},
"versionNumber": 2
},
"requestId": "cb1ba550-8485-42a2-ae90-00e114e99a80",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateLocalGatewayRoute
#Description
Creates a static route for the specified local gateway route table.
CreateLocalGatewayRouteTable
#Description
Creates a local gateway route table.
CreateLocalGatewayRouteTableVirtualInterfaceGroupAssociation
#Description
Creates a local gateway route table virtual interface group association.
CreateLocalGatewayRouteTableVpcAssociation
#Description
Associates the specified VPC with the specified local gateway route table.
CreateLocalGatewayVirtualInterface
#Description
Create a virtual interface for a local gateway.
CreateLocalGatewayVirtualInterfaceGroup
#Description
Create a local gateway virtual interface group.
CreateMacSystemIntegrityProtectionModificationTask
#Description
Creates a System Integrity Protection (SIP) modification task to configure the SIP settings for an x86 Mac instance or Apple silicon Mac instance.
CreateManagedPrefixList
#Description
Creates a managed prefix list.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f2e15dfc-25dd-46d2-b229-b8da2c2bbd80",
"eventName": "CreateManagedPrefixList",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:40:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "927fa68a-ad07-4eb0-8bfe-2e78558c1310",
"requestParameters": {
"CreateManagedPrefixListRequest": {
"AddressFamily": "IPv4",
"ClientToken": "63f50d0c-fb85-4727-8be6-8a142b25aeaa",
"MaxEntries": 10,
"PrefixListName": "dwfix-ec2-d393e412-pl",
"TagSpecification": {
"ResourceType": "prefix-list",
"Tag": [
{
"Key": "Name",
"Value": "dwfix-ec2-d393e412",
"tag": 1
},
{
"Key": "dwfix",
"Value": "1",
"tag": 2
}
],
"tag": 1
}
}
},
"responseElements": {
"CreateManagedPrefixListResponse": {
"prefixList": {
"addressFamily": "IPv4",
"maxEntries": 10,
"ownerId": "123456789012",
"prefixListArn": "arn:aws:ec2:us-west-1:123456789012:prefix-list/pl-0019d1157c40d82a7",
"prefixListId": "pl-0019d1157c40d82a7",
"prefixListName": "dwfix-ec2-d393e412-pl",
"state": "create-in-progress",
"tagSet": {
"item": [
{
"key": "dwfix",
"value": "1"
},
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
}
]
},
"version": 1
},
"requestId": "927fa68a-ad07-4eb0-8bfe-2e78558c1310",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateNatGateway
#Description
Creates a NAT gateway in the specified subnet.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "dbb3b16e-549e-48bc-bfa6-9ca4c2845e43",
"eventName": "CreateNatGateway",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "98cac787-9654-4d84-9fbc-d42f1023e2ef",
"requestParameters": {
"CreateNatGatewayRequest": {
"AllocationId": "eipalloc-08a083beb7e83dbc0",
"ClientToken": "86C58940-D407-4E02-A617-E40168CFDBE2",
"ConnectivityType": "public",
"SubnetId": "subnet-01ed430875cff578d",
"TagSpecification": {
"ResourceType": "natgateway",
"Tag": [
{
"Key": "StratusRedTeam",
"Value": true,
"tag": 1
},
{
"Key": "Name",
"Value": "stratus-red-team-ec2-steal-credentials-vpc-us-east-1a",
"tag": 2
}
],
"tag": 1
}
}
},
"responseElements": {
"CreateNatGatewayResponse": {
"clientToken": "86C58940-D407-4E02-A617-E40168CFDBE2",
"natGateway": {
"connectivityType": "public",
"createTime": "2023-07-10T11:55:14.000Z",
"natGatewayAddressSet": {
"item": {
"allocationId": "eipalloc-08a083beb7e83dbc0",
"isPrimary": true,
"status": "associating"
}
},
"natGatewayId": "nat-03575abbac42080d9",
"state": "pending",
"subnetId": "subnet-01ed430875cff578d",
"tagSet": {
"item": [
{
"key": "StratusRedTeam",
"value": true
},
{
"key": "Name",
"value": "stratus-red-team-ec2-steal-credentials-vpc-us-east-1a"
}
]
},
"vpcId": "vpc-06fe1a64761a0f720"
},
"requestId": "98cac787-9654-4d84-9fbc-d42f1023e2ef",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1078, T1562, T1562.007↳ also matches CreateNetworkAclEntry, CreateRouteTable, CreateInternetGateway
References #
CreateNetworkInsightsAccessScope
#Description
Creates a Network Access Scope.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "466a2f94-e5ce-40b5-a3dc-5547058d2996",
"eventName": "CreateNetworkInsightsAccessScope",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:46:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "db54f42f-6ea7-4bbc-8d51-b4cb8ebcc69e",
"requestParameters": {
"CreateNetworkInsightsAccessScopeRequest": {
"ClientToken": "d255bb82175f43959388c5b8c00843a1",
"TagSpecification": {
"ResourceType": "network-insights-access-scope",
"Tag": [
{
"Key": "Name",
"Value": "dwfix-ec2-d393e412",
"tag": 1
},
{
"Key": "dwfix",
"Value": "1",
"tag": 2
}
],
"tag": 1
}
}
},
"responseElements": {
"CreateNetworkInsightsAccessScopeResponse": {
"networkInsightsAccessScope": {
"createdDate": "2026-06-29T22:46:01.733Z",
"networkInsightsAccessScopeArn": "arn:aws:ec2:us-west-1:123456789012:network-insights-access-scope/nis-09c07334f0c179e68",
"networkInsightsAccessScopeId": "nis-09c07334f0c179e68",
"tagSet": {
"item": [
{
"key": "dwfix",
"value": "1"
},
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
}
]
},
"updatedDate": "2026-06-29T22:46:01.733Z"
},
"networkInsightsAccessScopeContent": {
"networkInsightsAccessScopeId": "nis-09c07334f0c179e68"
},
"requestId": "db54f42f-6ea7-4bbc-8d51-b4cb8ebcc69e",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateNetworkInsightsPath
#Description
Creates a path to analyze for reachability.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "7776d5d7-09ca-4a15-9bd8-3a04760cc839",
"eventName": "CreateNetworkInsightsPath",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:46:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "97fdb5aa-7f0f-4803-bcf9-26a397fb4608",
"requestParameters": {
"CreateNetworkInsightsPathRequest": {
"ClientToken": "a6e2f3dc7cc94e47bb114cc18c6209a9",
"Destination": "igw-03d64a9d751ff8ddf",
"Protocol": "tcp",
"Source": "i-0a4c8f9124bcc1a50",
"TagSpecification": {
"ResourceType": "network-insights-path",
"Tag": [
{
"Key": "Name",
"Value": "dwfix-ec2-d393e412",
"tag": 1
},
{
"Key": "dwfix",
"Value": "1",
"tag": 2
}
],
"tag": 1
}
}
},
"responseElements": {
"CreateNetworkInsightsPathResponse": {
"networkInsightsPath": {
"createdDate": "2026-06-29T22:46:00.276Z",
"destination": "igw-03d64a9d751ff8ddf",
"destinationArn": "arn:aws:ec2:us-west-1:123456789012:internet-gateway/igw-03d64a9d751ff8ddf",
"networkInsightsPathArn": "arn:aws:ec2:us-west-1:123456789012:network-insights-path/nip-01e67beb8a4227dca",
"networkInsightsPathId": "nip-01e67beb8a4227dca",
"protocol": "tcp",
"source": "i-0a4c8f9124bcc1a50",
"sourceArn": "arn:aws:ec2:us-west-1:123456789012:instance/i-0a4c8f9124bcc1a50",
"tagSet": {
"item": [
{
"key": "dwfix",
"value": "1"
},
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
}
]
}
},
"requestId": "97fdb5aa-7f0f-4803-bcf9-26a397fb4608",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateNetworkInterface
#Description
Creates a network interface in the specified subnet.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "16034e79-0235-4886-9566-19d4a4ca1d72",
"eventName": "CreateNetworkInterface",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "18b3084b-7025-4894-aa0c-8a9e953e4038",
"requestParameters": {
"clientToken": "C265B64D-B8B2-4C8F-912B-A346F34FC63A",
"groupSet": {},
"privateIpAddressesSet": {
"items": [
{
"primary": true,
"privateIpAddress": "10.0.1.10"
}
]
},
"subnetId": "subnet-0ed352584ab4aa265",
"tagSpecificationSet": {
"items": [
{
"resourceType": "network-interface",
"tags": [
{
"key": "StratusRedTeam",
"value": "true"
}
]
}
]
}
},
"responseElements": {
"networkInterface": {
"availabilityZone": "us-east-1a",
"groupSet": {
"items": [
{
"groupId": "sg-0b233157065b7d5e2",
"groupName": "default"
}
]
},
"interfaceType": "interface",
"ipv6AddressesSet": {},
"macAddress": "12:c4:b6:95:a1:71",
"networkInterfaceId": "eni-076fa9fb98a2500a7",
"ownerId": "123837392027",
"privateIpAddress": "10.0.1.10",
"privateIpAddressesSet": {
"item": [
{
"primary": true,
"privateIpAddress": "10.0.1.10"
}
]
},
"requesterId": "AIDATFQR7NSC5AU2ZV3IE",
"requesterManaged": false,
"sourceDestCheck": true,
"status": "pending",
"subnetId": "subnet-0ed352584ab4aa265",
"tagSet": {
"items": [
{
"key": "StratusRedTeam",
"value": "true"
}
]
},
"vpcId": "vpc-06fe1a64761a0f720"
},
"requestId": "18b3084b-7025-4894-aa0c-8a9e953e4038"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
CreateNetworkInterfacePermission
#Description
Grants an Amazon Web Services-authorized account permission to attach the specified network interface to an instance in their account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.OperationNotPermitted",
"errorMessage": "Permissions given to AWS service principals are not currently supported.",
"eventCategory": "Management",
"eventID": "cc778ae5-8640-4612-a5e5-22c1199d9578",
"eventName": "CreateNetworkInterfacePermission",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:45:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "bf0ff06a-5e66-4c34-a7c4-32e0d8419373",
"requestParameters": {
"CreateNetworkInterfacePermissionRequest": {
"AwsService": "ec2.amazonaws.com",
"NetworkInterfaceId": "eni-025f9aaa17cd9ff32",
"Permission": "EIP-ASSOCIATE"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreatePlacementGroup
#Description
Creates a placement group that you launch cluster instances into.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "bdf8bedf-4132-4d90-a5b4-68505c7bd1b9",
"eventName": "CreatePlacementGroup",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:40:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "836d68e1-c05b-458d-a56c-b46556b54a25",
"requestParameters": {
"groupName": "dwfix-ec2-d393e412-pg",
"strategy": "spread",
"tagSpecificationSet": {
"items": [
{
"resourceType": "placement-group",
"tags": [
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
},
{
"key": "dwfix",
"value": "1"
}
]
}
]
}
},
"responseElements": {
"_return": true,
"placementGroup": {
"groupArn": "arn:aws:ec2:us-west-1:123456789012:placement-group/dwfix-ec2-d393e412-pg",
"groupId": "pg-090818db2c412fcc8",
"groupName": "dwfix-ec2-d393e412-pg",
"spreadLevel": "rack",
"state": "available",
"strategy": "spread",
"tagSet": {
"items": [
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
},
{
"key": "dwfix",
"value": "1"
}
]
}
},
"requestId": "836d68e1-c05b-458d-a56c-b46556b54a25"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreatePublicIpv4Pool
#Description
Creates a public IPv4 address pool.
CreateReplaceRootVolumeTask
#Description
Replaces the EBS-backed root volume for a running instance with a new volume that is restored to the original root volume's launch state, that is restored to a specific snapshot taken from the original root volume, or that is restored from.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.IncorrectInstanceState",
"errorMessage": "Instance is not in the running state.",
"eventCategory": "Management",
"eventID": "866d7dec-28b2-4503-9cf3-b495b33e85c2",
"eventName": "CreateReplaceRootVolumeTask",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:45:36Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "661f2327-39b6-4af1-8064-905a4a746ccc",
"requestParameters": {
"CreateReplaceRootVolumeTaskRequest": {
"ClientToken": "4e73636f-6dbe-4e2b-8881-2df7650bc482",
"DeleteReplacedRootVolume": false,
"InstanceId": "i-0a4c8f9124bcc1a50",
"SnapshotId": "snap-0ae577a47e091fcaa"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateReservedInstancesListing
#Description
Creates a listing for Amazon EC2 Reserved Instances to be sold in the Reserved Instance Marketplace.
CreateRestoreImageTask
#Description
Starts a task that restores an AMI from an Amazon S3 object that was previously created by using CreateStoreImageTask.
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aws::errorCode (panther rule field) | ne | Client.DryRunOperation | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1204↳ also matches CreateStoreImageTask, CopyFpgaImage, CopyImage, CreateFpgaImage, CreateImage, ImportImage
CreateRouteServer
#Description
Creates a new route server to manage dynamic routing in a VPC.
CreateRouteServerEndpoint
#Description
Creates a new endpoint for a route server in a specified subnet.
CreateRouteServerPeer
#Description
Creates a new BGP peer for a specified route server endpoint.
CreateSecondaryNetwork
#Description
Creates a secondary network.
CreateSecondarySubnet
#Description
Creates a secondary subnet in a secondary network.
CreateSnapshot
#Description
Creates a snapshot of an Amazon EBS volume and stores it in Amazon S3.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "9eede385-5c6d-405e-9dda-fd10950e9069",
"eventName": "CreateSnapshot",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:11:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "d0778782-df1d-4eb6-91da-edbefb7e7db1",
"requestParameters": {
"tagSpecificationSet": {
"items": [
{
"resourceType": "snapshot",
"tags": [
{
"key": "StratusRedTeam",
"value": "true"
}
]
}
]
},
"volumeId": "vol-0fc2e34e74650e145"
},
"responseElements": {
"encrypted": false,
"ownerId": "123837392027",
"requestId": "d0778782-df1d-4eb6-91da-edbefb7e7db1",
"snapshotId": "snap-083d3b857c13988bc",
"startTime": 1688991086923,
"status": "pending",
"tagSet": {
"items": [
{
"key": "StratusRedTeam",
"value": "true"
}
]
},
"volumeId": "vol-0fc2e34e74650e145",
"volumeSize": "1"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_36659dd6-3cf5-4369-ae72-21be4cb11547 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
CreateSnapshots
#Description
Creates crash-consistent snapshots of multiple EBS volumes attached to an Amazon EC2 instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "468d0921-004a-4b5e-863b-d6b41cf35476",
"eventName": "CreateSnapshots",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:42:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "42ad60be-7fbd-4a37-8994-aaf739ed1f84",
"requestParameters": {
"CreateSnapshotsRequest": {
"Description": "dwfix-ec2-d393e412 multi-snap",
"InstanceSpecification": {
"ExcludeBootVolume": false,
"InstanceId": "i-0a4c8f9124bcc1a50"
},
"TagSpecification": {
"ResourceType": "snapshot",
"Tag": [
{
"Key": "Name",
"Value": "dwfix-ec2-d393e412",
"tag": 1
},
{
"Key": "dwfix",
"Value": "1",
"tag": 2
}
],
"tag": 1
}
}
},
"responseElements": {
"CreateSnapshotsResponse": {
"requestId": "42ad60be-7fbd-4a37-8994-aaf739ed1f84",
"snapshotSet": {
"item": {
"description": "dwfix-ec2-d393e412 multi-snap",
"encrypted": false,
"ownerId": "123456789012",
"progress": "",
"snapshotId": "snap-059f701cce7160c5e",
"startTime": "2026-06-29T22:42:02.839Z",
"state": "pending",
"tagSet": {
"item": [
{
"key": "dwfix",
"value": "1"
},
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
}
]
},
"volumeId": "vol-08f7e4b919b04f996",
"volumeSize": 8
}
},
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateSpotDatafeedSubscription
#Description
Creates a datafeed for Spot Instances, enabling you to view Spot Instance usage logs.
CreateSubnet
#Description
Creates a subnet in an existing VPC.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "078ad2dc-a2bf-46ee-90dc-f524fb5fe1f1",
"eventName": "CreateSubnet",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "8dd15b1c-a6bc-4c98-9299-a3554bac2203",
"requestParameters": {
"availabilityZone": "us-east-1a",
"cidrBlock": "10.0.128.0/24",
"tagSpecificationSet": {
"items": [
{
"resourceType": "subnet",
"tags": [
{
"key": "Name",
"value": "stratus-red-team-ec2-steal-credentials-vpc-public-us-east-1a"
},
{
"key": "StratusRedTeam",
"value": "true"
}
]
}
]
},
"vpcId": "vpc-06fe1a64761a0f720"
},
"responseElements": {
"requestId": "8dd15b1c-a6bc-4c98-9299-a3554bac2203",
"subnet": {
"assignIpv6AddressOnCreation": false,
"availabilityZone": "us-east-1a",
"availabilityZoneId": "use1-az2",
"availableIpAddressCount": 251,
"cidrBlock": "10.0.128.0/24",
"defaultForAz": false,
"enableDns64": false,
"ipv6CidrBlockAssociationSet": {},
"ipv6Native": false,
"mapPublicIpOnLaunch": false,
"ownerId": "123837392027",
"privateDnsNameOptionsOnLaunch": {
"enableResourceNameDnsAAAARecord": false,
"enableResourceNameDnsARecord": false,
"hostnameType": "ip-name"
},
"state": "available",
"subnetArn": "arn:aws:ec2:us-east-1:123837392027:subnet/subnet-01ed430875cff578d",
"subnetId": "subnet-01ed430875cff578d",
"tagSet": {
"items": [
{
"key": "Name",
"value": "stratus-red-team-ec2-steal-credentials-vpc-public-us-east-1a"
},
{
"key": "StratusRedTeam",
"value": "true"
}
]
},
"vpcId": "vpc-06fe1a64761a0f720"
}
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
CreateSubnetCidrReservation
#Description
Creates a subnet CIDR reservation.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "c0e6f60b-664a-4d07-97a8-542b7dab1d5d",
"eventName": "CreateSubnetCidrReservation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:48:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ebca3a22-d790-4d34-b973-8761c1c01e25",
"requestParameters": {
"CreateSubnetCidrReservationRequest": {
"Cidr": "10.0.1.0/28",
"Description": "dwfix test reservation",
"ReservationType": "prefix",
"SubnetId": "subnet-00c955600d8a2bf71"
}
},
"responseElements": {
"CreateSubnetCidrReservationResponse": {
"requestId": "ebca3a22-d790-4d34-b973-8761c1c01e25",
"subnetCidrReservation": {
"cidr": "10.0.1.0/28",
"description": "dwfix test reservation",
"ownerId": "123456789012",
"reservationType": "prefix",
"subnetCidrReservationId": "scr-058adb7c0eca14d57",
"subnetId": "subnet-00c955600d8a2bf71"
},
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateTrafficMirrorFilter
#Description
Creates a Traffic Mirror filter.
Example CloudTrail Event #
{
"awsRegion": "ap-southeast-2",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation. Encoded authorization failure message: QAyRWNFkfMIXJa_Z24XhmlxaYZfvxYqlVBS7f6lWOZIOhyRfSdy9oqmg-PRqb7hOeN3Wmg7L0SETVhj0qShMzpfbJNjvTwSLHyrzh8ma_L0nm1AExsRAVs5KC8aLabBpyO8aWLdSUgLZMTo5ckefoM5kAoaKDnYv758JTgBxQGbQacHC2xDEPfKRy5v9IZggKlhrR3oX7avehXY9ke3Rc0cIiscEM5arn3Gpk6yOserJnrI-DfP9lREj0zvEbK_mn4wLw93gzOVa3JJ-X2Dau2TATmRr3cBCoW3yTvJU_QuMaxloOa6h7HdDL2TXRQsgN5Y3LVVskKwXQGCk2C_ssnLALYalTg7IkLrZLS7hfW6lm7Fpd7FyIlU5LuZC_iiRkcKtz2eIcx6-LgLALH4xxY1nrgeMmgxaIBypSIO_ib1-WLImy4Bd-Bj8Q58ffnR1f1UNKrZNI3ekGii36rVT5d2HwglTKgSQ6KwruHULtep80BcjX2kKF3woTigha6GY_7GTQobvmmCWH-1aPIDuw3B2K9H506aQ",
"eventID": "2997ff89-8331-4c0c-b3bf-780bd5d0decf",
"eventName": "CreateTrafficMirrorFilter",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-04-10T14:58:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "9e2b8810-68ba-4998-b4e1-cfb9dfd3ea30",
"requestParameters": {
"CreateTrafficMirrorFilterRequest": {
"ClientToken": "8d622c29-fadf-47f0-b71b-b0404d4c48ff"
}
},
"responseElements": null,
"sourceIPAddress": "255.171.1.252",
"userAgent": "aws-cli/1.18.31 Python/3.8.2 Linux/4.9.184-linuxkit botocore/1.15.31",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1040↳ also matches CreateTrafficMirrorSession, CreateTrafficMirrorFilterRule, CreateTrafficMirrorTarget, DeleteTrafficMirrorFilter, DeleteTrafficMirrorFilterRule, DeleteTrafficMirrorSession, and 4 more
References #
CreateTrafficMirrorFilterRule
#Description
Creates a Traffic Mirror filter rule.
Example CloudTrail Event #
{
"eventVersion": "1.11",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE"
},
"eventTime": "2026-07-28T20:58:56Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "CreateTrafficMirrorFilterRule",
"awsRegion": "us-west-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#ec2.create-traffic-mirror-filter-rule",
"requestParameters": {
"CreateTrafficMirrorFilterRuleRequest": {
"RuleAction": "accept",
"SourceCidrBlock": "198.51.100.0/24",
"RuleNumber": 100,
"DestinationCidrBlock": "203.0.113.0/24",
"ClientToken": "a44f4b7e-ea82-4b9e-8c4d-e15c91f1cc93",
"Protocol": 6,
"TrafficDirection": "ingress",
"TrafficMirrorFilterId": "tmf-0dab8854170a7a4ad"
}
},
"responseElements": {
"CreateTrafficMirrorFilterRuleResponse": {
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/",
"requestId": "0522e94a-cb54-410e-b355-3e0bb19f14ab",
"clientToken": "a44f4b7e-ea82-4b9e-8c4d-e15c91f1cc93",
"trafficMirrorFilterRule": {
"destinationCidrBlock": "203.0.113.0/24",
"ruleAction": "accept",
"protocol": 6,
"ruleNumber": 100,
"sourceCidrBlock": "198.51.100.0/24",
"trafficDirection": "ingress",
"trafficMirrorFilterId": "tmf-0dab8854170a7a4ad",
"trafficMirrorFilterRuleId": "tmfr-00f1c5b47fd53fadf"
}
}
},
"requestID": "0522e94a-cb54-410e-b355-3e0bb19f14ab",
"eventID": "46bd9e8a-bf11-4a87-93cb-7efb942e31b6",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1040↳ also matches CreateTrafficMirrorSession, CreateTrafficMirrorFilter, CreateTrafficMirrorTarget, DeleteTrafficMirrorFilter, DeleteTrafficMirrorFilterRule, DeleteTrafficMirrorSession, and 4 more
CreateTrafficMirrorTarget
#Description
Creates a target for your Traffic Mirror session.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation. User: arn:aws:iam::123456789012:user/TrailDiscover is not authorized to perform: ec2:CreateTrafficMirrorTarget on resource: arn:aws:ec2:us-east-1:192374575148:network-interface/* because no identity-based policy allows the ec2:CreateTrafficMirrorTarget action. Encoded authorization failure message: H7q_Ce16dv2QHxzQQzWtKzMHnAfDdtrbGBaK1JPNY7BDyRralS5VrS04LZPDVb00qAeL-9LICwyTGNPnw6WMLNLhI6xelM2dVEXvhM9cBriIgvBfJgffxMSUQbN3e-lXfdmm7407CsCQ_xBhbUT3Or1BcCESaOLKm7XSSl3-RrYsNXgjF8f4hTqTh8zfi8fviy6VOAtJbjV7Ol73ZxK7PGq30qZVaL4utsysXubvuIBv961D34obWDqElsnct4PF5LfiK-rZmmJBhWHFYpke9k8R2-w-WtgYOzw9VJAoO4OfnyDOeK4skZR8OiHAe-k60PRDMB9SUUU-l0l8GIz3BaXxzvU4QmEDrCU9om8vEo8h7pvKlhs9n5zXql1QsGL7PLclgKob5QD1MWmHwWe9sauKKhezc3Qe_naoQMO6tRqV4vQqkFLjkjdCmDxN5NVnYrZ8lUD2_YFb5gU5Ke7RGEqSi10RKB1gWZvuI0aBvxym26OBjHz6Oh2OuJ7rKUo4gpzFf-uaKbdnPHXzG6atD3W-BXvUNnDTffEjwEn_sg",
"eventCategory": "Management",
"eventID": "db312c37-74a0-46c7-a801-5e6da8c4d34d",
"eventName": "CreateTrafficMirrorTarget",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2024-08-18T14:09:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.09",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "700e210b-b6ba-4968-8309-90f0ac13eef4",
"requestParameters": {
"CreateTrafficMirrorTargetRequest": {
"ClientToken": "1b22a7ef-cced-4535-9ebc-cdd46913c976",
"Description": "TrailDiscoverDescription",
"NetworkInterfaceId": "TrailDiscoverNetworkInterfaceId",
"NetworkLoadBalancerArn": "TrailDiscoverNetworkLoadBalancerArn"
}
},
"responseElements": null,
"sourceIPAddress": "0.0.0.0",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "aws-cli/2.17.32 md/awscrt#0.21.2 ua/2.0 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.11.9 md/pyimpl#CPython exec-env/grimoire_fbb74a09-3b31-4160-bdc2-a680f206a0a8 cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#ec2.create-traffic-mirror-target",
"userIdentity": {
"accessKeyId": "AKIA****************",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/TrailDiscover",
"principalId": "AROA****************:User",
"type": "IAMUser",
"userName": "TrailDiscover"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1040↳ also matches CreateTrafficMirrorSession, CreateTrafficMirrorFilter, CreateTrafficMirrorFilterRule, DeleteTrafficMirrorFilter, DeleteTrafficMirrorFilterRule, DeleteTrafficMirrorSession, and 4 more
References #
CreateTransitGateway
#Description
Creates a transit gateway.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "9c89ee84-fb93-4cf0-aa29-83cc9e1ee8ac",
"eventName": "CreateTransitGateway",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:40:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "028b6061-42ca-43e5-b7d0-a70271d7c7b5",
"requestParameters": {
"CreateTransitGatewayRequest": {
"Description": "dwfix-ec2-d393e412 tgw",
"Options": {
"AutoAcceptSharedAttachments": "disable",
"DefaultRouteTableAssociation": "disable",
"DefaultRouteTablePropagation": "disable"
},
"TagSpecification": {
"ResourceType": "transit-gateway",
"Tag": [
{
"Key": "Name",
"Value": "dwfix-ec2-d393e412",
"tag": 1
},
{
"Key": "dwfix",
"Value": "1",
"tag": 2
}
],
"tag": 1
}
}
},
"responseElements": {
"CreateTransitGatewayResponse": {
"requestId": "028b6061-42ca-43e5-b7d0-a70271d7c7b5",
"transitGateway": {
"creationTime": "2026-06-29T22:40:01.000Z",
"description": "dwfix-ec2-d393e412 tgw",
"options": {
"amazonSideAsn": 64512,
"autoAcceptSharedAttachments": "disable",
"defaultRouteTableAssociation": "disable",
"defaultRouteTablePropagation": "disable",
"dnsSupport": "enable",
"encryptionSupport": {
"encryptionState": "disabled"
},
"multicastSupport": "disable",
"securityGroupReferencingSupport": "disable",
"vpnEcmpSupport": "enable"
},
"ownerId": "123456789012",
"state": "pending",
"tagSet": {
"item": [
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
},
{
"key": "dwfix",
"value": "1"
}
]
},
"transitGatewayArn": "arn:aws:ec2:us-west-1:123456789012:transit-gateway/tgw-0109d0ce00ed6848b",
"transitGatewayId": "tgw-0109d0ce00ed6848b"
},
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateTransitGatewayConnect
#Description
Creates a Connect attachment from a specified transit gateway attachment.
CreateTransitGatewayConnectPeer
#Description
Creates a Connect peer for a specified transit gateway Connect attachment between a transit gateway and an appliance.
CreateTransitGatewayMeteringPolicy
#Description
Creates a metering policy for a transit gateway to track and measure network traffic.
CreateTransitGatewayMeteringPolicyEntry
#Description
Creates an entry in a transit gateway metering policy to define traffic measurement rules.
CreateTransitGatewayMulticastDomain
#Description
Creates a multicast domain using the specified transit gateway.
CreateTransitGatewayPeeringAttachment
#Description
Requests a transit gateway peering attachment between the specified transit gateway (requester) and a peer transit gateway (accepter).
CreateTransitGatewayPolicyTable
#Description
Creates a transit gateway policy table.
CreateTransitGatewayPrefixListReference
#Description
Creates a reference (route) to a prefix list in a specified transit gateway route table.
CreateTransitGatewayRoute
#Description
Creates a static route for the specified transit gateway route table.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.IncorrectState",
"errorMessage": "tgw-rtb-0f5c12c8b5c90a1a1 is in invalid state",
"eventCategory": "Management",
"eventID": "3859ff2f-dc45-4702-aeda-739c007f7822",
"eventName": "CreateTransitGatewayRoute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:46:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c3311431-a523-4db1-acfc-c749c44ad8f6",
"requestParameters": {
"CreateTransitGatewayRouteRequest": {
"Blackhole": true,
"DestinationCidrBlock": "192.168.100.0/24",
"TransitGatewayRouteTableId": "tgw-rtb-0f5c12c8b5c90a1a1"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateTransitGatewayRouteTable
#Description
Creates a route table for the specified transit gateway.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "ad0e524f-7e21-429f-b3c0-6fa9c80c8e81",
"eventName": "CreateTransitGatewayRouteTable",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:46:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5fb6adc5-d398-4d5d-9325-3f91f58cd374",
"requestParameters": {
"CreateTransitGatewayRouteTableRequest": {
"TagSpecifications": {
"ResourceType": "transit-gateway-route-table",
"Tag": [
{
"Key": "Name",
"Value": "dwfix-ec2-d393e412",
"tag": 1
},
{
"Key": "dwfix",
"Value": "1",
"tag": 2
}
],
"tag": 1
},
"TransitGatewayId": "tgw-0109d0ce00ed6848b"
}
},
"responseElements": {
"CreateTransitGatewayRouteTableResponse": {
"requestId": "5fb6adc5-d398-4d5d-9325-3f91f58cd374",
"transitGatewayRouteTable": {
"creationTime": "2026-06-29T22:46:11.000Z",
"defaultAssociationRouteTable": false,
"defaultPropagationRouteTable": false,
"state": "pending",
"tagSet": {
"item": [
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
},
{
"key": "dwfix",
"value": "1"
}
]
},
"transitGatewayId": "tgw-0109d0ce00ed6848b",
"transitGatewayRouteTableId": "tgw-rtb-0f5c12c8b5c90a1a1"
},
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateTransitGatewayRouteTableAnnouncement
#Description
Advertises a new transit gateway route table.
CreateTransitGatewayVpcAttachment
#Description
Attaches the specified VPC to the specified transit gateway.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "70bfbf53-83db-4d77-b13e-f9cdda3f170f",
"eventName": "CreateTransitGatewayVpcAttachment",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:46:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "58921e3d-d665-49f5-b365-b3cee323a697",
"requestParameters": {
"CreateTransitGatewayVpcAttachmentRequest": {
"SubnetIds": {
"content": "subnet-00c955600d8a2bf71",
"tag": 1
},
"TagSpecifications": {
"ResourceType": "transit-gateway-attachment",
"Tag": [
{
"Key": "Name",
"Value": "dwfix-ec2-d393e412",
"tag": 1
},
{
"Key": "dwfix",
"Value": "1",
"tag": 2
}
],
"tag": 1
},
"TransitGatewayId": "tgw-0109d0ce00ed6848b",
"VpcId": "vpc-00c0dad452596a616"
}
},
"responseElements": {
"CreateTransitGatewayVpcAttachmentResponse": {
"requestId": "58921e3d-d665-49f5-b365-b3cee323a697",
"transitGatewayVpcAttachment": {
"creationTime": "2026-06-29T22:46:12.000Z",
"options": {
"applianceModeSupport": "disable",
"dnsSupport": "enable",
"ipv6Support": "disable",
"securityGroupReferencingSupport": "enable"
},
"state": "pending",
"subnetIds": {
"item": "subnet-00c955600d8a2bf71"
},
"tagSet": {
"item": [
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
},
{
"key": "dwfix",
"value": "1"
}
]
},
"transitGatewayAttachmentId": "tgw-attach-08d8a09ccdcb3d355",
"transitGatewayId": "tgw-0109d0ce00ed6848b",
"vpcId": "vpc-00c0dad452596a616",
"vpcOwnerId": "123456789012"
},
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateVerifiedAccessEndpoint
#Description
An Amazon Web Services Verified Access endpoint is where you define your application along with an optional endpoint-level access policy.
CreateVerifiedAccessGroup
#Description
An Amazon Web Services Verified Access group is a collection of Amazon Web Services Verified Access endpoints who's associated applications have similar security requirements.
CreateVerifiedAccessInstance
#Description
An Amazon Web Services Verified Access instance is a regional entity that evaluates application requests and grants access only when your security requirements are met.
CreateVerifiedAccessTrustProvider
#Description
A trust provider is a third-party entity that creates, maintains, and manages identity information for users and devices.
CreateVolume
#Description
Creates an Amazon EBS volume that can be attached to an instance in the same Availability Zone.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "396f94bc-78ec-4b64-917d-aadc2260c81d",
"eventName": "CreateVolume",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:10:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "5b2c0b96-bec1-4a37-b6d8-3a4ac6c979c2",
"requestParameters": {
"clientToken": "7C289842-4CE2-47D0-8706-FBCE5D907C5E",
"size": "1",
"tagSpecificationSet": {
"items": [
{
"resourceType": "volume",
"tags": [
{
"key": "StratusRedTeam",
"value": "true"
},
{
"key": "Name",
"value": "stratus-red-team-share-ami-ami"
}
]
}
]
},
"zone": "us-east-1a"
},
"responseElements": {
"createTime": 1688991025000,
"encrypted": false,
"iops": 100,
"multiAttachEnabled": false,
"requestId": "5b2c0b96-bec1-4a37-b6d8-3a4ac6c979c2",
"size": "1",
"status": "creating",
"tagSet": {
"items": [
{
"key": "StratusRedTeam",
"value": "true"
},
{
"key": "Name",
"value": "stratus-red-team-share-ami-ami"
}
]
},
"volumeId": "vol-0a2e548958718390d",
"volumeType": "gp2",
"zone": "us-east-1a"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_b47d6b97-21d3-4b01-8937-6f0c23cb2d4b HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
CreateVpc
#Description
Creates a VPC with the specified CIDR block.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "f5e4b2d3-a4a2-4a78-b81f-9036f12b623e",
"eventName": "CreateVpc",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "227252b0-eb8a-4c29-810e-def37a9f3476",
"requestParameters": {
"amazonProvidedIpv6CidrBlock": false,
"cidrBlock": "10.0.0.0/16",
"instanceTenancy": "default",
"tagSpecificationSet": {
"items": [
{
"resourceType": "vpc",
"tags": [
{
"key": "Name",
"value": "stratus-red-team-ec2-steal-credentials-vpc"
},
{
"key": "StratusRedTeam",
"value": "true"
}
]
}
]
}
},
"responseElements": {
"requestId": "227252b0-eb8a-4c29-810e-def37a9f3476",
"vpc": {
"cidrBlock": "10.0.0.0/16",
"cidrBlockAssociationSet": {
"items": [
{
"associationId": "vpc-cidr-assoc-01a3c97bf2a2efa11",
"cidrBlock": "10.0.0.0/16",
"cidrBlockState": {
"state": "associated"
}
}
]
},
"dhcpOptionsId": "dopt-0ef51062810f8ca7b",
"instanceTenancy": "default",
"ipv6CidrBlockAssociationSet": {},
"isDefault": false,
"ownerId": "123837392027",
"state": "pending",
"tagSet": {
"items": [
{
"key": "Name",
"value": "stratus-red-team-ec2-steal-credentials-vpc"
},
{
"key": "StratusRedTeam",
"value": "true"
}
]
},
"vpcId": "vpc-06fe1a64761a0f720"
}
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches AcceptVpcPeeringConnection, AttachClassicLinkVpc, DeleteVpc, DetachClassicLinkVpc, DisableVpcClassicLink, EnableVpcClassicLink, ModifyVpcAttribute, RejectVpcPeeringConnection
References #
CreateVpcBlockPublicAccessExclusion
#Description
Create a VPC Block Public Access (BPA) exclusion.
CreateVpcEncryptionControl
#Description
Creates a VPC Encryption Control configuration for a specified VPC.
CreateVpcEndpoint
#Description
Creates a VPC endpoint for a specified AWS service.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "574e7b17-54aa-4874-8164-91000cc1ccce",
"eventName": "CreateVpcEndpoint",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:48:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4d8089f3-04a1-4492-aad0-d749c2eccb4f",
"requestParameters": {
"CreateVpcEndpointRequest": {
"RouteTableId": {
"content": "rtb-06b1ec38aa8ffb600",
"tag": 1
},
"ServiceName": "com.amazonaws.us-west-1.s3",
"TagSpecification": {
"ResourceType": "vpc-endpoint",
"Tag": [
{
"Key": "Name",
"Value": "dwfix-ec2-d393e412",
"tag": 1
},
{
"Key": "dwfix",
"Value": "1",
"tag": 2
}
],
"tag": 1
},
"VpcEndpointType": "Gateway",
"VpcId": "vpc-00c0dad452596a616"
}
},
"responseElements": {
"CreateVpcEndpointResponse": {
"requestId": "4d8089f3-04a1-4492-aad0-d749c2eccb4f",
"vpcEndpoint": {
"creationTimestamp": "2026-06-29T22:48:47.000Z",
"dnsEntrySet": "",
"dnsOptions": {
"dnsRecordIpType": "service-defined"
},
"groupSet": "",
"ipAddressType": "ipv4",
"networkInterfaceIdSet": "",
"ownerId": "123456789012",
"policyDocument": {
"Version": "2008-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": "*",
"Action": "*",
"Resource": "*"
}
]
},
"privateDnsEnabled": false,
"requesterManaged": false,
"routeTableIdSet": {
"item": "rtb-06b1ec38aa8ffb600"
},
"serviceName": "com.amazonaws.us-west-1.s3",
"state": "available",
"subnetIdSet": "",
"tagSet": {
"item": [
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
},
{
"key": "dwfix",
"value": "1"
}
]
},
"vpcEndpointId": "vpce-0699134642a5b2f4d",
"vpcEndpointType": "Gateway",
"vpcId": "vpc-00c0dad452596a616"
},
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateVpcEndpointConnectionNotification
#Description
Creates a connection notification for a specified VPC endpoint or VPC endpoint service.
CreateVpcEndpointServiceConfiguration
#Description
Creates a VPC endpoint service to which service consumers (Amazon Web Services accounts, users, and IAM roles) can connect.
CreateVpcPeeringConnection
#Description
Requests a VPC peering connection between two VPCs: a requester VPC that you own and a peer VPC with which to create the connection.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "Client.MissingParameter",
"errorMessage": "The request must contain the parameter vpcId",
"eventID": "a6e13f34-7dee-405a-895b-6ae4e4967614",
"eventName": "CreateVpcPeeringConnection",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2019-11-17T04:58:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "043e429d-72f8-4233-8379-acf891753a46",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "8.103.248.255",
"userAgent": "aws-cli/1.14.44 Python/3.6.8 Linux/4.4.0-039049-Microsoft botocore/1.8.48",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
CreateVpnConcentrator
#Description
Creates a VPN concentrator that aggregates multiple VPN connections to a transit gateway.
CreateVpnConnection
#Description
Creates a VPN connection between an existing virtual private gateway and a VPN customer gateway.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpnGatewayID.NotFound",
"errorMessage": "The vpnGateway ID 'vgw-03b7415aef1ba49a5' does not exist",
"eventCategory": "Management",
"eventID": "5668f6a8-8721-4a46-a08b-2999ed837aac",
"eventName": "CreateVpnConnection",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:46:05Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9cad7367-33ed-4749-9558-66b664797612",
"requestParameters": {
"customerGatewayId": "cgw-04a9f55555b346fed",
"options": {
"staticRoutesOnly": true
},
"tagSpecificationSet": {
"items": [
{
"resourceType": "vpn-connection",
"tags": [
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
},
{
"key": "dwfix",
"value": "1"
}
]
}
]
},
"type": "ipsec.1",
"vpnGatewayId": "vgw-03b7415aef1ba49a5"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
CreateVpnConnectionRoute
#Description
Creates a static route associated with a VPN connection between an existing virtual private gateway and a VPN customer gateway.
CreateVpnGateway
#Description
Creates a virtual private gateway.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "cda16e37-f10f-4930-9d3b-396c44cb3f23",
"eventName": "CreateVpnGateway",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:46:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4e514fa0-925e-4a2c-aafd-58d271032829",
"requestParameters": {
"tagSpecificationSet": {
"items": [
{
"resourceType": "vpn-gateway",
"tags": [
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
},
{
"key": "dwfix",
"value": "1"
}
]
}
]
},
"type": "ipsec.1"
},
"responseElements": {
"requestId": "4e514fa0-925e-4a2c-aafd-58d271032829",
"vpnGateway": {
"amazonSideAsn": 64512,
"attachments": {},
"state": "pending",
"tagSet": {
"items": [
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
},
{
"key": "dwfix",
"value": "1"
}
]
},
"type": "ipsec.1",
"vpnGatewayId": "vgw-03b7415aef1ba49a5"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteCapacityManagerDataExport
#Description
Deletes an existing Capacity Manager data export configuration.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidCapacityManagerDataExportId.Malformed",
"errorMessage": "The capacity-manager-data-export ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "b72bd82c-1fce-4e9a-8844-43c210b82545",
"eventName": "DeleteCapacityManagerDataExport",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c00a45f5-3ff9-485c-b54b-702789f071f0",
"requestParameters": {
"DeleteCapacityManagerDataExportRequest": {
"CapacityManagerDataExportId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteCarrierGateway
#Description
Deletes a carrier gateway.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.UnsupportedOperation",
"errorMessage": "The functionality you requested is not available in this region.",
"eventCategory": "Management",
"eventID": "2459b9aa-9944-4b72-a9be-f4e337421e95",
"eventName": "DeleteCarrierGateway",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "09a136b5-460a-4593-b04b-3cf20f5958e1",
"requestParameters": {
"DeleteCarrierGatewayRequest": {
"CarrierGatewayId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteClientVpnEndpoint
#Description
Deletes the specified Client VPN endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidClientVpnEndpointId.NotFound",
"errorMessage": "The client-vpn-endpoint ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "5f80a40d-4cdf-4711-9a7c-7ce30ef450d8",
"eventName": "DeleteClientVpnEndpoint",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "514c66dd-96f5-4549-9022-20b5053e905b",
"requestParameters": {
"DeleteClientVpnEndpointRequest": {
"ClientVpnEndpointId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteClientVpnRoute
#Description
Deletes a route from a Client VPN endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidClientVpnEndpointId.NotFound",
"errorMessage": "Endpoint dw-probe does not exist",
"eventCategory": "Management",
"eventID": "0d8df003-83e9-47f0-9651-fda3cbfb2c9e",
"eventName": "DeleteClientVpnRoute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e6213a93-27bb-4a14-9437-f2b6df9b7298",
"requestParameters": {
"DeleteClientVpnRouteRequest": {
"ClientVpnEndpointId": "dw-probe",
"DestinationCidrBlock": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteCoipCidr
#Description
Deletes a range of customer-owned IP addresses.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpv4PoolCoipId.Malformed",
"errorMessage": "The coip-pool ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "54e46b97-90ce-412f-aebd-318c50fd9f9c",
"eventName": "DeleteCoipCidr",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "22b0b0a2-96ca-43fb-b5f6-efc142e260df",
"requestParameters": {
"DeleteCoipCidrRequest": {
"Cidr": "dw-probe",
"CoipPoolId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteCoipPool
#Description
Deletes a pool of customer-owned IP (CoIP) addresses.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpv4PoolCoipId.Malformed",
"errorMessage": "The coip-pool ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "0fb92ec6-c726-4786-a6b4-71ed1476d155",
"eventName": "DeleteCoipPool",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5b36d039-82de-442b-b2eb-2dd56350989c",
"requestParameters": {
"DeleteCoipPoolRequest": {
"CoipPoolId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteCustomerGateway
#Description
Deletes the specified customer gateway.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidCustomerGatewayId.Malformed",
"errorMessage": "Invalid id: \"dw-probe\" (expecting \"cgw-...\")",
"eventCategory": "Management",
"eventID": "2863b0e5-d8b7-4c08-9696-6c1fdb34a4b0",
"eventName": "DeleteCustomerGateway",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "44cd7f85-6617-4bde-b3c6-a9aea98549dd",
"requestParameters": {
"customerGatewayId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches AttachInternetGateway, CreateCustomerGateway, CreateInternetGateway, DeleteInternetGateway, DetachInternetGateway
DeleteDhcpOptions
#Description
Deletes the specified set of DHCP options.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidDhcpOptionsId.Malformed",
"errorMessage": "The dhcp-options ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "fd8cbfae-bff3-4207-8b91-cffa6201e7ca",
"eventName": "DeleteDhcpOptions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7db3e2fb-3227-4317-9e4a-ddcda80c5e1d",
"requestParameters": {
"dhcpOptionsId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteEgressOnlyInternetGateway
#Description
Deletes an egress-only internet gateway.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.MalformedGatewayID.NotFound",
"errorMessage": "The eigw ID dw-probe is malformed",
"eventCategory": "Management",
"eventID": "b2de6e37-9e36-4a46-8025-7cb2c1a5b98e",
"eventName": "DeleteEgressOnlyInternetGateway",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e92e29c1-b278-4d87-99a1-d85e7984f161",
"requestParameters": {
"DeleteEgressOnlyInternetGatewayRequest": {
"EgressOnlyInternetGatewayId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteFleets
#Description
Deletes the specified EC2 Fleet request.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidFleetId.Malformed",
"errorMessage": "The fleet ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "b4fe54a1-d648-4d9b-8396-3ae191efdd64",
"eventName": "DeleteFleets",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "3ad67e84-b206-4f0b-9aed-1e13616d55d1",
"requestParameters": {
"DeleteFleetsRequest": {
"FleetId": {
"content": "dw-probe",
"tag": 1
},
"TerminateInstances": false
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteFpgaImage
#Description
Deletes the specified Amazon FPGA Image (AFI).
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.UnsupportedOperation",
"errorMessage": "The functionality you requested is not available in this region.",
"eventCategory": "Management",
"eventID": "5d0c6d09-512f-4068-8fe4-90bad617f33d",
"eventName": "DeleteFpgaImage",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ca935361-a773-40c5-9b78-f635b8c3d320",
"requestParameters": {
"DeleteFpgaImageRequest": {
"FpgaImageId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteImageUsageReport
#Description
Deletes the specified image usage report.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidImageUsageReportId.Malformed",
"errorMessage": "The image-usage-report ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "a3d87ad8-d275-4c51-ba41-3dcebeff1b2b",
"eventName": "DeleteImageUsageReport",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7c228951-cccc-4eee-9a27-32dca1562d9f",
"requestParameters": {
"DeleteImageUsageReportRequest": {
"ReportId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteInstanceConnectEndpoint
#Description
Deletes the specified EC2 Instance Connect Endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidInstanceConnectEndpointId.Malformed",
"errorMessage": "The instance-connect-endpoint ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "6d9c73b2-25d8-4823-9ed9-d312c00bdb9d",
"eventName": "DeleteInstanceConnectEndpoint",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "64a02afd-280b-4196-a566-f35bbdeb30d7",
"requestParameters": {
"DeleteInstanceConnectEndpointRequest": {
"InstanceConnectEndpointId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteInstanceEventWindow
#Description
Deletes the specified event window.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "1 validation error detected: Value 'dw-probe' at 'eventWindowId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^iew-[\\w]+$",
"eventCategory": "Management",
"eventID": "63c4df52-df3c-4629-8351-252c6180cf67",
"eventName": "DeleteInstanceEventWindow",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e2444d4a-a7d8-492a-8b1d-9cd746937028",
"requestParameters": {
"DeleteInstanceEventWindowRequest": {
"InstanceEventWindowId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
DeleteInternetGateway
#Description
Deletes the specified Internet gateway.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "930bcbfc-fe56-4d77-a1c5-c5c6e75812ca",
"eventName": "DeleteInternetGateway",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:08:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "86886406-e4ff-4536-8880-6c7f49edfd0c",
"requestParameters": {
"internetGatewayId": "igw-040b2274c4a167722"
},
"responseElements": {
"_return": true,
"requestId": "86886406-e4ff-4536-8880-6c7f49edfd0c"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/4.67.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.261 (go1.19.8; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches AttachInternetGateway, CreateCustomerGateway, CreateInternetGateway, DeleteCustomerGateway, DetachInternetGateway
References #
DeleteIpam
#Description
Delete an IPAM.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamId.Malformed",
"errorMessage": "The specified IPAM Id is not valid. Specify an IPAM Id in the form ipam-xxxxxxxxxxxxxxxxx.",
"eventCategory": "Management",
"eventID": "9d9d454c-d6ea-45b6-8f99-1f4ff09d3ce4",
"eventName": "DeleteIpam",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "611feb20-c634-4265-ac08-49b5ecaef01b",
"requestParameters": {
"DeleteIpamRequest": {
"IpamId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteIpamExternalResourceVerificationToken
#Description
Delete a verification token.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamExternalResourceVerificationTokenId.Malformed",
"errorMessage": "The ipam-external-resource-verification-token ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "8f9494ff-ca98-42e1-8e59-25e618a31114",
"eventName": "DeleteIpamExternalResourceVerificationToken",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5b4f87e4-760c-4a59-af5c-85a27d9041f6",
"requestParameters": {
"DeleteIpamExternalResourceVerificationTokenRequest": {
"IpamExternalResourceVerificationTokenId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteIpamPolicy
#Description
Deletes an IPAM policy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamPolicyId.Malformed",
"errorMessage": "The ipam-policy ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "7b356c57-52b8-442b-bf45-896209b7bd21",
"eventName": "DeleteIpamPolicy",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "3ad01d2c-4d9d-437f-aab3-7988dafefceb",
"requestParameters": {
"DeleteIpamPolicyRequest": {
"IpamPolicyId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteIpamPool
#Description
Delete an IPAM pool.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamPoolId.Malformed",
"errorMessage": "The ipam-pool ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "925d96f5-96b4-4dc4-9a53-fe6355730d21",
"eventName": "DeleteIpamPool",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "787de90d-0f6f-4ef2-bb45-c82d9500058e",
"requestParameters": {
"DeleteIpamPoolRequest": {
"IpamPoolId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteIpamPrefixListResolver
#Description
Deletes an IPAM prefix list resolver.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamPrefixListResolverId.Malformed",
"errorMessage": "The ipam-prefix-list-resolver ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "59c77a51-463f-4d10-bd81-73042645780a",
"eventName": "DeleteIpamPrefixListResolver",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "79378da3-07a9-444d-9ddf-74534a1302d2",
"requestParameters": {
"DeleteIpamPrefixListResolverRequest": {
"IpamPrefixListResolverId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteIpamPrefixListResolverTarget
#Description
Deletes an IPAM prefix list resolver target.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamPrefixListResolverTargetId.Malformed",
"errorMessage": "The ipam-prefix-list-resolver-target ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "5c34ae54-461c-415e-a05f-554433b911ec",
"eventName": "DeleteIpamPrefixListResolverTarget",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "04ea60f8-83ea-461a-93ad-fae509a3d105",
"requestParameters": {
"DeleteIpamPrefixListResolverTargetRequest": {
"IpamPrefixListResolverTargetId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteIpamResourceDiscovery
#Description
Deletes an IPAM resource discovery.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamResourceDiscoveryId.Malformed",
"errorMessage": "The specified IPAM resource discovery ID is not valid. Specify an IPAM resource discovery ID in the form ipam-res-disco-xxxxxxxxxxxxxxxxx.",
"eventCategory": "Management",
"eventID": "6d2d987f-5de4-4b12-bd34-beeda2995775",
"eventName": "DeleteIpamResourceDiscovery",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "55407571-0713-4ed4-b1db-4cd6999a5773",
"requestParameters": {
"DeleteIpamResourceDiscoveryRequest": {
"IpamResourceDiscoveryId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteIpamScope
#Description
Delete the scope for an IPAM.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamScopeId.Malformed",
"errorMessage": "The specified IPAM scope ID is not valid. Specify an IPAM scope ID in the form ipam-scope-xxxxxxxxxxxxxxxxx.",
"eventCategory": "Management",
"eventID": "531535e9-3ffd-4209-a900-52023d376fa9",
"eventName": "DeleteIpamScope",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "58d5a287-67e4-4998-bd12-cf0ca294ad19",
"requestParameters": {
"DeleteIpamScopeRequest": {
"IpamScopeId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteKeyPair
#Description
Deletes the specified key pair, by removing the public key from Amazon EC2.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.MissingParameter",
"errorMessage": "The request must contain the parameter KeyName",
"eventCategory": "Management",
"eventID": "64e3fc8c-4519-4103-ad3f-ab98285ecd49",
"eventName": "DeleteKeyPair",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:45:16Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6f0f7652-2876-41ed-b5d0-87f4322a4682",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteLaunchTemplate
#Description
Deletes a launch template.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "Client.MissingParameter",
"errorMessage": "Either a launch template ID or a launch template name must be specified in the request.",
"eventID": "4f0e0cab-3638-41e3-a5a3-011e3111c79c",
"eventName": "DeleteLaunchTemplate",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2019-11-17T04:59:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "3dfb7cf8-e214-4630-927d-0228cfb24ffd",
"requestParameters": {
"DeleteLaunchTemplateRequest": ""
},
"responseElements": null,
"sourceIPAddress": "8.103.248.255",
"userAgent": "aws-cli/1.14.44 Python/3.6.8 Linux/4.4.0-039049-Microsoft botocore/1.8.48",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DeleteLaunchTemplateVersions
#Description
Deletes one or more versions of a launch template.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.MissingParameter",
"errorMessage": "Either a launch template ID or a launch template name must be specified in the request.",
"eventCategory": "Management",
"eventID": "3d0e6e47-fadd-4ef0-8d96-716fa6cb4bc1",
"eventName": "DeleteLaunchTemplateVersions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2366b28a-8555-43e6-8448-bdbcb13bb25c",
"requestParameters": {
"DeleteLaunchTemplateVersionsRequest": {
"LaunchTemplateVersion": {
"content": "dw-probe",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteLocalGatewayRoute
#Description
Deletes the specified route from the specified local gateway route table.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidLocalGatewayRouteTableID.Malformed",
"errorMessage": "The local-gateway-route-table ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "fad30896-21c9-4818-b366-28a85d51ea94",
"eventName": "DeleteLocalGatewayRoute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "751a9dc5-de81-426c-a270-3a79cfe96ea3",
"requestParameters": {
"DeleteLocalGatewayRouteRequest": {
"LocalGatewayRouteTableId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteLocalGatewayRouteTable
#Description
Deletes a local gateway route table.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidLocalGatewayRouteTableID.Malformed",
"errorMessage": "The local-gateway-route-table ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "dd6976b0-c895-4fd6-95fb-a8bb7debe09b",
"eventName": "DeleteLocalGatewayRouteTable",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e7f0da3a-4490-4dd0-b34c-a78feaf49e40",
"requestParameters": {
"DeleteLocalGatewayRouteTableRequest": {
"LocalGatewayRouteTableId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteLocalGatewayRouteTableVirtualInterfaceGroupAssociation
#Description
Deletes a local gateway route table virtual interface group association.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidLocalGatewayRouteTableVirtualInterfaceGroupAssociationID.Malformed",
"errorMessage": "The local-gateway-route-table-virtual-interface-group-association ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "43342a0a-1275-4f82-ae68-a15760881d1e",
"eventName": "DeleteLocalGatewayRouteTableVirtualInterfaceGroupAssociation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c861d047-49d9-4c6d-9e85-c88c34f033c2",
"requestParameters": {
"DeleteLocalGatewayRouteTableVirtualInterfaceGroupAssociationRequest": {
"LocalGatewayRouteTableVirtualInterfaceGroupAssociationId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteLocalGatewayRouteTableVpcAssociation
#Description
Deletes the specified association between a VPC and local gateway route table.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidLocalGatewayRouteTableVpcAssociationID.Malformed",
"errorMessage": "The local-gateway-route-table-vpc-association ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "186557a1-372a-45e6-92db-6a59ccdbfdf3",
"eventName": "DeleteLocalGatewayRouteTableVpcAssociation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b0d4fce5-3187-461b-a815-64c2eae1893f",
"requestParameters": {
"DeleteLocalGatewayRouteTableVpcAssociationRequest": {
"LocalGatewayRouteTableVpcAssociationId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteLocalGatewayVirtualInterface
#Description
Deletes the specified local gateway virtual interface.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidLocalGatewayVirtualInterfaceID.Malformed",
"errorMessage": "The local-gateway-virtual-interface ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "32e2793f-4aea-4a82-8e59-e152a1ea68f1",
"eventName": "DeleteLocalGatewayVirtualInterface",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "32c6bd77-0025-4cbe-a141-6e871c8cba6e",
"requestParameters": {
"DeleteLocalGatewayVirtualInterfaceRequest": {
"LocalGatewayVirtualInterfaceId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteLocalGatewayVirtualInterfaceGroup
#Description
Delete the specified local gateway interface group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidLocalGatewayVirtualInterfaceGroupID.Malformed",
"errorMessage": "The local-gateway-virtual-interface-group ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "daa85093-a804-4682-b123-75d3c4c01afc",
"eventName": "DeleteLocalGatewayVirtualInterfaceGroup",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "eaf53754-93d0-47f4-841b-1027258ad17c",
"requestParameters": {
"DeleteLocalGatewayVirtualInterfaceGroupRequest": {
"LocalGatewayVirtualInterfaceGroupId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteManagedPrefixList
#Description
Deletes the specified managed prefix list.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidPrefixListId.Malformed",
"errorMessage": "The prefix-list ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "d2b999a4-5107-440d-9d22-490d78a6e7ef",
"eventName": "DeleteManagedPrefixList",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6c3074e1-b572-4b43-8c38-7ec85f8c2919",
"requestParameters": {
"DeleteManagedPrefixListRequest": {
"PrefixListId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteNatGateway
#Description
Deletes the specified NAT gateway.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "de095443-8389-4aa2-9bcb-d3295a255169",
"eventName": "DeleteNatGateway",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:08:06Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "de006d2f-9fc1-49b9-814f-b5914c38881b",
"requestParameters": {
"DeleteNatGatewayRequest": {
"NatGatewayId": "nat-0dd264ee104155137"
}
},
"responseElements": {
"DeleteNatGatewayResponse": {
"natGatewayId": "nat-0dd264ee104155137",
"requestId": "de006d2f-9fc1-49b9-814f-b5914c38881b",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DeleteNetworkInsightsAccessScope
#Description
Deletes the specified Network Access Scope.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "dw-probe is not a valid NetworkInsightsAccessScopeId.",
"eventCategory": "Management",
"eventID": "08ccf09b-38f8-4295-a071-f1de6a1e8f41",
"eventName": "DeleteNetworkInsightsAccessScope",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:29Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0aee0f8c-a599-407d-9ebc-a995d9094a04",
"requestParameters": {
"DeleteNetworkInsightsAccessScopeRequest": {
"NetworkInsightsAccessScopeId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteNetworkInsightsAccessScopeAnalysis
#Description
Deletes the specified Network Access Scope analysis.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "dw-probe is not a valid NetworkInsightsAccessScopeAnalysisId.",
"eventCategory": "Management",
"eventID": "f0e01e0f-145f-431e-a0f0-1c8a0870b623",
"eventName": "DeleteNetworkInsightsAccessScopeAnalysis",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "cc0db49e-6d8e-41a1-9565-da55b7f86eeb",
"requestParameters": {
"DeleteNetworkInsightsAccessScopeAnalysisRequest": {
"NetworkInsightsAccessScopeAnalysisId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteNetworkInsightsAnalysis
#Description
Deletes the specified network insights analysis.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "dw-probe is not a valid NetworkInsightsAnalysisId.",
"eventCategory": "Management",
"eventID": "555ab816-e1d1-4443-8a37-55b3ee158795",
"eventName": "DeleteNetworkInsightsAnalysis",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ed8be186-4505-4c9a-9e09-25abadd877dd",
"requestParameters": {
"DeleteNetworkInsightsAnalysisRequest": {
"NetworkInsightsAnalysisId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteNetworkInsightsPath
#Description
Deletes the specified path.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "dw-probe is not a valid NetworkInsightsPathId.",
"eventCategory": "Management",
"eventID": "93228956-4400-4213-8a87-ff53bc91f210",
"eventName": "DeleteNetworkInsightsPath",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c9940bbf-8a46-47d4-8d51-e27f2e1eac7f",
"requestParameters": {
"DeleteNetworkInsightsPathRequest": {
"NetworkInsightsPathId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteNetworkInterface
#Description
Deletes the specified network interface.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "33a9aebf-b70c-4de6-beaa-2b108fa358ce",
"eventName": "DeleteNetworkInterface",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:12:06Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "9cffc258-0812-4313-a70f-b2bb26d43c3e",
"requestParameters": {
"networkInterfaceId": "eni-06b7a305fe9519d03"
},
"responseElements": {
"_return": true,
"requestId": "9cffc258-0812-4313-a70f-b2bb26d43c3e"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DeleteNetworkInterfacePermission
#Description
Deletes a permission for a network interface.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidPermissionID.Malformed",
"errorMessage": "The ENI permission ID dw-probe is malformed",
"eventCategory": "Management",
"eventID": "24d8f18c-0e01-49f6-b405-c40e8aee6118",
"eventName": "DeleteNetworkInterfacePermission",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "75a2a1dc-80a1-43e0-88bf-3a710389019c",
"requestParameters": {
"DeleteNetworkInterfacePermissionRequest": {
"NetworkInterfacePermissionId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeletePlacementGroup
#Description
Deletes the specified placement group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidPlacementGroup.Unknown",
"errorMessage": "The placement group 'dw-probe' is unknown.",
"eventCategory": "Management",
"eventID": "1b484ef3-d06a-4dfa-86e2-4533e1fd93e6",
"eventName": "DeletePlacementGroup",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "585e4389-e902-44e6-a917-056fb36169be",
"requestParameters": {
"groupName": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeletePublicIpv4Pool
#Description
Delete a public IPv4 pool.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidPublicIpv4PoolID.Malformed",
"errorMessage": "The pool ID 'dw-probe' is invalid.",
"eventCategory": "Management",
"eventID": "34b1d0eb-31ad-4ed2-9b77-b82d98d1003c",
"eventName": "DeletePublicIpv4Pool",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c5deb2b6-70d2-4644-bc1c-fe0869babab6",
"requestParameters": {
"DeletePublicIpv4PoolRequest": {
"PoolId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteQueuedReservedInstances
#Description
Deletes the queued purchases for the specified Reserved Instances.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidReservedInstancesID.NotFound",
"errorMessage": "The reserved-instances ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "86983f06-77a7-482d-a9e9-09e0c9ad8d0d",
"eventName": "DeleteQueuedReservedInstances",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2703cb41-d917-4cdd-9066-ece143a0a919",
"requestParameters": {
"DeleteQueuedReservedInstancesRequest": {
"ReservedInstancesId": {
"content": "dw-probe",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteRouteServer
#Description
Deletes the specified route server.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRouteServerId.Malformed",
"errorMessage": "The route-server ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "edbe2bf8-7c66-469c-b0f8-494f0655e4d0",
"eventName": "DeleteRouteServer",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9ad41cdd-a94d-4ca9-8c55-e83a3d4e3dfa",
"requestParameters": {
"DeleteRouteServerRequest": {
"RouteServerId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteRouteServerEndpoint
#Description
Deletes the specified route server endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRouteServerEndpointId.Malformed",
"errorMessage": "The route-server-endpoint ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "79b33898-3aa9-46ba-a383-5b7ec528a1c5",
"eventName": "DeleteRouteServerEndpoint",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d5d45c18-8b27-4456-805f-0fab13076e15",
"requestParameters": {
"DeleteRouteServerEndpointRequest": {
"RouteServerEndpointId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteRouteServerPeer
#Description
Deletes the specified BGP peer from a route server.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRouteServerPeerId.Malformed",
"errorMessage": "The route-server-peer ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "99ac6e5e-3074-4a65-9355-75a7ccc64c4c",
"eventName": "DeleteRouteServerPeer",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d280966c-6f0b-4af2-8fc5-c8480f88fa63",
"requestParameters": {
"DeleteRouteServerPeerRequest": {
"RouteServerPeerId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteSecondaryNetwork
#Description
Deletes a secondary network.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidSecondaryNetworkId.Malformed",
"errorMessage": "The secondary-network ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "64feeeea-9a90-47f4-8c1a-9b1fcebea15e",
"eventName": "DeleteSecondaryNetwork",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "52af086d-30e0-4491-ac8f-57ac28a9f0cd",
"requestParameters": {
"DeleteSecondaryNetworkRequest": {
"ClientToken": "397f09dd-78d3-4684-a40d-352ff870d2e9",
"SecondaryNetworkId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteSecondarySubnet
#Description
Deletes a secondary subnet.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidAction",
"errorMessage": "The action DeleteSecondarySubnet is not valid for this web service.",
"eventCategory": "Management",
"eventID": "b38c62bd-ba81-41d4-a68a-ffe2d40d12f9",
"eventName": "DeleteSecondarySubnet",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9fc5460c-5668-476f-ad4a-1e64fd600fe0",
"requestParameters": {
"DeleteSecondarySubnetRequest": {
"ClientToken": "ac401a70-c282-42b1-be2f-0c844d176e77",
"SecondarySubnetId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteSecurityGroup
#Description
Deletes a security group.
Example CloudTrail Event #
{
"eventVersion": "1.11",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE"
},
"eventTime": "2026-07-28T20:58:40Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "DeleteSecurityGroup",
"awsRegion": "us-west-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/Z,E,n,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#ec2.delete-security-group",
"requestParameters": {
"groupId": "sg-0200d267c43de2fbc"
},
"responseElements": {
"requestId": "1f00956a-134f-4cd1-b95c-522e7512c3b6",
"_return": true,
"groupId": "sg-0200d267c43de2fbc"
},
"requestID": "1f00956a-134f-4cd1-b95c-522e7512c3b6",
"eventID": "db1b4c66-7939-42db-958b-4de58e2d7f62",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches AuthorizeSecurityGroupEgress, AuthorizeSecurityGroupIngress, CreateSecurityGroup, RevokeSecurityGroupEgress, RevokeSecurityGroupIngress
DeleteSnapshot
#Description
Deletes the specified snapshot.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "af96f3f5-5b2d-40dd-886e-4db2d999130b",
"eventName": "DeleteSnapshot",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:12:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "adf10ecf-38a9-4e9d-9039-881ec40c20b9",
"requestParameters": {
"force": false,
"snapshotId": "snap-083d3b857c13988bc"
},
"responseElements": {
"_return": true,
"requestId": "adf10ecf-38a9-4e9d-9039-881ec40c20b9"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DeleteSpotDatafeedSubscription
#Description
Deletes the datafeed for Spot Instances.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "fe861022-74c7-447f-98a7-43cb3779be1e",
"eventName": "DeleteSpotDatafeedSubscription",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2019-11-17T04:59:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "9a5d89be-58f7-4feb-8cd7-aef7fb82bff9",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "8.103.248.255",
"userAgent": "aws-cli/1.14.44 Python/3.6.8 Linux/4.4.0-039049-Microsoft botocore/1.8.48",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DeleteSubnet
#Description
Deletes the specified subnet.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "b0fb6697-fa27-429c-b90c-dbd7d0381d49",
"eventName": "DeleteSubnet",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:08:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "bfa021b8-68ee-44c6-b2c4-3ec501445680",
"requestParameters": {
"subnetId": "subnet-096553f59d783f082"
},
"responseElements": {
"_return": true,
"requestId": "bfa021b8-68ee-44c6-b2c4-3ec501445680"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/4.67.0 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.261 (go1.19.8; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DeleteSubnetCidrReservation
#Description
Deletes a subnet CIDR reservation.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidSubnetCidrReservationID.Malformed",
"errorMessage": "The subnet-cidr-reservation ID dw-probe is malformed",
"eventCategory": "Management",
"eventID": "427c3b67-d7b4-43b7-9117-16a146139602",
"eventName": "DeleteSubnetCidrReservation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2535cb40-2147-440b-a958-b83cbdd38daa",
"requestParameters": {
"DeleteSubnetCidrReservationRequest": {
"SubnetCidrReservationId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTrafficMirrorFilter
#Description
Deletes the specified Traffic Mirror filter.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "Invalid ID: dw-probe. Filter ID must be 20 characters!",
"eventCategory": "Management",
"eventID": "8e3b7df5-bf68-4fa0-8190-b19f303d65a9",
"eventName": "DeleteTrafficMirrorFilter",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:33Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "23880102-faf6-4c1c-8847-409b8e764395",
"requestParameters": {
"DeleteTrafficMirrorFilterRequest": {
"TrafficMirrorFilterId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1040↳ also matches CreateTrafficMirrorSession, CreateTrafficMirrorFilter, CreateTrafficMirrorFilterRule, CreateTrafficMirrorTarget, DeleteTrafficMirrorFilterRule, DeleteTrafficMirrorSession, and 4 more
DeleteTrafficMirrorFilterRule
#Description
Deletes the specified Traffic Mirror rule.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "Invalid ID: dw-probe. Filter rule ID must be 21 characters!",
"eventCategory": "Management",
"eventID": "40741a94-0bf6-4b5e-bbfe-00e97dce3228",
"eventName": "DeleteTrafficMirrorFilterRule",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:33Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2e034ded-8646-493d-97dd-7d1b63d057a3",
"requestParameters": {
"DeleteTrafficMirrorFilterRuleRequest": {
"TrafficMirrorFilterRuleId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1040↳ also matches CreateTrafficMirrorSession, CreateTrafficMirrorFilter, CreateTrafficMirrorFilterRule, CreateTrafficMirrorTarget, DeleteTrafficMirrorFilter, DeleteTrafficMirrorSession, and 4 more
DeleteTrafficMirrorSession
#Description
Deletes the specified Traffic Mirror session.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "Invalid ID: dw-probe. Session ID must be 20 characters!",
"eventCategory": "Management",
"eventID": "f61deef9-0b24-4e6c-b107-8b5d8be8effc",
"eventName": "DeleteTrafficMirrorSession",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:33Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7645a1c5-203e-4993-abe4-4a0af06310bb",
"requestParameters": {
"DeleteTrafficMirrorSessionRequest": {
"TrafficMirrorSessionId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1040↳ also matches CreateTrafficMirrorSession, CreateTrafficMirrorFilter, CreateTrafficMirrorFilterRule, CreateTrafficMirrorTarget, DeleteTrafficMirrorFilter, DeleteTrafficMirrorFilterRule, and 4 more
DeleteTrafficMirrorTarget
#Description
Deletes the specified Traffic Mirror target.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "Invalid ID: dw-probe. Target ID must be 20 characters!",
"eventCategory": "Management",
"eventID": "48b116ab-7f43-4f5f-bf59-017e9179e82c",
"eventName": "DeleteTrafficMirrorTarget",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:33Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ea75e663-fc31-483e-a45f-81c9b70589ef",
"requestParameters": {
"DeleteTrafficMirrorTargetRequest": {
"TrafficMirrorTargetId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1040↳ also matches CreateTrafficMirrorSession, CreateTrafficMirrorFilter, CreateTrafficMirrorFilterRule, CreateTrafficMirrorTarget, DeleteTrafficMirrorFilter, DeleteTrafficMirrorFilterRule, and 4 more
DeleteTransitGateway
#Description
Deletes the specified transit gateway.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayID.Malformed",
"errorMessage": "Invalid Transit Gateway id dw-probe.",
"eventCategory": "Management",
"eventID": "dc2f74ba-d5bc-4be6-b0f7-a1bc42101efc",
"eventName": "DeleteTransitGateway",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:33Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0053ccfc-879c-499a-94e1-d8aba73c8919",
"requestParameters": {
"DeleteTransitGatewayRequest": {
"TransitGatewayId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTransitGatewayClientVpnAttachment
#Description
Deletes a Transit Gateway attachment for a Client VPN endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayAttachmentID.Malformed",
"errorMessage": "The transit-gateway-attachment ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "94a39324-4fcd-4356-8a53-115a87587b64",
"eventName": "DeleteTransitGatewayClientVpnAttachment",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ecfa63c3-4c9f-42a0-9f4d-c2908d6042ce",
"requestParameters": {
"DeleteTransitGatewayClientVpnAttachmentRequest": {
"TransitGatewayAttachmentId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTransitGatewayConnect
#Description
Deletes the specified Connect attachment.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayAttachmentID.Malformed",
"errorMessage": "The transit-gateway-attachment ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "22486e16-cd09-45c8-8c10-87a0adac8b76",
"eventName": "DeleteTransitGatewayConnect",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e3c319ea-d2d6-4e6a-b3e1-48fa91e6ceda",
"requestParameters": {
"DeleteTransitGatewayConnectRequest": {
"TransitGatewayAttachmentId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTransitGatewayConnectPeer
#Description
Deletes the specified Connect peer.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayConnectPeerID.Malformed",
"errorMessage": "The transit-gateway-connect-peer ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "907451da-e802-4fda-93aa-8e82f916440a",
"eventName": "DeleteTransitGatewayConnectPeer",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "136c48e5-1275-458c-8308-2d9d289f35bd",
"requestParameters": {
"DeleteTransitGatewayConnectPeerRequest": {
"TransitGatewayConnectPeerId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTransitGatewayMeteringPolicy
#Description
Deletes a transit gateway metering policy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayMeteringPolicyIdMalformedException",
"errorMessage": "The transit-gateway-metering-policy ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "94c7c88e-7e7f-443e-aabc-bae84036fcfe",
"eventName": "DeleteTransitGatewayMeteringPolicy",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8bbbb7e2-f543-41cb-a562-d9723a6658fb",
"requestParameters": {
"DeleteTransitGatewayMeteringPolicyRequest": {
"TransitGatewayMeteringPolicyId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTransitGatewayMeteringPolicyEntry
#Description
Deletes an entry from a transit gateway metering policy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayMeteringPolicyIdMalformedException",
"errorMessage": "The transit-gateway-metering-policy ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "cff66025-161f-41a2-96fc-055e121c34d7",
"eventName": "DeleteTransitGatewayMeteringPolicyEntry",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c579a310-0268-4f2e-a80c-0deb9d67e768",
"requestParameters": {
"DeleteTransitGatewayMeteringPolicyEntryRequest": {
"PolicyRuleNumber": 1,
"TransitGatewayMeteringPolicyId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTransitGatewayMulticastDomain
#Description
Deletes the specified transit gateway multicast domain.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayMulticastDomainId.Malformed",
"errorMessage": "Invalid Transit Gateway Multicast Domain id dw-probe.",
"eventCategory": "Management",
"eventID": "197a74e7-b130-4fce-8216-2c927c5377a6",
"eventName": "DeleteTransitGatewayMulticastDomain",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "38b1cd73-580f-4467-bc00-d08ab07f9578",
"requestParameters": {
"DeleteTransitGatewayMulticastDomainRequest": {
"TransitGatewayMulticastDomainId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTransitGatewayPeeringAttachment
#Description
Deletes a transit gateway peering attachment.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayAttachmentID.Malformed",
"errorMessage": "Invalid Transit Gateway Attachment id.",
"eventCategory": "Management",
"eventID": "04c983ef-5bce-466f-be6e-374f11603289",
"eventName": "DeleteTransitGatewayPeeringAttachment",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9a9f9ed8-3e68-4e14-af00-7f022fd0e260",
"requestParameters": {
"DeleteTransitGatewayPeeringAttachmentRequest": {
"TransitGatewayAttachmentId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTransitGatewayPolicyTable
#Description
Deletes the specified transit gateway policy table.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayPolicyTableId.Malformed",
"errorMessage": "The transit-gateway-policy-table ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "060ea080-d981-4e37-a68d-23b9617d5819",
"eventName": "DeleteTransitGatewayPolicyTable",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f8ae87e5-8d17-4b49-a1e5-87dd3a80a1df",
"requestParameters": {
"DeleteTransitGatewayPolicyTableRequest": {
"TransitGatewayPolicyTableId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTransitGatewayPrefixListReference
#Description
Deletes a reference (route) to a prefix list in a specified transit gateway route table.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRouteTableId.Malformed",
"errorMessage": "Invalid Transit Gateway Route Table id dw-probe.",
"eventCategory": "Management",
"eventID": "42ea587b-7147-43e4-bedd-66d2d23611f3",
"eventName": "DeleteTransitGatewayPrefixListReference",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6f38fd73-2738-464a-8314-de63e2048e1f",
"requestParameters": {
"DeleteTransitGatewayPrefixListReferenceRequest": {
"PrefixListId": "dw-probe",
"TransitGatewayRouteTableId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTransitGatewayRoute
#Description
Deletes the specified route from the specified transit gateway route table.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRouteTableId.Malformed",
"errorMessage": "Invalid Transit Gateway Route Table id dw-probe.",
"eventCategory": "Management",
"eventID": "4aaf110d-9205-428a-ada5-fc8e157bd0ce",
"eventName": "DeleteTransitGatewayRoute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "512315d0-daf9-4fc3-9d75-adf99b4c3333",
"requestParameters": {
"DeleteTransitGatewayRouteRequest": {
"DestinationCidrBlock": "dw-probe",
"TransitGatewayRouteTableId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTransitGatewayRouteTable
#Description
Deletes the specified transit gateway route table.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRouteTableId.Malformed",
"errorMessage": "Invalid Transit Gateway Route Table id dw-probe.",
"eventCategory": "Management",
"eventID": "2e999e6d-602f-4d14-a10e-41d60475d05d",
"eventName": "DeleteTransitGatewayRouteTable",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:36Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8985af50-b499-41a3-a42e-be8d8cc2f419",
"requestParameters": {
"DeleteTransitGatewayRouteTableRequest": {
"TransitGatewayRouteTableId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTransitGatewayRouteTableAnnouncement
#Description
Advertises to the transit gateway that a transit gateway route table is deleted.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayRouteTableAnnouncementId.Malformed",
"errorMessage": "The transit-gateway-route-table-announcement ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "de24f261-7719-467a-8703-15782b8f4d4b",
"eventName": "DeleteTransitGatewayRouteTableAnnouncement",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:36Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f3437b93-9690-4821-a03e-bf497293251b",
"requestParameters": {
"DeleteTransitGatewayRouteTableAnnouncementRequest": {
"TransitGatewayRouteTableAnnouncementId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteTransitGatewayVpcAttachment
#Description
Deletes the specified VPC attachment.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayAttachmentID.Malformed",
"errorMessage": "Invalid Transit Gateway Attachment id.",
"eventCategory": "Management",
"eventID": "08658ced-a22e-438e-b569-72089cfa043e",
"eventName": "DeleteTransitGatewayVpcAttachment",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:36Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "77f3a9b8-5355-485d-9ba9-a577053ecfea",
"requestParameters": {
"DeleteTransitGatewayVpcAttachmentRequest": {
"TransitGatewayAttachmentId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteVerifiedAccessEndpoint
#Description
Delete an Amazon Web Services Verified Access endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVerifiedAccessEndpointId.NotFound",
"errorMessage": "VerifiedAccessEndpoint dw-probe does not exist",
"eventCategory": "Management",
"eventID": "c4597cea-39e7-45d6-b079-2f04cff0c189",
"eventName": "DeleteVerifiedAccessEndpoint",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:36Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e9f11be9-fc05-43e7-9229-4ff9200d1746",
"requestParameters": {
"DeleteVerifiedAccessEndpointRequest": {
"ClientToken": "107104d6-426d-401a-adb5-188304ea70d5",
"VerifiedAccessEndpointId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteVerifiedAccessGroup
#Description
Delete an Amazon Web Services Verified Access group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVerifiedAccessGroupId.NotFound",
"errorMessage": "VerifiedAccessGroup dw-probe does not exist",
"eventCategory": "Management",
"eventID": "a5fd6e52-9d9f-46c1-a04c-d6a6a95fb139",
"eventName": "DeleteVerifiedAccessGroup",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:37Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "bad9b328-9850-4d3f-ac47-e9f8253be124",
"requestParameters": {
"DeleteVerifiedAccessGroupRequest": {
"ClientToken": "84d9ce7c-6880-43d3-932a-4efad3d0d312",
"VerifiedAccessGroupId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteVerifiedAccessInstance
#Description
Delete an Amazon Web Services Verified Access instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVerifiedAccessInstanceId.NotFound",
"errorMessage": "VerifiedAccessInstance dw-probe does not exist",
"eventCategory": "Management",
"eventID": "9f4f6e07-faaf-47a6-b3de-8611cb24468e",
"eventName": "DeleteVerifiedAccessInstance",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:37Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "716cfede-d6ea-4539-b94f-6cfe88ecdf61",
"requestParameters": {
"DeleteVerifiedAccessInstanceRequest": {
"ClientToken": "12220941-5065-4220-8106-c526254d51cb",
"VerifiedAccessInstanceId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteVerifiedAccessTrustProvider
#Description
Delete an Amazon Web Services Verified Access trust provider.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVerifiedAccessTrustProviderId.NotFound",
"errorMessage": "VerifiedAccessTrustProvider dw-probe does not exist",
"eventCategory": "Management",
"eventID": "3407bc39-35b0-4cc8-8a73-371a97129dda",
"eventName": "DeleteVerifiedAccessTrustProvider",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:37Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "969071b9-8c3e-48c6-b5ae-6ac1fa7cb774",
"requestParameters": {
"DeleteVerifiedAccessTrustProviderRequest": {
"ClientToken": "87e193cb-b995-412c-9f9f-5e03fffb75a4",
"VerifiedAccessTrustProviderId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteVolume
#Description
Deletes the specified Amazon EBS volume.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "77a5e160-ad9e-419b-a329-2f8406054631",
"eventName": "DeleteVolume",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:12:04Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "2d8fd360-079d-4c5f-8aa1-e612af8bece0",
"requestParameters": {
"reportVolumeFailure": false,
"volumeId": "vol-0fc2e34e74650e145"
},
"responseElements": {
"_return": true,
"requestId": "2d8fd360-079d-4c5f-8aa1-e612af8bece0"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DeleteVpc
#Description
Deletes the specified VPC.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "c9c907af-3402-4ce0-a887-53d0f5ba4be3",
"eventName": "DeleteVpc",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:08:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "115a20b3-6b36-4449-a7f4-93b24f269081",
"requestParameters": {
"vpcId": "vpc-0255d384b4b458b46"
},
"responseElements": {
"_return": true,
"requestId": "115a20b3-6b36-4449-a7f4-93b24f269081"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches AcceptVpcPeeringConnection, AttachClassicLinkVpc, CreateVpc, DetachClassicLinkVpc, DisableVpcClassicLink, EnableVpcClassicLink, ModifyVpcAttribute, RejectVpcPeeringConnection
References #
DeleteVpcBlockPublicAccessExclusion
#Description
Delete a VPC Block Public Access (BPA) exclusion.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.VpcBlockPublicAccessExclusionId.Malformed",
"errorMessage": "The vpc-block-public-access-exclusion ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "7eb43045-0811-42f2-a648-e52a79a32c49",
"eventName": "DeleteVpcBlockPublicAccessExclusion",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "beaec851-c31d-419c-8032-f35696933107",
"requestParameters": {
"DeleteVpcBlockPublicAccessExclusionRequest": {
"ExclusionId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteVpcEncryptionControl
#Description
Deletes a VPC Encryption Control configuration.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpcEncryptionControlId.Malformed",
"errorMessage": "The vpc-encryption-control ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "195aad69-893f-4905-9807-56cb7f2d6fb3",
"eventName": "DeleteVpcEncryptionControl",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9c0dc833-c95f-4d92-84c0-d427899a21a6",
"requestParameters": {
"DeleteVpcEncryptionControlRequest": {
"VpcEncryptionControlId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteVpcEndpointConnectionNotifications
#Description
Deletes the specified VPC endpoint connection notifications.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameter",
"errorMessage": "Invalid Id: 'dw-probe' (expecting 'vpce-nfn-...; the Id may only contain lowercase alphanumeric characters and two dashes')",
"eventCategory": "Management",
"eventID": "f2c810ed-a65f-41b1-b9f1-b500fd4d9d96",
"eventName": "DeleteVpcEndpointConnectionNotifications",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "abc80740-a161-456e-8f83-6d5c29755945",
"requestParameters": {
"DeleteVpcEndpointConnectionNotificationsRequest": {
"ConnectionNotificationId": {
"content": "dw-probe",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteVpcEndpoints
#Description
Deletes one or more specified VPC endpoints.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpcEndpointId.Malformed",
"errorMessage": "Invalid Id: 'dw-probe' (expecting 'vpce-...; the Id may only contain lowercase alphanumeric characters and a single dash')",
"eventCategory": "Management",
"eventID": "18a0debd-07d3-49f7-b034-1a7515f04c4f",
"eventName": "DeleteVpcEndpoints",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "cec0aaa4-7d3f-4c10-b81f-15f74b6590de",
"requestParameters": {
"DeleteVpcEndpointsRequest": {
"VpcEndpointId": {
"content": "dw-probe",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteVpcEndpointServiceConfigurations
#Description
Deletes the specified VPC endpoint service configurations.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpcEndpointServiceId.Malformed",
"errorMessage": "Invalid Id: 'dw-probe' (expecting 'vpce-svc-...; the Id may only contain lowercase alphanumeric characters and two dashes')",
"eventCategory": "Management",
"eventID": "6de5ad97-6f94-41b1-9671-f8b8ac5de97d",
"eventName": "DeleteVpcEndpointServiceConfigurations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f015b967-75e8-4797-b944-73066a3f1ca8",
"requestParameters": {
"DeleteVpcEndpointServiceConfigurationsRequest": {
"ServiceId": {
"content": "dw-probe",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteVpcPeeringConnection
#Description
Deletes a VPC peering connection.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpcPeeringConnectionId.Malformed",
"errorMessage": "The vpc-peering-connection ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "c651ce03-5566-4758-8c8a-248b508c68be",
"eventName": "DeleteVpcPeeringConnection",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "bd1b9ec6-3daa-405a-bbdd-2dd78c21f4dd",
"requestParameters": {
"vpcPeeringConnectionId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteVpnConcentrator
#Description
Deletes the specified VPN concentrator.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpnConcentratorID.Malformed",
"errorMessage": "The vpn-concentrator ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "090c7e6c-ed17-4738-9238-f0694e8f7c5e",
"eventName": "DeleteVpnConcentrator",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2e1b56d7-2935-42fc-b991-93ec7cc30549",
"requestParameters": {
"DeleteVpnConcentratorRequest": {
"VpnConcentratorId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteVpnConnection
#Description
Deletes the specified VPN connection.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpnConnectionID.NotFound",
"errorMessage": "The vpnConnection ID 'dw-probe' does not exist",
"eventCategory": "Management",
"eventID": "fed21ef8-044a-422e-9d0a-59c9080dbc50",
"eventName": "DeleteVpnConnection",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1369ab37-9721-4fc3-a788-4634aeec62d7",
"requestParameters": {
"vpnConnectionId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteVpnConnectionRoute
#Description
Deletes the specified static route associated with a VPN connection between an existing virtual private gateway and a VPN customer gateway.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpnConnectionID.NotFound",
"errorMessage": "The vpnConnection ID 'dw-probe' does not exist",
"eventCategory": "Management",
"eventID": "fb2c99c1-b058-4fa2-889f-afd9a8c3b1f8",
"eventName": "DeleteVpnConnectionRoute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5b67480a-dc77-4c87-85a9-03c37569aaef",
"requestParameters": {
"destinationCidrBlock": "dw-probe",
"vpnConnectionId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteVpnGateway
#Description
Deletes the specified virtual private gateway.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpnGatewayID.NotFound",
"errorMessage": "The vpnGateway ID 'dw-probe' does not exist",
"eventCategory": "Management",
"eventID": "511d7419-eea3-4de7-ba91-29a0fe47092e",
"eventName": "DeleteVpnGateway",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9449e37a-9507-47f1-aa93-90ea80e74800",
"requestParameters": {
"vpnGatewayId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeprovisionByoipCidr
#Description
Releases the specified address range that you provisioned for use with your Amazon Web Services resources through bring your own IP addresses (BYOIP) and deletes the corresponding address pool.
DeprovisionIpamByoasn
#Description
Deprovisions your Autonomous System Number (ASN) from your Amazon Web Services account.
DeprovisionIpamPoolCidr
#Description
Deprovision a CIDR provisioned from an IPAM pool.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "1241faf1-e638-479d-bfe8-04c02cf068d6",
"eventName": "DeprovisionIpamPoolCidr",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:48:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8b0542a1-420b-48a4-9283-4d5a90b9a9c7",
"requestParameters": {
"DeprovisionIpamPoolCidrRequest": {
"Cidr": "10.99.0.0/16",
"IpamPoolId": "ipam-pool-0b5795c40ef5b6d99"
}
},
"responseElements": {
"DeprovisionIpamPoolCidrResponse": {
"ipamPoolCidr": {
"cidr": "10.99.0.0/16",
"ipamPoolCidrId": "ipam-pool-cidr-00a9fa47cce7f4a0a9bdbda8809e6cc1f",
"netmaskLength": 16,
"state": "pending-deprovision"
},
"requestId": "8b0542a1-420b-48a4-9283-4d5a90b9a9c7",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeprovisionPublicIpv4PoolCidr
#Description
Deprovision a CIDR from a public IPv4 pool.
DeregisterImage
#Description
Deregisters the specified AMI.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "01789781-6054-4dd1-93a6-e9d36c5bbb69",
"eventName": "DeregisterImage",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:12:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "eb9db9ef-5e03-4e05-a8a8-59000b7881cb",
"requestParameters": {
"imageId": "ami-0aa1d83d0b0985c86"
},
"responseElements": {
"_return": true,
"requestId": "eb9db9ef-5e03-4e05-a8a8-59000b7881cb"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DeregisterInstanceEventNotificationAttributes
#Description
Deregisters tag keys to prevent tags that have the specified tag keys from being included in scheduled event notifications for resources in the Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.MissingParameter",
"errorMessage": "The request must include the InstanceTagAttribute parameter. Add the required parameter and retry the request.",
"eventCategory": "Management",
"eventID": "8e3ec28d-5187-4251-a435-bb60525d097e",
"eventName": "DeregisterInstanceEventNotificationAttributes",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:40Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a438e282-7575-4e9a-ad50-3b79dadd382b",
"requestParameters": {
"DeregisterInstanceEventNotificationAttributesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
DeregisterTransitGatewayMulticastGroupMembers
#Description
Deregisters the specified members (network interfaces) from the transit gateway multicast group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.MissingParameter",
"errorMessage": "Missing required parameter in request: TransitGatewayMulticastDomainId.",
"eventCategory": "Management",
"eventID": "939f08ff-0139-469a-a588-c25405f25073",
"eventName": "DeregisterTransitGatewayMulticastGroupMembers",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:45:16Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7f2b25c9-0e18-4fc7-bdca-88ff849bc3f6",
"requestParameters": {
"DeregisterTransitGatewayMulticastGroupMembersRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeregisterTransitGatewayMulticastGroupSources
#Description
Deregisters the specified sources (network interfaces) from the transit gateway multicast group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.MissingParameter",
"errorMessage": "Missing required parameter in request: TransitGatewayMulticastDomainId.",
"eventCategory": "Management",
"eventID": "819b7bce-d739-490f-b957-ea97559ca265",
"eventName": "DeregisterTransitGatewayMulticastGroupSources",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:45:16Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "69bd8d33-a7c4-4f20-ac82-9a0aea3b849c",
"requestParameters": {
"DeregisterTransitGatewayMulticastGroupSourcesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeAccountAttributes
#Description
Describes the specified attribute of your AWS account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "fa6ec09a-d1fc-445c-a77c-c237c87d8339",
"eventName": "DescribeAccountAttributes",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:58:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "5e3170a8-0e1e-4c01-9637-306863f3f2a7",
"requestParameters": {
"accountAttributeNameSet": {},
"filterSet": {}
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "stratus-red-team_631bdcf7-5789-4c2b-9607-f5637f3270cb",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeAddresses
#Description
Describes one or more of your Elastic IP addresses.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "3a8cae4e-43f8-4452-bf1c-860615660cf4",
"eventName": "DescribeAddresses",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "bea051d8-3690-4b3c-8cbf-b47b645c04f3",
"requestParameters": {
"allocationIdsSet": {
"items": [
{
"allocationId": "eipalloc-08a083beb7e83dbc0"
}
]
},
"filterSet": {},
"publicIpsSet": {}
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeAddressesAttribute
#Description
Describes the attributes of the specified Elastic IP addresses.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "9dedbd8b-b72b-4790-9193-ca493a98dcf7",
"eventName": "DescribeAddressesAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:27:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "02800d8a-5455-4be4-9092-32a3c07813d9",
"requestParameters": {
"DescribeAddressesAttributeRequest": {
"Attribute": "domain-name",
"MaxResults": 100
}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCVDQK5XKV",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeAddressTransfers
#Description
Describes an Elastic IP address transfer.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "fd858f23-2611-4ef2-a23f-b06426ac2693",
"eventName": "DescribeAddressTransfers",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:27:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "7cf0a6bf-6a70-4089-ab68-29c08ce745fc",
"requestParameters": {
"DescribeAddressTransfersRequest": {
"MaxResults": 10
}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCVDQK5XKV",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeAggregateIdFormat
#Description
Describes the longer ID format settings for all resource types in a specific Region.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "92878b5f-ad59-4a26-a0aa-fd27de054c2e",
"eventName": "DescribeAggregateIdFormat",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-10-17T20:10:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "2a841885-f382-435c-86f9-e752146e6e8",
"requestParameters": {
"DescribeAggregateIdFormatRequest": {}
},
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeAvailabilityZones
#Description
Describes one or more of the Availability Zones that are available to you.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "a55bb769-64c1-4fe8-bd12-102ab1d0d2bb",
"eventName": "DescribeAvailabilityZones",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:06Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "5f8fd9a4-79dc-416a-80c4-8f9efac1bde0",
"requestParameters": {
"availabilityZoneIdSet": {},
"availabilityZoneSet": {},
"filterSet": {
"items": [
{
"name": "state",
"valueSet": {
"items": [
{
"value": "available"
}
]
}
}
]
}
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeAwsNetworkPerformanceMetricSubscriptions
#Description
Describes the current Infrastructure Performance metric subscriptions.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f7257b28-7c20-4f4c-8205-a386d8cf6c73",
"eventName": "DescribeAwsNetworkPerformanceMetricSubscriptions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "08e84dcc-31a4-4e10-a9a9-8fb73e163fb6",
"requestParameters": {
"DescribeAwsNetworkPerformanceMetricSubscriptionsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeBundleTasks
#Description
Describes one or more of your bundling tasks.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "f0abd03b-f5e3-4003-8146-3d7c321f5b59",
"eventName": "DescribeBundleTasks",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-03-01T07:24:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "035337-3fb7-46b2-ba5e-3b39baa59687",
"requestParameters": {
"bundlesSet": {}
},
"responseElements": null,
"sourceIPAddress": "6.84.9.35",
"userAgent": "aws-cli/1.2.9 Python/3.4.3 Linux/4.4.0-53-generic",
"userIdentity": {
"accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeByoipCidrs
#Description
Describes the IP address ranges that were provisioned for use with Amazon Web Services resources through through bring your own IP addresses (BYOIP).
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.DryRunOperation",
"errorMessage": "Request would have succeeded, but DryRun flag is set.",
"eventID": "39a24e38-a31e-43e1-a522-478201fa6",
"eventName": "DescribeByoipCidrs",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-05-19T17:44:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "db6e8fd3-32cf-41fc-8245-ef205a7d0d4a",
"requestParameters": {
"DescribeByoipCidrsRequest": {
"MaxResults": 1
}
},
"responseElements": null,
"sourceIPAddress": "255.251.4.254",
"userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeCapacityBlockExtensionHistory
#Description
Describes the events for the specified Capacity Block extension during the specified time.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "0ee1219a-47e4-4f1f-a4cf-fb620e246517",
"eventName": "DescribeCapacityBlockExtensionHistory",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "b29db676-8344-45f1-853b-ec7d4dd00a9b",
"requestParameters": {
"DescribeCapacityBlockExtensionHistoryRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeCapacityBlockExtensionOfferings
#Description
Describes Capacity Block extension offerings available for purchase in the Amazon Web Services Region that you're currently using.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidCapacityReservationId.Malformed",
"errorMessage": "The capacity-reservation ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "9ceb6fbe-5ed0-4786-b3c4-11891cb6bc9a",
"eventName": "DescribeCapacityBlockExtensionOfferings",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c53dbaa7-7c92-452d-ba84-8a24560974a9",
"requestParameters": {
"DescribeCapacityBlockExtensionOfferingsRequest": {
"CapacityBlockExtensionDurationHours": 1,
"CapacityReservationId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeCapacityBlockOfferings
#Description
Describes Capacity Block offerings available for purchase in the Amazon Web Services Region that you're currently using.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.MissingParameter",
"errorMessage": "The request must include the InstanceType parameter. Add the required parameter and retry the request.",
"eventCategory": "Management",
"eventID": "99fe1265-8c41-4c39-9315-096867bfb67b",
"eventName": "DescribeCapacityBlockOfferings",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "61773443-d54d-415f-8d62-4b7dbfc539fc",
"requestParameters": {
"DescribeCapacityBlockOfferingsRequest": {
"CapacityDurationHours": 1
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeCapacityBlocks
#Description
Describes details about Capacity Blocks in the Amazon Web Services Region that you're currently using.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.Unsupported",
"errorMessage": "The operation DescribeCapacityBlocks is not supported.",
"eventCategory": "Management",
"eventID": "13cf9949-af6f-4b8d-8cde-23a04f22438b",
"eventName": "DescribeCapacityBlocks",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "86acd2b2-19ea-4445-a002-a5964ced7271",
"requestParameters": {
"DescribeCapacityBlocksRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeCapacityBlockStatus
#Description
Describes the availability of capacity for the specified Capacity blocks, or all of your Capacity Blocks.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.Unsupported",
"errorMessage": "The operation DescribeCapacityBlockStatus is not supported.",
"eventCategory": "Management",
"eventID": "ca59511d-f713-4185-80ee-0a33bc020187",
"eventName": "DescribeCapacityBlockStatus",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "bdfb345f-b450-4e24-9409-31e05bbaabbc",
"requestParameters": {
"DescribeCapacityBlockStatusRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeCapacityManagerDataExports
#Description
Describes one or more Capacity Manager data export configurations.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "22e09d11-2716-41e0-89b2-9a36487e3ff0",
"eventName": "DescribeCapacityManagerDataExports",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "53752a75-6fec-446d-8877-981f3ebe7653",
"requestParameters": {
"DescribeCapacityManagerDataExportsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeCapacityReservationBillingRequests
#Description
Describes a request to assign the billing of the unused capacity of a Capacity Reservation.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f2887cb5-eaa2-4f99-9bef-b724fcf4a21a",
"eventName": "DescribeCapacityReservationBillingRequests",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "a9e387d5-87f3-4a62-ac55-48013f04438f",
"requestParameters": {
"DescribeCapacityReservationBillingRequestsRequest": {
"Role": "odcr-owner"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeCapacityReservationCancellationQuotes
#Description
Describes one or more Capacity Reservation cancellation quotes.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "ef5879b4-4f8e-406c-a078-90b09e141279",
"eventName": "DescribeCapacityReservationCancellationQuotes",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "588faaa6-992b-4e47-be29-08d881f7ef39",
"requestParameters": {
"DescribeCapacityReservationCancellationQuotesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeCapacityReservationFleets
#Description
Describes one or more Capacity Reservation Fleets.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "b514a664-f43a-41ab-9431-22d528300397",
"eventName": "DescribeCapacityReservationFleets",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "406112d9-8a6f-4b23-ad0f-f8f22ac5e1c3",
"requestParameters": {
"DescribeCapacityReservationFleetsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeCapacityReservations
#Description
Describes one or more of your Capacity Reservations.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "79522-0961-4d43-bd95-4d839d78daf9",
"eventName": "DescribeCapacityReservations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2019-07-25T09:40:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "953b4d3e-0b8b-423e-81cd-586198dce38f",
"requestParameters": {
"DescribeCapacityReservationsRequest": {}
},
"responseElements": null,
"sourceIPAddress": "248.251.245.4",
"userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeCapacityReservationTopology
#Description
Describes a tree-based hierarchy that represents the physical host placement of your pending or active Capacity Reservations within an Availability Zone or Local Zone.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "6b904996-7769-41ca-a8e7-408487deb813",
"eventName": "DescribeCapacityReservationTopology",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "bff2d54b-e722-47e6-a095-13f6e75a3561",
"requestParameters": {
"DescribeCapacityReservationTopologyRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeClassicLinkInstances
#Description
Describes one or more of your linked EC2-Classic instances.
Example CloudTrail Event #
{
"awsRegion": "eu-west-1",
"eventID": "60c87c94-8933-4e86-ae8c-afac72dc31d9",
"eventName": "DescribeClassicLinkInstances",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-02-28T17:46:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "1c2b760b-654e-4441-89ec-5fa5c09eb810",
"requestParameters": {
"filterSet": {},
"instancesSet": {}
},
"responseElements": null,
"sourceIPAddress": "254.135.184.250",
"userAgent": "aws-cli/1.11.35 Python/2.7.12 Darwin/16.4.0 botocore/1.4.92",
"userIdentity": {
"accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeClientVpnConnections
#Description
Describes active client connections and connections that have been terminated within the last 60 minutes for the specified Client VPN endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.DryRunOperation",
"errorMessage": "Request would have succeeded, but DryRun flag is set.",
"eventID": "327892-7b88-44c3-8cfd-f4cfde7ecc98",
"eventName": "DescribeClientVpnConnections",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-05-19T17:44:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "c486cf9f-955e-44b8-b8ba-e246802bb093",
"requestParameters": {
"DescribeClientVpnConnectionsRequest": {
"ClientVpnEndpointId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "255.251.4.254",
"userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeClientVpnEndpoints
#Description
Describes one or more Client VPN endpoints in the account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "3846ce81-1a49-44f7-869e-55d27d2b44ee",
"eventName": "DescribeClientVpnEndpoints",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2019-07-25T09:40:56Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "72af6199-07ae-46ac-b2f9-c2e01543b7e",
"requestParameters": {
"DescribeClientVpnEndpointsRequest": {}
},
"responseElements": null,
"sourceIPAddress": "248.251.245.4",
"userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeClientVpnTargetNetworks
#Description
Describes the target networks associated with the specified Client VPN endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.DryRunOperation",
"errorMessage": "Request would have succeeded, but DryRun flag is set.",
"eventID": "c4ca512e-adb8-4280-af9f-e2ea68aa34c0",
"eventName": "DescribeClientVpnTargetNetworks",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-05-19T17:44:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "286ed344-df7e-405c-befd-cf54af47a6b4",
"requestParameters": {
"DescribeClientVpnTargetNetworksRequest": {
"ClientVpnEndpointId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "255.251.4.254",
"userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeCoipPools
#Description
Describes the specified customer-owned address pools or all of your customer-owned address pools.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "9553e556-22e0-4eed-bd8d-6fdfa08be86e",
"eventName": "DescribeCoipPools",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-06-10T05:33:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "a443bdd8-072e-48bb-9ed2-7859fd54baaf",
"requestParameters": {
"DescribeCoipPoolsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeConversionTasks
#Description
Describes one or more of your conversion tasks.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "4903dd5d-37f9-419f-8b19-74c172425ccf9",
"eventName": "DescribeConversionTasks",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-03-01T07:24:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "b833f6e1-cf38-4d57-a2f6-01e9b49f0745",
"requestParameters": {
"conversionTaskIdSet": {}
},
"responseElements": null,
"sourceIPAddress": "6.84.9.35",
"userAgent": "aws-cli/1.2.9 Python/3.4.3 Linux/4.4.0-53-generic",
"userIdentity": {
"accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeCustomerGateways
#Description
Describes one or more of your VPN customer gateways.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "98c26f33-85cf-418f-92b0-cac6110464f8",
"eventName": "DescribeCustomerGateways",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:13:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "29a87e28-7b61-4d55-82e6-73cb7d16b257",
"requestParameters": {
"customerGatewaySet": {},
"filterSet": {}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCSUD2OWV6",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:13:16Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeDeclarativePoliciesReports
#Description
Describes the metadata of an account status report, including the status of the report.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "9c4a101a-3779-4ad1-9a7f-56ec634a5d2d",
"eventName": "DescribeDeclarativePoliciesReports",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "a71fa7cc-45cd-4bad-8867-6372902b4737",
"requestParameters": {
"DescribeDeclarativePoliciesReportsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeEgressOnlyInternetGateways
#Description
Describes your egress-only internet gateways.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "6a69e15e-511f-4845-8b88-bd4b598331ef",
"eventName": "DescribeEgressOnlyInternetGateways",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:13:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "6818af6a-6d67-4538-82ef-8aa25863c779",
"requestParameters": {
"DescribeEgressOnlyInternetGatewaysRequest": {
"MaxResults": 255
}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCSUD2OWV6",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:13:16Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeElasticGpus
#Description
Amazon Elastic Graphics reached end of life on January 8, 2024.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "14aee4e1-22c2-4dda-b9a7-b12c268d005e",
"eventName": "DescribeElasticGpus",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-10-17T20:10:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "3e6410d9-ca0b-416a-88c6-83fa9398b8d8",
"requestParameters": {
"DescribeElasticGpusRequest": {}
},
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeExportImageTasks
#Description
Describes the specified export image tasks or all of your export image tasks.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "f598ba0f-3226-4c32-8454-6b69fc210174a",
"eventName": "DescribeExportImageTasks",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-06-10T05:33:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "5ae57b81-d645-4486-9499-84fd11210",
"requestParameters": {
"DescribeExportImageTasksRequest": ""
},
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeExportTasks
#Description
Describes one or more of your export tasks.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "fcb548b7-5afe-4db6-a954-6f59cbf6d488",
"eventName": "DescribeExportTasks",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-02-27T19:35:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "7d908292-ea81-4a09-bdad-60fb36c7ab9e",
"requestParameters": {
"exportTaskIdSet": {}
},
"responseElements": null,
"sourceIPAddress": "5.165.77.250",
"userAgent": "aws-cli/1.5.2 Python/2.7.8 Linux/4.9.0-1-amd64",
"userIdentity": {
"accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeFastLaunchImages
#Description
Describe details for Windows AMIs that are configured for Windows fast launch.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "ce6752e1-cd18-4199-8ec1-d7fd84f7f341",
"eventName": "DescribeFastLaunchImages",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "34a481ac-55ad-443b-b3b7-d87f89e1d119",
"requestParameters": {
"DescribeFastLaunchImagesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeFastSnapshotRestores
#Description
Describes the state of fast snapshot restores for your snapshots.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "3500dc4f-4bb6-4da5-93fd-023a4ca86d83",
"eventName": "DescribeFastSnapshotRestores",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-02-21T09:23:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "3a2546f6-f459-44fe-ad64-b7e7888db954",
"requestParameters": {
"DescribeFastSnapshotRestoresRequest": ""
},
"responseElements": null,
"sourceIPAddress": "240.5.57.4",
"userAgent": "aws-cli/2.0.0 Python/3.8.1 Darwin/19.3.0 botocore/2.0.0dev4",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeFleetHistory
#Description
Describes the events for the specified EC2 Fleet during the specified time.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.DryRunOperation",
"errorMessage": "Request would have succeeded, but DryRun flag is set.",
"eventID": "06c9d340-32f5-4f5f-b1dd-1f7554e23150",
"eventName": "DescribeFleetHistory",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-11-10T12:01:36Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "06d588293-0edc-4287-a1d4-a667b3241c5d",
"requestParameters": {
"DescribeFleetHistoryRequest": {
"FleetId": "dummy_data",
"StartTime": "2015-01-01T00:00:00Z"
}
},
"responseElements": null,
"sourceIPAddress": "43.254.0.31",
"userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeFleetInstances
#Description
Describes the running instances for the specified EC2 Fleet.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.DryRunOperation",
"errorMessage": "Request would have succeeded, but DryRun flag is set.",
"eventID": "b401b390-fbce-44f3-b695-ee05eae8340f",
"eventName": "DescribeFleetInstances",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-11-10T12:01:36Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "aa8454c3-b1ec-46b5-a0c9-ea1692e694c8",
"requestParameters": {
"DescribeFleetInstancesRequest": {
"FleetId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "43.254.0.31",
"userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeFleets
#Description
Describes the specified EC2 Fleet or all of your EC2 Fleets.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "dd373de5-8f18-4898-a1e6-e75bad8e13a2",
"eventName": "DescribeFleets",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-08-06T19:50:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "49def88c-348e-448d-b8d5-2bdf68431c9",
"requestParameters": {
"DescribeFleetsRequest": {}
},
"responseElements": null,
"sourceIPAddress": "139.235.254.142",
"userAgent": "aws-cli/1.15.71 Python/2.7.15 Linux/4.17.10-1-ARCH botocore/1.10.70",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeFlowLogs
#Description
Describes one or more flow logs.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "65b25319-3e2c-42ed-9fa3-382717bac4ab",
"eventName": "DescribeFlowLogs",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:02:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "5cf34e84-b96d-4e60-8f9a-2dc874da3bea",
"requestParameters": {
"DescribeFlowLogsRequest": {
"FlowLogId": {
"content": "fl-064ed3a785e4a37ef",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_20f9795b-aa02-4c8e-bad6-bd338ec09f59 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeFpgaImageAttribute
#Description
Describes the specified attribute of the specified Amazon FPGA Image (AFI).
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.DryRunOperation",
"errorMessage": "Request would have succeeded, but DryRun flag is set.",
"eventID": "5245f94c-2237-4056-9f84-e3b7a7fa8274",
"eventName": "DescribeFpgaImageAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-11-10T12:01:37Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "818326d8b-6e4c-41a0-83f1-03d002a9a6d0",
"requestParameters": {
"DescribeFpgaImageAttributeRequest": {
"Attribute": "dummy_data",
"FpgaImageId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "43.254.0.31",
"userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeFpgaImages
#Description
Describes the Amazon FPGA Images (AFIs) available to you.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "2453e8fe-36fa-489a-b29d-113bbc1cd696",
"eventName": "DescribeFpgaImages",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-10-17T20:10:56Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "1bb167c0-88da-42b6-a9d0-2093deccad61",
"requestParameters": {
"DescribeFpgaImagesRequest": {}
},
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeHostReservationOfferings
#Description
Describes the Dedicated Host Reservations that are available to purchase.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "a16177f4-c88e-45eb-bf18-fbea502d1f52",
"eventName": "DescribeHostReservationOfferings",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-11-10T12:01:37Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "19db836a-b08e-4cf1-b618-9ece516493",
"requestParameters": {
"DescribeHostReservationOfferingsRequest": {}
},
"responseElements": null,
"sourceIPAddress": "43.254.0.31",
"userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeHostReservations
#Description
Describes Dedicated Host Reservations which are associated with Dedicated Hosts in your account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "4183d95a-ee1f-42db-b9f5-f129bfcee95e",
"eventName": "DescribeHostReservations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-03-11T18:16:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "f11b42df-cf78-4f88-ac33-185dac60cbea",
"requestParameters": {
"DescribeHostReservationsRequest": {}
},
"responseElements": null,
"sourceIPAddress": "34.7.241.251",
"userAgent": "aws-cli/1.10.67 Python/2.7.10 Darwin/16.4.0 botocore/1.4.93",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeHosts
#Description
Describes one or more of your Dedicated hosts.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "267926fc-8510-493d-8c33-91a780c7225e",
"eventName": "DescribeHosts",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:27:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "ca8ead57-9da9-4b3a-ac03-6931b4be37fd",
"requestParameters": {
"DescribeHostsRequest": {
"MaxResults": 500
}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCVDQK5XKV",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeIamInstanceProfileAssociations
#Description
Describes your IAM instance profile associations.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "162c4abf-b247-4276-beb5-cb457514b0b6",
"eventName": "DescribeIamInstanceProfileAssociations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-12-13T23:52:34Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "09d9bd8f-0f41-4a2d-b805-446583db9042",
"requestParameters": {
"DescribeIamInstanceProfileAssociationsRequest": {}
},
"responseElements": null,
"sourceIPAddress": "121.206.185.1",
"userAgent": "aws-cli/1.11.190 Python/3.6.3 Darwin/16.7.0 botocore/1.7.48",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeIdentityIdFormat
#Description
Describes the ID format settings for resources for the specified IAM user, IAM role, or root user.
Example CloudTrail Event #
{
"awsRegion": "eu-west-1",
"errorCode": "Client.InvalidTargetArn.Unknown",
"errorMessage": "Invalid TargetArn: missing parameter",
"eventID": "9ce28d14-9443-413c-8017-c375e53e0c7b",
"eventName": "DescribeIdentityIdFormat",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-07-15T12:21:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "88bb488d-5cfc-4dd0-9a7d-a71aa70fa8ff",
"requestParameters": {
"DescribeIdentityIdFormatRequest": {}
},
"responseElements": null,
"sourceIPAddress": "173.114.134.8",
"userAgent": "AWSPowerShell/74.36.54.6 .NET_Runtime/4.0 .NET_Framework/4.0 OS/Microsoft_Windows_NT_10.0.814599.0 WindowsPowerShell/5.0 ClientSync",
"userIdentity": {
"accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeIdFormat
#Description
Describes the ID format settings for your resources on a per-region basis, for example, to view which resource types are enabled for longer IDs.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "a972063bf-a9ae-47b8-a270-0fc91fde6ff7",
"eventName": "DescribeIdFormat",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-02-12T20:45:05Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "047083a-1fc0-4891-8796-3a6c92a8ac42",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "255.253.125.115",
"userAgent": "console.ec2.amazonaws.com",
"userIdentity": {
"accessKeyId": "ASIAIB6AB67SP5RKU9Z4",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:root",
"principalId": "811596193553",
"sessionContext": {
"attributes": {
"creationDate": "2017-02-12T19:57:05Z",
"mfaAuthenticated": "false"
}
},
"type": "Root"
}
}
References #
DescribeImageAttribute
#Description
Describes the specified attribute of the specified AMI.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "Client.InvalidAMIID.Malformed",
"errorMessage": "Invalid id: \"snap-83d15d668fb2941db\" (expecting \"ami-...\")",
"eventID": "6e4bae95-48b7-47fc-aa36-f23e54469ed",
"eventName": "DescribeImageAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-05-17T14:29:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "01a1749e-3ac0-41b5-b973-da0c3082f44a",
"requestParameters": {
"attributeType": "launchPermission",
"imageId": "snap-83d15d668fb2941db"
},
"responseElements": null,
"sourceIPAddress": "252.250.127.237",
"userAgent": "AWSPowerShell/251.194.70.74 .NET_Runtime/4.0 .NET_Framework/4.0 OS/Microsoft_Windows_NT_10.0.17369.0 WindowsPowerShell/5.0 ClientSync",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeImageReferences
#Description
Describes your Amazon Web Services resources that are referencing the specified images.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidAMIID.Malformed",
"errorMessage": "One or more ImageIds isn't valid. Verify that each ImageId is in the correct format and try again.",
"eventCategory": "Management",
"eventID": "3d0fb1cc-e628-4b10-be92-5df5a1700bb9",
"eventName": "DescribeImageReferences",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "1aa78771-5677-4c96-8d97-ff439aeecb75",
"requestParameters": {
"DescribeImageReferencesRequest": {
"ImageId": {
"content": "dw-probe",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeImageUsageReportEntries
#Description
Describes the entries in image usage reports, showing how your images are used across other Amazon Web Services accounts.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "a4f24aaf-fd9b-47a8-8e74-3de4c98322a4",
"eventName": "DescribeImageUsageReportEntries",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "78c3c02e-fdc1-4d3b-a6b8-20c4036c0f59",
"requestParameters": {
"DescribeImageUsageReportEntriesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeImageUsageReports
#Description
Describes the configuration and status of image usage reports, filtered by report IDs or image IDs.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "fc0f5802-8115-40d0-b56c-8fb7b61ac6be",
"eventName": "DescribeImageUsageReports",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "cf8bf414-e162-48f6-80b2-ea1481c23ff1",
"requestParameters": {
"DescribeImageUsageReportsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeImportImageTasks
#Description
Displays details about an import virtual machine or import snapshot tasks that are already created.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "dfd02eb3-ce0f-415d-911d-11b111f3e0d6",
"eventName": "DescribeImportImageTasks",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2019-03-31T22:08:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "c7e284806-135d-464f-9b5a-4bcee5db2f6a",
"requestParameters": {
"maxResults": 0
},
"responseElements": null,
"sourceIPAddress": "ec2-frontend-api.amazonaws.com",
"userAgent": "ec2-frontend-api.amazonaws.com",
"userIdentity": {
"accessKeyId": "ASIAE8B2KJPFIJXCU8Z8",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"invokedBy": "ec2-frontend-api.amazonaws.com",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"sessionContext": {
"attributes": {
"creationDate": "2019-03-31T22:08:55Z",
"mfaAuthenticated": "false"
}
},
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeImportSnapshotTasks
#Description
Displays details about an import snapshot tasks that is already created.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "6a39a1b4-57e9-417b-8fd2-2b364811f9b",
"eventName": "DescribeImportSnapshotTasks",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2019-03-31T22:08:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "6c613cb9-12ff-43f7-a5fa-4d7a5d5e4fdc",
"requestParameters": {
"maxResults": 0
},
"responseElements": null,
"sourceIPAddress": "ec2-frontend-api.amazonaws.com",
"userAgent": "ec2-frontend-api.amazonaws.com",
"userIdentity": {
"accessKeyId": "ASIAE8B2KJPFIJXCU8Z8",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"invokedBy": "ec2-frontend-api.amazonaws.com",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"sessionContext": {
"attributes": {
"creationDate": "2019-03-31T22:08:55Z",
"mfaAuthenticated": "false"
}
},
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeInstanceConnectEndpoints
#Description
Describes the specified EC2 Instance Connect Endpoints or all EC2 Instance Connect Endpoints.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "95c63342-02af-4f04-9b28-ef11a3c1f777",
"eventName": "DescribeInstanceConnectEndpoints",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "dea730d2-2e6a-46b7-bfd9-9d9a90653520",
"requestParameters": {
"DescribeInstanceConnectEndpointsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeInstanceCreditSpecifications
#Description
Describes the credit option for CPU usage of the specified burstable performance instances.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "7af60355-a727-4b2a-bec1-81ff36c9616f",
"eventName": "DescribeInstanceCreditSpecifications",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "d0fd33cb-ee3e-4fd3-a50f-b49b61ddf92e",
"requestParameters": {
"DescribeInstanceCreditSpecificationsRequest": {
"InstanceId": {
"content": "i-0dbc91f429e48eeed",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeInstanceEventNotificationAttributes
#Description
Describes the tag keys that are registered to appear in scheduled event notifications for resources in the current Region.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "555632f1-9398-49d9-983d-5e8f808c9944",
"eventName": "DescribeInstanceEventNotificationAttributes",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-06-10T05:33:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "61768a9-f452-43d2-a5c1-6f72afc5cb49",
"requestParameters": {
"DescribeInstanceEventNotificationAttributesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeInstanceEventWindows
#Description
Describes the specified event windows or all event windows.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "cf83f0b5-72aa-43d9-bfac-bbebea2846f8",
"eventName": "DescribeInstanceEventWindows",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "041894a3-2e21-4a53-9ee0-6712d6bf557f",
"requestParameters": {
"DescribeInstanceEventWindowsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeInstanceImageMetadata
#Description
Describes the AMI that was used to launch an instance, even if the AMI is deprecated, deregistered, made private (no longer public or shared with your account), or not allowed.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "c9b7176d-88d2-4f26-8d5c-a3b8343fb494",
"eventName": "DescribeInstanceImageMetadata",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "df909cb7-1465-4545-a1ab-7cb7d7ded2c5",
"requestParameters": {
"DescribeInstanceImageMetadataRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeInstanceSqlHaHistoryStates
#Description
Describes the historical SQL Server High Availability states for Amazon EC2 instances that are enabled for Amazon EC2 High Availability for SQL Server monitoring.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "7aec14f3-bcd5-45ba-b074-2a49c636b890",
"eventName": "DescribeInstanceSqlHaHistoryStates",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "9bb233da-66d3-4c7b-88ae-76564fb3600f",
"requestParameters": {
"DescribeInstanceSqlHaHistoryStatesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeInstanceSqlHaStates
#Description
Describes the SQL Server High Availability states for Amazon EC2 instances that are enabled for Amazon EC2 High Availability for SQL Server monitoring.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "26fec21d-86d7-4a4f-9e37-074ffef8bb90",
"eventName": "DescribeInstanceSqlHaStates",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "cd0b83be-6645-4076-8c6d-396f21382ae2",
"requestParameters": {
"DescribeInstanceSqlHaStatesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeInstanceStatus
#Description
Describes the status of one or more instances, including any scheduled events.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "0cdb9fc4-c1e9-4260-ac1b-ac14e0840711",
"eventName": "DescribeInstanceStatus",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:27:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "6a06b21b-0fae-4259-8ad8-574db29ac93f",
"requestParameters": {
"filterSet": {},
"includeAllInstances": false,
"instancesSet": {},
"maxResults": 1000
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCVDQK5XKV",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeInstanceTopology
#Description
Describes a tree-based hierarchy that represents the physical host placement of your EC2 instances within an Availability Zone or Local Zone.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "b9bd82ff-7f71-42c1-a503-2fb156602247",
"eventName": "DescribeInstanceTopology",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "1d920ce7-ff3c-4cb9-9ec8-0336889b6550",
"requestParameters": {
"DescribeInstanceTopologyRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeInstanceTypeOfferings
#Description
Lists the instance types that are offered for the specified location.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "4a2c4a02-06b1-4588-b5d2-4fa638fc4ef4",
"eventName": "DescribeInstanceTypeOfferings",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-06-10T05:33:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "e45b1bb9-bd11-4847-838d-0df164fb4af3",
"requestParameters": {
"DescribeInstanceTypeOfferingsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeInstanceTypes
#Description
Describes the specified instance types.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "5e17e922-0865-4b9c-9336-ef69d9d9c26a",
"eventName": "DescribeInstanceTypes",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-07-07T15:53:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "8f3f93fa-9ad3-4642-85c8-9f83a30dc688",
"requestParameters": {
"DescribeInstanceTypesRequest": {
"MaxResults": 100,
"NextToken": "AAIAATpzTWe8z_qcoCCUkmj1wtgqXR5BJ5Ti94_a3MAjkKF8HZX9iGjRHll2G5_WE29BpU6hdR2D4JhZHlmBis56ItbXiBYBLs-07p4xSwLCXDLVuXRzO6l4FKLWvNBXq5Ovi-1hcpovbmDe7zyQsw6kHL0uoJM_BDUc8u0="
}
},
"responseElements": null,
"sourceIPAddress": "167.98.108.182",
"userAgent": "EC2ConsoleFrontend, aws-internal/3 aws-sdk-java/1.11.1030 Linux/5.4.122-66.218.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/25.292-b10 java/1.8.0_292 vendor/Oracle_Corporation cfg/retry-mode/legacy",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI37YFF5PNWP",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/sean",
"principalId": "AIDA3TLZJI375TCG5FSRI",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:56:28Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "sean"
}
}
References #
DescribeInternetGateways
#Description
Describes one or more of your Internet gateways.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "7b306a05-b01e-4f83-ba04-55f0416c887e",
"eventName": "DescribeInternetGateways",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:13:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "6587233b-552f-4e60-9cb7-6b4b85617ead",
"requestParameters": {
"filterSet": {},
"internetGatewayIdSet": {},
"maxResults": 1000
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCSUD2OWV6",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:13:16Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeIpamByoasn
#Description
Describes your Autonomous System Numbers (ASNs), their provisioning statuses, and the BYOIP CIDRs with which they are associated.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "79359508-075d-4fb7-baaa-3260a1d7f89a",
"eventName": "DescribeIpamByoasn",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "b3490651-0cc1-4a91-b251-22e4ade3458a",
"requestParameters": {
"DescribeIpamByoasnRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeIpamExternalResourceVerificationTokens
#Description
Describe verification tokens.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "e130a008-4ffa-40ea-884c-457ad0b676c4",
"eventName": "DescribeIpamExternalResourceVerificationTokens",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "8074d889-87d3-4f95-b453-7cf9ce0eb77f",
"requestParameters": {
"DescribeIpamExternalResourceVerificationTokensRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeIpamPolicies
#Description
Describes one or more IPAM policies.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "830eb3e4-9d87-4707-9250-2c0a7ea528c4",
"eventName": "DescribeIpamPolicies",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "f279e8fc-a342-4ea8-928d-072c2d0d6748",
"requestParameters": {
"DescribeIpamPoliciesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeIpamPoolAllocations
#Description
Describes IPAM pool allocations.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "7d65a0d5-4dc6-49e5-bc69-18dad44e4d81",
"eventName": "DescribeIpamPoolAllocations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "e93f394b-eda2-4803-b271-b3cb9f6b0e36",
"requestParameters": {
"DescribeIpamPoolAllocationsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeIpamPools
#Description
Get information about your IPAM pools.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "a92e63cf-fc9c-4d20-b026-cf66f7806ef9",
"eventName": "DescribeIpamPools",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "5f58d047-eea1-40be-a5e1-9daf49a12bba",
"requestParameters": {
"DescribeIpamPoolsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeIpamPrefixListResolvers
#Description
Describes one or more IPAM prefix list resolvers.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "478e93ff-a10a-46c0-8c13-25bbaa14f5a5",
"eventName": "DescribeIpamPrefixListResolvers",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "bf3ca8a4-83da-49de-b9ec-1abd686696f9",
"requestParameters": {
"DescribeIpamPrefixListResolversRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeIpamPrefixListResolverTargets
#Description
Describes one or more IPAM prefix list resolver Targets.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "aa803630-4cf8-499c-9347-b742c1abf141",
"eventName": "DescribeIpamPrefixListResolverTargets",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "575b3c91-65ed-4979-bbbb-7ac073cd73d4",
"requestParameters": {
"DescribeIpamPrefixListResolverTargetsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeIpamResourceDiscoveries
#Description
Describes IPAM resource discoveries.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "dcb4a5a3-c730-424e-9c67-0f67b489743b",
"eventName": "DescribeIpamResourceDiscoveries",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "a8c3dc5a-cae8-4051-b890-870aaf5b948b",
"requestParameters": {
"DescribeIpamResourceDiscoveriesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeIpamResourceDiscoveryAssociations
#Description
Describes resource discovery association with an Amazon VPC IPAM.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "58020c4b-0810-48f3-abf4-05595ea6470b",
"eventName": "DescribeIpamResourceDiscoveryAssociations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "7dddd133-fc68-4be1-a35e-f1c39af2a65f",
"requestParameters": {
"DescribeIpamResourceDiscoveryAssociationsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeIpams
#Description
Get information about your IPAM pools.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "0c0314e4-1297-45b2-b391-2fb456a1dfe9",
"eventName": "DescribeIpams",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "5b140852-9ee1-4e50-9f3d-22c5c5ebbb1d",
"requestParameters": {
"DescribeIpamsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeIpamScopes
#Description
Get information about your IPAM scopes.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "7b433525-08fb-458d-8f10-4fd02400731f",
"eventName": "DescribeIpamScopes",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "eaec0423-9965-4559-b738-11df8f9e118c",
"requestParameters": {
"DescribeIpamScopesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeIpv6Pools
#Description
Describes your IPv6 address pools.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "2a44f0f2-2e2a-4798-bab4-b67e866030db6",
"eventName": "DescribeIpv6Pools",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-06-10T05:33:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "14777b7-343f-4b33-8201-c8a5e6e1bb81",
"requestParameters": {
"DescribeIpv6PoolsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeKeyPairs
#Description
Describes one or more of your key pairs.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "630674b4-e51d-4763-9f4d-9f5de2cb208f",
"eventName": "DescribeKeyPairs",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:27:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "1f88696d-5c9e-4420-a649-e37b6e067cb9",
"requestParameters": {
"filterSet": {},
"includePublicKey": false,
"keyPairIdSet": {},
"keySet": {}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCVDQK5XKV",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeLaunchTemplates
#Description
Describes one or more launch templates.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "1ca249de-b9db-4596-bb50-3e69955cb99b",
"eventName": "DescribeLaunchTemplates",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:27:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "18f89994-83cd-4cf6-83e0-b4c7dcc73987",
"requestParameters": {
"DescribeLaunchTemplatesRequest": {
"MaxResults": 1
}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCVDQK5XKV",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeLaunchTemplateVersions
#Description
Describes one or more versions of a specified launch template.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "8deb3cde-6b2f-4313-95dc-f491f3bcff3b",
"eventName": "DescribeLaunchTemplateVersions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-07-07T13:25:33Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "bc967c75-879a-4c90-a1b2-7c22f973be95",
"requestParameters": {
"DescribeLaunchTemplateVersionsRequest": {
"LaunchTemplateId": "lt-0c29f947cb42c3e34",
"LaunchTemplateVersion": {
"content": 1,
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "eks-nodegroup.amazonaws.com",
"userAgent": "eks-nodegroup.amazonaws.com",
"userIdentity": {
"accountId": "797507667711",
"arn": "arn:aws:sts::797507667711:assumed-role/AWSServiceRoleForAmazonEKSNodegroup/EKS",
"invokedBy": "eks-nodegroup.amazonaws.com",
"principalId": "AROA3TLZJI37WARU2V5OV:EKS",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T13:25:33Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:role/aws-service-role/eks-nodegroup.amazonaws.com/AWSServiceRoleForAmazonEKSNodegroup",
"principalId": "AROA3TLZJI37WARU2V5OV",
"type": "Role",
"userName": "AWSServiceRoleForAmazonEKSNodegroup"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
References #
DescribeLocalGatewayRouteTables
#Description
Describes one or more local gateway route tables.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "a6baa8eb-cce8-4c83-893c-bd13fd47238b",
"eventName": "DescribeLocalGatewayRouteTables",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-06-10T05:33:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "1f2678f1-0668-49a3-817d-f8ea1aaffe5c",
"requestParameters": {
"DescribeLocalGatewayRouteTablesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociations
#Description
Describes the associations between virtual interface groups and local gateway route tables.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "1beeaddf-6860-4c14-ba8d-64e531e76131",
"eventName": "DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-06-10T05:33:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "7812e8f5-dbbf-458d-b4b1-154ab141902e",
"requestParameters": {
"DescribeLocalGatewayRouteTableVirtualInterfaceGroupAssociationsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeLocalGatewayRouteTableVpcAssociations
#Description
Describes the specified associations between VPCs and local gateway route tables.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "33f6314d-8e08-4774-9070-89e605efe229",
"eventName": "DescribeLocalGatewayRouteTableVpcAssociations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-06-10T05:33:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "433b6c25-441d-4746-9ed0-6bd241ffb295",
"requestParameters": {
"DescribeLocalGatewayRouteTableVpcAssociationsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeLocalGateways
#Description
Describes one or more local gateways.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "e3b4a7ad-8c8c-4a8a-8152-72f398560d99",
"eventName": "DescribeLocalGateways",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-06-10T05:33:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "61ac20e5-7907-40a4-8289-284ca9669ab5",
"requestParameters": {
"DescribeLocalGatewaysRequest": ""
},
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeLocalGatewayVirtualInterfaceGroups
#Description
Describes the specified local gateway virtual interface groups.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "ca31e918-a341-4c23-b2e1-38d4a321b2e2",
"eventName": "DescribeLocalGatewayVirtualInterfaceGroups",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-06-10T05:33:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "9761cfd0-3c92-43cb-ac10-c1099d0337d5",
"requestParameters": {
"DescribeLocalGatewayVirtualInterfaceGroupsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeLocalGatewayVirtualInterfaces
#Description
Describes the specified local gateway virtual interfaces.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "65eacfbb-4907-4f51-a57b-58814c94585f",
"eventName": "DescribeLocalGatewayVirtualInterfaces",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-06-10T05:33:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "e54468-d2ad-48b7-a11f-f465933706d4",
"requestParameters": {
"DescribeLocalGatewayVirtualInterfacesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeLockedSnapshots
#Description
Describes the lock status for a snapshot.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "0a09c547-cc37-48cc-97a0-cee9267b6137",
"eventName": "DescribeLockedSnapshots",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "1947e8cb-907b-4e97-a25e-24a77d32a8bc",
"requestParameters": {
"DescribeLockedSnapshotsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeMacHosts
#Description
Describes the specified EC2 Mac Dedicated Host or all of your EC2 Mac Dedicated Hosts.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.UnsupportedOperation",
"errorMessage": "The functionality you requested is not available in this region.",
"eventCategory": "Management",
"eventID": "4613947f-af0f-4fb7-b585-890887406e87",
"eventName": "DescribeMacHosts",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "1fa7ac9f-4615-4ede-afb6-767ed3ace67c",
"requestParameters": {
"DescribeMacHostsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeMacModificationTasks
#Description
Describes a System Integrity Protection (SIP) modification task or volume ownership delegation task for an Amazon EC2 Mac instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.UnsupportedOperation",
"errorMessage": "The functionality you requested is not available in this region.",
"eventCategory": "Management",
"eventID": "449e73f9-01e9-461b-a135-c524e2a78364",
"eventName": "DescribeMacModificationTasks",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "ccd9bc9a-7fc4-4a71-bc13-4fd4f50b3c93",
"requestParameters": {
"DescribeMacModificationTasksRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeManagedPrefixLists
#Description
Describes your managed prefix lists and any Amazon Web Services-managed prefix lists.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "acba087b-740d-40db-9033-3205f831f5c9",
"eventName": "DescribeManagedPrefixLists",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-07-07T18:47:11Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "b8c893e2-7e4c-4ffd-baa0-36b7774c56f8",
"requestParameters": {
"DescribeManagedPrefixListsRequest": {
"MaxResults": 100
}
},
"responseElements": null,
"sourceIPAddress": "213.205.197.211",
"userAgent": "console.ec2.amazonaws.com",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI376AFGRVSZ",
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:user/bruce",
"principalId": "AIDA3TLZJI372XH6M2Q25",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T11:45:11Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bruce"
}
}
References #
DescribeMovingAddresses
#Description
Describes your Elastic IP addresses that are being moved to the EC2-VPC platform, or that are being restored to the EC2-Classic platform.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "689cbcaa-1e21-4cab-b7fb-5151726c747e",
"eventName": "DescribeMovingAddresses",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-09-11T17:35:40Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "87a2bea9-fabd-4080-bd28-a2f10043c09a",
"requestParameters": {
"DescribeMovingAddressesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "60.219.252.71",
"userAgent": "Boto3/1.14.28 Python/3.8.5 Linux/5.7.0-kali1-amd64 Botocore/1.17.28",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeNatGateways
#Description
Describes one or more of the your NAT gateways.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "1b729f93-cc5b-4654-9e51-b48edb9c6f51",
"eventName": "DescribeNatGateways",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "219910a0-cfb2-4fb8-adc0-c0a3d00d9cf2",
"requestParameters": {
"DescribeNatGatewaysRequest": {
"NatGatewayId": {
"content": "nat-03575abbac42080d9",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeNetworkAcls
#Description
Describes one or more of your network ACLs.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "fecbf813-f665-4af7-b373-8e30480930ee",
"eventName": "DescribeNetworkAcls",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:14:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "be259a68-d2ee-4bd0-b166-bbdf20108a36",
"requestParameters": {
"filterSet": {},
"maxResults": 1000,
"networkAclIdSet": {}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCSUD2OWV6",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:13:16Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeNetworkInsightsAccessScopeAnalyses
#Description
Describes the specified Network Access Scope analyses.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "6c2e391f-ca9b-49ed-a2bc-c95e80e57df9",
"eventName": "DescribeNetworkInsightsAccessScopeAnalyses",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "50705cfc-17ba-4d09-8726-9893e4d87dbd",
"requestParameters": {
"DescribeNetworkInsightsAccessScopeAnalysesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeNetworkInsightsAccessScopes
#Description
Describes the specified Network Access Scopes.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "cce08680-9486-470e-bccd-e31bf928c69f",
"eventName": "DescribeNetworkInsightsAccessScopes",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "5c869992-b76a-44ad-83a7-017b3bfab20d",
"requestParameters": {
"DescribeNetworkInsightsAccessScopesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeNetworkInsightsAnalyses
#Description
Describes one or more of your network insights analyses.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "7922b6a5-d5d5-4b1e-b6dc-fb2d85cfe4f3",
"eventName": "DescribeNetworkInsightsAnalyses",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "83256056-fa1b-44af-8a93-65a5657c39fd",
"requestParameters": {
"DescribeNetworkInsightsAnalysesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeNetworkInsightsPaths
#Description
Describes one or more of your paths.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "8ae607e6-321e-4f0d-86d6-c47cc45c9e9f",
"eventName": "DescribeNetworkInsightsPaths",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "9a98d372-b390-4fc1-a137-d26ba370e9b3",
"requestParameters": {
"DescribeNetworkInsightsPathsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeNetworkInterfaceAttribute
#Description
Describes a network interface attribute.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "3735a088-29a1-480a-ab4f-c907d6ef3584",
"eventName": "DescribeNetworkInterfaceAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-06-27T13:27:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "ac9e730c-7908-4571-a6e4-b8c513acc37a",
"requestParameters": {
"networkInterfaceId": "eni-f6ffd558"
},
"responseElements": null,
"sourceIPAddress": "127.3.73.208",
"userAgent": "aws-cli/1.18.46 Python/3.7.7 Linux/5.4.0-kali4-amd64 botocore/1.15.46",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeNetworkInterfacePermissions
#Description
Describes the permissions for your network interfaces.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "1420d649-a3d0-4860-a1d2-7aad696f3357",
"eventName": "DescribeNetworkInterfacePermissions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-12-13T23:56:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "14caf7d1-8a04-4b5f-b18c-3fbddf30bc11",
"requestParameters": {
"DescribeNetworkInterfacePermissionsRequest": {}
},
"responseElements": null,
"sourceIPAddress": "121.206.185.1",
"userAgent": "aws-cli/1.11.190 Python/3.6.3 Darwin/16.7.0 botocore/1.7.48",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeNetworkInterfaces
#Description
Describes one or more of your network interfaces.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "15775da8-b851-45e4-8ad9-a8729eac01ec",
"eventName": "DescribeNetworkInterfaces",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "3521c52e-583a-4b89-ba44-6dc67a0bb80e",
"requestParameters": {
"filterSet": {},
"networkInterfaceIdSet": {
"items": [
{
"networkInterfaceId": "eni-076fa9fb98a2500a7"
}
]
}
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeOutpostLags
#Description
Describes the Outposts link aggregation groups (LAGs).
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "18dd7526-1d44-4eba-9c65-a069745acf66",
"eventName": "DescribeOutpostLags",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "8e3c9421-5a2e-495f-9e31-a97e9204ad07",
"requestParameters": {
"DescribeOutpostLagsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribePlacementGroups
#Description
Describes one or more of your placement groups.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "80038760-4964-464f-9423-22dbfb4edfa6",
"eventName": "DescribePlacementGroups",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:27:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "d41a70fd-4a0c-474b-a9e9-2b01ee1b005b",
"requestParameters": {
"filterSet": {},
"placementGroupIdSet": {},
"placementGroupSet": {}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCVDQK5XKV",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribePrefixLists
#Description
Describes available AWS services in a prefix list format, which includes the prefix list name and prefix list ID of the service and the IP address range for the service.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "4b8e2f20-666d-4258-befc-51b2b126e842",
"eventName": "DescribePrefixLists",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-10-17T20:10:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "124b9b01-fbac-4438-9400-33c968071bd9",
"requestParameters": {
"DescribePrefixListsRequest": {}
},
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribePrincipalIdFormat
#Description
Describes the ID format settings for the root user and all IAM roles and IAM users that have explicitly specified a longer ID (17-character ID) preference.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "9aaa2bb0-878f-4f20-ab41-6fa5fde6817b",
"eventName": "DescribePrincipalIdFormat",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-10-17T20:10:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "eb1f7a70-62a5-4b1f-982d-06361a1960ca",
"requestParameters": {
"DescribePrincipalIdFormatRequest": {}
},
"responseElements": null,
"sourceIPAddress": "9.245.1.85",
"userAgent": "Botocore/1.12.25 Python/2.7.15 Linux/4.16.0-kali2-amd64",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribePublicIpv4Pools
#Description
Describes the specified IPv4 address pools.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "e09b4cc2-2456-4a2a-805b-63107e770b70",
"eventName": "DescribePublicIpv4Pools",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2019-07-25T09:40:56Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "87fb127d-ce6f-415c-aa4f-af58953ba8f9",
"requestParameters": {
"DescribePublicIpv4PoolsRequest": {}
},
"responseElements": null,
"sourceIPAddress": "248.251.245.4",
"userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeReplaceRootVolumeTasks
#Description
Describes a root volume replacement task.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f819b1c9-41fd-4b15-904c-98d35eb74c47",
"eventName": "DescribeReplaceRootVolumeTasks",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "dad4dce4-6c96-46cc-80b1-7c86dffe81e3",
"requestParameters": {
"DescribeReplaceRootVolumeTasksRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeReservedInstances
#Description
Describes one or more of the Reserved Instances that you purchased.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventID": "833d54df-d375-428f-9c2c-076b2ae2c20e",
"eventName": "DescribeReservedInstances",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-02-27T23:16:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "e2722f71-4e84-4610-8b5d-2c19d66415e4",
"requestParameters": {
"filterSet": {},
"reservedInstancesSet": {}
},
"responseElements": null,
"sourceIPAddress": "3.239.132.95",
"userAgent": "aws-cli/1.7.36 Python/2.7.11 Linux/4.4.0-34-generic",
"userIdentity": {
"accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeReservedInstancesListings
#Description
Describes your account's Reserved Instance listings in the Reserved Instance Marketplace.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "Client.OptInRequired",
"errorMessage": "AccountId '811596193553', You are not authorized to use the requested product. Please complete the seller registration https://portal.aws.amazon.com/ec2/ri/seller_registration?action=businessInfo.",
"eventID": "ad74dbcc-1ba2-489f-b635-2fc3cd94c374",
"eventName": "DescribeReservedInstancesListings",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-03-01T07:30:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "c203cf73-179d-4eaf-9133-fdad25889b4",
"requestParameters": {
"filterSet": {},
"reservedInstancesListingSet": {},
"reservedInstancesSet": {}
},
"responseElements": null,
"sourceIPAddress": "6.84.9.35",
"userAgent": "aws-cli/1.2.9 Python/3.4.3 Linux/4.4.0-53-generic",
"userIdentity": {
"accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeReservedInstancesModifications
#Description
Describes the modifications made to your Reserved Instances.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "f8cefc04-de21-4cca-bc64-05aac20aed8d",
"eventName": "DescribeReservedInstancesModifications",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-03-01T07:30:33Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "f2532c97-b8e9-49aa-842c-1e792c0b9d6a",
"requestParameters": {
"filterSet": {},
"reservedInstancesModificationSet": {}
},
"responseElements": null,
"sourceIPAddress": "6.84.9.35",
"userAgent": "aws-cli/1.2.9 Python/3.4.3 Linux/4.4.0-53-generic",
"userIdentity": {
"accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeReservedInstancesOfferings
#Description
Describes Reserved Instance offerings that are available for purchase.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "1f941e87-d46e-4239-8523-f2c5d256fe09",
"eventName": "DescribeReservedInstancesOfferings",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-03-01T07:30:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "68de79c7-f45a-45c0-8c9f-4ff191b04928",
"requestParameters": {
"nextToken": "IjCP06V0WY8QLSt/Hnn+QQzdGaYMkM+fcKgqVzakS/ic5wjjK7zrQ6ornnyMlWah",
"reservedInstancesOfferingsSet": {}
},
"responseElements": null,
"sourceIPAddress": "6.84.9.35",
"userAgent": "aws-cli/1.2.9 Python/3.4.3 Linux/4.4.0-53-generic",
"userIdentity": {
"accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeRouteServerEndpoints
#Description
Describes one or more route server endpoints.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "a940280e-593c-4234-9cc7-352dd5600661",
"eventName": "DescribeRouteServerEndpoints",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "94043644-144a-4c30-a0ce-2c6989453c4b",
"requestParameters": {
"DescribeRouteServerEndpointsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeRouteServerPeers
#Description
Describes one or more route server peers.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "a1f5ba94-4a11-4fe4-b9c5-0a4100833eb4",
"eventName": "DescribeRouteServerPeers",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "7c488206-f5be-4961-aede-ab8a58db0ab4",
"requestParameters": {
"DescribeRouteServerPeersRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeRouteServers
#Description
Describes one or more route servers.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "79b6224b-0791-4191-821c-83405d43a0d7",
"eventName": "DescribeRouteServers",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "914c29f8-3710-41a9-bb2c-40ffd11c5c38",
"requestParameters": {
"DescribeRouteServersRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeRouteTables
#Description
Describes one or more of your route tables.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "bf0dace9-5898-4ff9-a2f8-b55014751093",
"eventName": "DescribeRouteTables",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:13:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "a665966b-48eb-45d6-a80b-c948bd347cd6",
"requestParameters": {
"filterSet": {},
"maxResults": 100,
"routeTableIdSet": {}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCSUD2OWV6",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:13:16Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeScheduledInstanceAvailability
#Description
Finds available schedules that meet the specified criteria.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.DryRunOperation",
"errorMessage": "Request would have succeeded, but DryRun flag is set.",
"eventID": "3edcb6fc-07de-42a4-99c3-b27f3b3ff63a",
"eventName": "DescribeScheduledInstanceAvailability",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-11-10T12:01:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "e886c6ff-fe03-4228-992f-c506f376526e",
"requestParameters": {
"DescribeScheduledInstanceAvailabilityRequest": {
"FirstSlotStartTimeRange": {
"EarliestTime": "2015-01-01T00:00:00Z",
"LatestTime": "2015-01-01T00:00:00Z"
}
}
},
"responseElements": null,
"sourceIPAddress": "43.254.0.31",
"userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeScheduledInstances
#Description
Describes one or more of your Scheduled Instances.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "8c590598-b6c1-48fb-90d2-ca04ae3dd1fa",
"eventName": "DescribeScheduledInstances",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-03-11T18:20:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "df7f285d-5ab2-40b3-8690-5acfeba2c859",
"requestParameters": {
"DescribeScheduledInstancesRequest": {}
},
"responseElements": null,
"sourceIPAddress": "34.7.241.251",
"userAgent": "aws-cli/1.10.67 Python/2.7.10 Darwin/16.4.0 botocore/1.4.93",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeSecondaryInterfaces
#Description
Describes one or more of your secondary interfaces.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidAction",
"errorMessage": "The action DescribeSecondaryInterfaces is not valid for this web service.",
"eventCategory": "Management",
"eventID": "6bfd0c8c-e6e5-490f-931b-e005c61ad14f",
"eventName": "DescribeSecondaryInterfaces",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "13e2c0bc-f9d0-42cc-bb5a-f5e1a487628e",
"requestParameters": {
"DescribeSecondaryInterfacesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeSecondaryNetworks
#Description
Describes one or more secondary networks.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.UnsupportedOperation",
"errorMessage": "The functionality you requested is not supported in this region.",
"eventCategory": "Management",
"eventID": "dcba4404-8763-4e97-b172-c76c1a826a81",
"eventName": "DescribeSecondaryNetworks",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "52172d0c-a733-4759-b8c9-fe93d4c825f7",
"requestParameters": {
"DescribeSecondaryNetworksRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeSecondarySubnets
#Description
Describes one or more of your secondary subnets.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidAction",
"errorMessage": "The action DescribeSecondarySubnets is not valid for this web service.",
"eventCategory": "Management",
"eventID": "6399c973-6f64-4038-a4ff-34ea07e0ec05",
"eventName": "DescribeSecondarySubnets",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "3ac0be6f-08d2-421c-99b2-b405bdb37bf5",
"requestParameters": {
"DescribeSecondarySubnetsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeSecurityGroupReferences
#Description
[EC2-VPC only] Describes the VPCs on the other side of a VPC peering connection that are referencing the security groups you've specified in this request.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.DryRunOperation",
"errorMessage": "Request would have succeeded, but DryRun flag is set.",
"eventID": "a5aa3d88-ef8d-4f6e-87f0-4ec8cf839bc3",
"eventName": "DescribeSecurityGroupReferences",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-11-10T12:01:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "ced04b70-8a90-439e-8462-b93a49005d",
"requestParameters": {
"DescribeSecurityGroupReferencesRequest": {
"GroupId": {
"content": "test",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "43.254.0.31",
"userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1518↳ also matches DescribeSecurityGroups, DescribeSecurityGroupRules, DescribeSubnets
References #
DescribeSecurityGroupRules
#Description
Describes one or more of your security group rules.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "3d97c37f-4f59-41a3-a689-968685ec41d9",
"eventName": "DescribeSecurityGroupRules",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "e54bc96c-6d91-4d9e-b743-2c4470ed01b7",
"requestParameters": {
"DescribeSecurityGroupRulesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1518↳ also matches DescribeSecurityGroups, DescribeSecurityGroupReferences, DescribeSubnets
DescribeSecurityGroupVpcAssociations
#Description
Describes security group VPC associations made with AssociateSecurityGroupVpc.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "dda1ac61-ea4d-45d7-8907-339be0f1746a",
"eventName": "DescribeSecurityGroupVpcAssociations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "611274df-555f-4c31-b64b-59af41044eea",
"requestParameters": {
"DescribeSecurityGroupVpcAssociationsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeServiceLinkVirtualInterfaces
#Description
Describes the Outpost service link virtual interfaces.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "706e0fe7-f554-43bb-bcce-affffa9fa249",
"eventName": "DescribeServiceLinkVirtualInterfaces",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "b3452fb6-981a-4ce0-bd96-8f280ceefc9f",
"requestParameters": {
"DescribeServiceLinkVirtualInterfacesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeSnapshots
#Description
Describes one or more of the Amazon EBS snapshots available to you.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "dfccbba6-f976-4731-a29c-bae01d706ced",
"eventName": "DescribeSnapshots",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:27:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "9df6a97a-6bf0-40ed-8427-925702f08b0d",
"requestParameters": {
"filterSet": {},
"maxResults": 1000,
"ownersSet": {
"items": [
{
"owner": "123837392027"
}
]
},
"sharedUsersSet": {},
"snapshotSet": {}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCVDQK5XKV",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeSpotDatafeedSubscription
#Description
Describes the datafeed for Spot Instances.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "Client.InvalidSpotDatafeed.NotFound",
"errorMessage": "Spot datafeed subscription does not exist.",
"eventID": "8d7dafc7-d1b5-469b-898d-cc0571a421a6",
"eventName": "DescribeSpotDatafeedSubscription",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-03-01T07:31:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "48075eb-82bc-4c71-b4cf-8f2386dbadf7",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "6.84.9.35",
"userAgent": "aws-cli/1.2.9 Python/3.4.3 Linux/4.4.0-53-generic",
"userIdentity": {
"accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeSpotFleetInstances
#Description
Describes the running instances for the specified Spot fleet.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.DryRunOperation",
"errorMessage": "Request would have succeeded, but DryRun flag is set.",
"eventID": "cf1670cb-256f-44be-8d75-eb885ad46067",
"eventName": "DescribeSpotFleetInstances",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-11-10T12:01:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "7d2d652b-d6ba-4a98-ad12-a4944c53be6d",
"requestParameters": {
"DescribeSpotFleetInstancesRequest": {
"SpotFleetRequestId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "43.254.0.31",
"userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeSpotFleetRequestHistory
#Description
Describes the events for the specified Spot fleet request during the specified time.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.DryRunOperation",
"errorMessage": "Request would have succeeded, but DryRun flag is set.",
"eventID": "ad726e81-bde1-44aa-9dd3-68d563142b7e4",
"eventName": "DescribeSpotFleetRequestHistory",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-11-10T12:01:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "6ebd2862-cd18-4cd6-9185-2f995330cc67",
"requestParameters": {
"DescribeSpotFleetRequestHistoryRequest": {
"SpotFleetRequestId": "dummy_data",
"StartTime": "2015-01-01T00:00:00Z"
}
},
"responseElements": null,
"sourceIPAddress": "43.254.0.31",
"userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeSpotFleetRequests
#Description
Describes your Spot fleet requests.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "6bb9baae-bc9f-4062-8e63-2f1c7c112ff6",
"eventName": "DescribeSpotFleetRequests",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-03-11T18:20:36Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "c95544-3971-4c2b-b96d-4c2f1ef602e4",
"requestParameters": {
"DescribeSpotFleetRequestsRequest": {}
},
"responseElements": null,
"sourceIPAddress": "34.7.241.251",
"userAgent": "aws-cli/1.10.67 Python/2.7.10 Darwin/16.4.0 botocore/1.4.93",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeSpotInstanceRequests
#Description
Describes the Spot Instance requests that belong to your account.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "c4a2d388-0301-41f6-b3f1-2407dc4de14f",
"eventName": "DescribeSpotInstanceRequests",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-02-27T23:16:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "83e073d4-e4d1-4c56-9dcc-b5ebed718c83",
"requestParameters": {
"filterSet": {},
"spotInstanceRequestIdSet": {}
},
"responseElements": null,
"sourceIPAddress": "3.239.132.95",
"userAgent": "aws-cli/1.7.36 Python/2.7.11 Linux/4.4.0-34-generic",
"userIdentity": {
"accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeSpotPriceHistory
#Description
Describes the Spot Price history.
Example CloudTrail Event #
{
"awsRegion": "ap-south-1",
"eventID": "9c09edb7-8bfb-41dd-9dc1-40385ec60da7",
"eventName": "DescribeSpotPriceHistory",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-03-04T17:18:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "207a103f-f5f2-46d3-adf6-437b80469",
"requestParameters": {
"endTime": 1489904317865,
"instanceTypeSet": {
"items": [
{
"instanceType": "g2.8xlarge"
}
]
},
"productDescriptionSet": {},
"startTime": 1488647917865
},
"responseElements": null,
"sourceIPAddress": "5.165.77.250",
"userAgent": "Boto3/1.4.2 Python/2.7.13 Linux/4.9.0-1-amd64 Botocore/1.5.19",
"userIdentity": {
"accessKeyId": "AKIA1ZBTOEKWKVHP6GHZ",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeStaleSecurityGroups
#Description
[EC2-VPC only] Describes the stale security group rules for security groups in a specified VPC.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.DryRunOperation",
"errorMessage": "Request would have succeeded, but DryRun flag is set.",
"eventID": "c6a2bbb6-2866-49a1-a316-9c9717fbddf1",
"eventName": "DescribeStaleSecurityGroups",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-11-10T12:01:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "5cf3008c-1e7b-45bc-84af-cb5cba404d3c",
"requestParameters": {
"DescribeStaleSecurityGroupsRequest": {
"VpcId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "43.254.0.31",
"userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeStoreImageTasks
#Description
Describes the progress of the AMI store tasks.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "4d42f521-da83-46a2-ad70-c80ddeacc518",
"eventName": "DescribeStoreImageTasks",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "3f858caa-b998-4fc5-b129-158f4937e9a4",
"requestParameters": {
"DescribeStoreImageTasksRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeSubnets
#Description
Describes one or more of your subnets.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "74284e7a-7abf-43dc-b1d1-a0d8633ba00c",
"eventName": "DescribeSubnets",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:13:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "10766182-9558-4144-a9be-9e43a28920b8",
"requestParameters": {
"filterSet": {},
"maxResults": 1000,
"subnetSet": {}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCSUD2OWV6",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:13:16Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1518↳ also matches DescribeSecurityGroups, DescribeSecurityGroupReferences, DescribeSecurityGroupRules
References #
DescribeTrafficMirrorFilterRules
#Description
Describe traffic mirror filters that determine the traffic that is mirrored.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "4a8a0993-02ce-469f-821e-1ca8260b250a",
"eventName": "DescribeTrafficMirrorFilterRules",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "a58acd13-c60a-421e-b91d-e7ccba9f0ba8",
"requestParameters": {
"DescribeTrafficMirrorFilterRulesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeTrafficMirrorFilters
#Description
Describes one or more Traffic Mirror filters.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "42328f8-2029-4681-8202-33c1e743044aa",
"eventName": "DescribeTrafficMirrorFilters",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-06-10T05:33:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "a77829e5-badf-4cf6-a520-8a6e0d9f0bd5",
"requestParameters": {
"DescribeTrafficMirrorFiltersRequest": ""
},
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeTrafficMirrorSessions
#Description
Describes one or more Traffic Mirror sessions.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "9ba4e09f-faf1-4b38-ad2d-e0fd048b6ba4",
"eventName": "DescribeTrafficMirrorSessions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-06-10T05:33:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "a09ad992-b307-4c54-b307-ffb503d1737c",
"requestParameters": {
"DescribeTrafficMirrorSessionsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeTrafficMirrorTargets
#Description
Information about one or more Traffic Mirror targets.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "93fd3651-219a-4c92-b80f-a29341ecb450",
"eventName": "DescribeTrafficMirrorTargets",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-06-10T05:33:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "3de33695-7068-4daa-be3e-279a60dc2379",
"requestParameters": {
"DescribeTrafficMirrorTargetsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeTransitGatewayAttachments
#Description
Describes one or more attachments between resources and transit gateways.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "cf917116-bed7-4ffc-bf38-c36a7102f54e",
"eventName": "DescribeTransitGatewayAttachments",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2019-07-25T09:40:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "feda68a8-d617-4932-9b57-7e1158f80d08",
"requestParameters": {
"DescribeTransitGatewayAttachmentsRequest": {}
},
"responseElements": null,
"sourceIPAddress": "248.251.245.4",
"userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeTransitGatewayConnectPeers
#Description
Describes one or more Connect peers.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "5cc38a7b-7a7e-4bbc-a3de-4b7a8cd4beb1",
"eventName": "DescribeTransitGatewayConnectPeers",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "ef91d15e-f311-4794-91ae-ebe9dfc5c90d",
"requestParameters": {
"DescribeTransitGatewayConnectPeersRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeTransitGatewayConnects
#Description
Describes one or more Connect attachments.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "5894ec98-d98a-4c8c-90c3-3b4f3546ec1d",
"eventName": "DescribeTransitGatewayConnects",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "125b066d-5aa4-411a-955d-fcd9f48cefc0",
"requestParameters": {
"DescribeTransitGatewayConnectsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeTransitGatewayMeteringPolicies
#Description
Describes one or more transit gateway metering policies.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "ee76950b-82c9-4313-9fcf-0bc02bcf756a",
"eventName": "DescribeTransitGatewayMeteringPolicies",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "a76477fc-222f-44bb-907d-d089fb1c8c08",
"requestParameters": {
"DescribeTransitGatewayMeteringPoliciesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeTransitGatewayPeeringAttachments
#Description
Describes your transit gateway peering attachments.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "50ab3be2-33ce-4bd5-85ea-79f375766cca",
"eventName": "DescribeTransitGatewayPeeringAttachments",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-06-10T05:33:39Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "436993f-0376-4257-95a8-d9b0baf4e6b5",
"requestParameters": {
"DescribeTransitGatewayPeeringAttachmentsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "251.105.254.1",
"userAgent": "Botocore/1.16.26 Python/2.7.18 Linux/5.4.0-2-amd64",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeTransitGatewayPolicyTables
#Description
Describes one or more transit gateway route policy tables.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "c9838453-845f-49ec-9578-4dd739c4fffb",
"eventName": "DescribeTransitGatewayPolicyTables",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "87599c49-9fa5-48f7-bf65-06b858940b8c",
"requestParameters": {
"DescribeTransitGatewayPolicyTablesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeTransitGatewayRouteTableAnnouncements
#Description
Describes one or more transit gateway route table advertisements.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "4b49efab-0654-4c1d-97bf-ceb36fae253d",
"eventName": "DescribeTransitGatewayRouteTableAnnouncements",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "2a0f1ec9-b5a6-4df1-8319-4747a589f52b",
"requestParameters": {
"DescribeTransitGatewayRouteTableAnnouncementsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeTransitGatewayRouteTables
#Description
Describes one or more transit gateway route tables.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "c3ecd4b2-ab6b-4bb9-bbfc-11bde9c51492",
"eventName": "DescribeTransitGatewayRouteTables",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2019-07-25T09:40:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "861f1341-9c9a-4e8e-8428-d168a3129dda",
"requestParameters": {
"DescribeTransitGatewayRouteTablesRequest": {}
},
"responseElements": null,
"sourceIPAddress": "248.251.245.4",
"userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeTransitGateways
#Description
Describes one or more transit gateways.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "9b9b5bfa-7240-4300-ab85-52f65e004558",
"eventName": "DescribeTransitGateways",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2019-07-25T09:40:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "1c3c773e-1993-4ff0-9a23-9757bdf0f106",
"requestParameters": {
"DescribeTransitGatewaysRequest": {}
},
"responseElements": null,
"sourceIPAddress": "248.251.245.4",
"userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeTransitGatewayVpcAttachments
#Description
Describes one or more VPC attachments.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "fb6136e6-0f08-44dd-8556-e353e114847e0",
"eventName": "DescribeTransitGatewayVpcAttachments",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2019-07-25T09:40:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "dad960f8-e300-444c-86bb-82b92f5c9162",
"requestParameters": {
"DescribeTransitGatewayVpcAttachmentsRequest": {}
},
"responseElements": null,
"sourceIPAddress": "248.251.245.4",
"userAgent": "Boto3/1.9.39 Python/2.7.16 Linux/4.19.0-kali5-amd64 Botocore/1.12.86",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeTrunkInterfaceAssociations
#Description
Describes one or more network interface trunk associations.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.OperationNotPermitted",
"errorMessage": "User 123456789012 is not permitted to perform this operation",
"eventCategory": "Management",
"eventID": "1d50d5e9-2ea6-4d8e-b908-e74029bb3656",
"eventName": "DescribeTrunkInterfaceAssociations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "bcddf5b1-6f91-45d3-a88e-c81494b62be5",
"requestParameters": {
"DescribeTrunkInterfaceAssociationsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeVerifiedAccessEndpoints
#Description
Describes the specified Amazon Web Services Verified Access endpoints.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "a1ded684-ccce-435c-94ea-c0f2511700b4",
"eventName": "DescribeVerifiedAccessEndpoints",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "442d4b76-4ef4-43d2-9878-652649c3d0bd",
"requestParameters": {
"DescribeVerifiedAccessEndpointsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeVerifiedAccessGroups
#Description
Describes the specified Verified Access groups.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "1f54ad6f-9eb4-4094-89aa-3cc78f5b0b7d",
"eventName": "DescribeVerifiedAccessGroups",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "d856fec2-f246-4101-a50d-dca66898d8bd",
"requestParameters": {
"DescribeVerifiedAccessGroupsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeVerifiedAccessInstanceLoggingConfigurations
#Description
Describes the specified Amazon Web Services Verified Access instances.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "736c4f3a-8b31-4951-b1ba-cf0fcbe398a5",
"eventName": "DescribeVerifiedAccessInstanceLoggingConfigurations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "3c6f620d-ea25-483a-b667-ae24fdcef9ee",
"requestParameters": {
"DescribeVerifiedAccessInstanceLoggingConfigurationsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeVerifiedAccessInstances
#Description
Describes the specified Amazon Web Services Verified Access instances.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "21cbec31-9bb8-4537-b5b9-a666d8e6922d",
"eventName": "DescribeVerifiedAccessInstances",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "4aedb801-7e6a-4766-815e-06b058ddc95f",
"requestParameters": {
"DescribeVerifiedAccessInstancesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeVerifiedAccessTrustProviders
#Description
Describes the specified Amazon Web Services Verified Access trust providers.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "35e7855a-9ca6-41a2-a7ae-4fade59286b4",
"eventName": "DescribeVerifiedAccessTrustProviders",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "9972d591-ca81-44ed-9f44-c709c406b3f6",
"requestParameters": {
"DescribeVerifiedAccessTrustProvidersRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeVolumeAttribute
#Description
Describes the specified attribute of the specified volume.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"eventID": "9c3dcdf0-edb2-4f24-9d04-3652af634102",
"eventName": "DescribeVolumeAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2017-02-12T22:59:33Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "149ba3d3-342d-4561-a5ac-92ea33ba017b",
"requestParameters": {
"volumeId": "vol-8e100f305b7a6fef3"
},
"responseElements": null,
"sourceIPAddress": "255.253.125.115",
"userAgent": "console.ec2.amazonaws.com",
"userIdentity": {
"accessKeyId": "ASIAIB6AB67SP5RKU9Z4",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:root",
"principalId": "811596193553",
"sessionContext": {
"attributes": {
"creationDate": "2017-02-12T19:57:05Z",
"mfaAuthenticated": "false"
}
},
"type": "Root"
}
}
References #
DescribeVolumeStatus
#Description
Describes the status of the specified volumes.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "8242ec66-3f5d-4032-be35-6cdbc6fc58d7",
"eventName": "DescribeVolumeStatus",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:27:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "79b5840a-5a54-45ed-912e-c4eea46c2a67",
"requestParameters": {
"filterSet": {},
"maxResults": 1000,
"volumeSet": {}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCVDQK5XKV",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeVpcAttribute
#Description
Describes the specified attribute of the specified VPC.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "f7731d05-e80f-424b-8f67-732cbb8ea29f",
"eventName": "DescribeVpcAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "76fb511b-ee07-4b05-8a5e-93c4274912bc",
"requestParameters": {
"vpcId": "vpc-06fe1a64761a0f720"
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeVpcBlockPublicAccessExclusions
#Description
Describe VPC Block Public Access (BPA) exclusions.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.MissingParameter",
"errorMessage": "One of the following parameters must be provided: ExclusionIds, MaxResults",
"eventCategory": "Management",
"eventID": "ccb6346e-6268-4d12-983b-2b2176d69b21",
"eventName": "DescribeVpcBlockPublicAccessExclusions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "763b28d1-45b9-4cfe-a6a4-92dc154396b1",
"requestParameters": {
"DescribeVpcBlockPublicAccessExclusionsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeVpcBlockPublicAccessOptions
#Description
Describe VPC Block Public Access (BPA) options.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "7b391d58-7c1b-4147-b07b-c5a911e6e0ef",
"eventName": "DescribeVpcBlockPublicAccessOptions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "58a1ddf9-b093-44c6-969c-31bfbb351f23",
"requestParameters": {
"DescribeVpcBlockPublicAccessOptionsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeVpcClassicLink
#Description
Describes the ClassicLink status of one or more VPCs.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "0b261e62-f85e-4d7e-87c3-3c572e4aa108",
"eventName": "DescribeVpcClassicLink",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "7194db16-83d1-4212-bde3-be25c49729df",
"requestParameters": {
"filterSet": {},
"vpcSet": {
"item": [
{
"vpcId": "vpc-06fe1a64761a0f720"
}
]
}
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeVpcClassicLinkDnsSupport
#Description
Describes the ClassicLink DNS support status of one or more VPCs.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "7445d04f-062d-4248-b930-1c5f53644f4d",
"eventName": "DescribeVpcClassicLinkDnsSupport",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "2cff7748-7483-4a82-a170-4ea18db16d00",
"requestParameters": {
"DescribeVpcClassicLinkDnsSupportRequest": {
"VpcIds": {
"content": "vpc-06fe1a64761a0f720",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeVpcEncryptionControls
#Description
Describes one or more VPC Encryption Control configurations.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "b86638fb-f92c-453e-96f0-32c3b58b317a",
"eventName": "DescribeVpcEncryptionControls",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c4a0cf20-5c43-47b2-9e50-d20c4fee1d3e",
"requestParameters": {
"DescribeVpcEncryptionControlsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeVpcEndpointAssociations
#Description
Describes the VPC resources, VPC endpoint services, Amazon Lattice services, or service networks associated with the VPC endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "8c585b3c-0bf3-45d5-b95a-e8dd9aa3b9be",
"eventName": "DescribeVpcEndpointAssociations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "3eb9039b-d35b-43f3-b31f-81bf1ab06403",
"requestParameters": {
"DescribeVpcEndpointAssociationsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeVpcEndpointConnections
#Description
Describes the VPC endpoint connections to your VPC endpoint services, including any endpoints that are pending your acceptance.
Example CloudTrail Event #
{
"awsRegion": "ap-south-1",
"eventID": "a8138a81-4cd0-4a4c-b95d-31f557bed7e5",
"eventName": "DescribeVpcEndpointConnections",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-08-05T17:07:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "ae2c2413-3172-45c5-8777-40ce18cb5b28",
"requestParameters": {
"DescribeVpcEndpointConnectionsRequest": {}
},
"responseElements": null,
"sourceIPAddress": "250.251.253.3",
"userAgent": "Boto3/1.5.32 Python/3.6.4 Darwin/17.6.0 Botocore/1.8.50",
"userIdentity": {
"accessKeyId": "ASIAPYBUDZE3ZQU169GB",
"accountId": "811596193553",
"arn": "arn:aws:sts::811596193553:assumed-role/SummitRouteAudit/4032461535040776536",
"principalId": "AROAMY611GPC0EPB1P0F9:4032461535040776536",
"sessionContext": {
"attributes": {
"creationDate": "2018-08-05T17:00:49Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:role/SummitRouteAudit",
"principalId": "AROAMY611GPC0EPB1P0F9",
"type": "Role",
"userName": "SummitRouteAudit"
}
},
"type": "AssumedRole"
}
}
References #
DescribeVpcEndpoints
#Description
Describes one or more of your VPC endpoints.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "05a18e4f-a57c-4ff4-bdf2-e457af1d335d",
"eventName": "DescribeVpcEndpoints",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:13:32Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "eb6c6d0a-3cd1-444e-9d3a-09c5cd98b22b",
"requestParameters": {
"DescribeVpcEndpointsRequest": {
"Filter": {
"Name": "vpc-id",
"Value": {
"content": "vpc-098ff30ff74b36f73",
"tag": 1
},
"tag": 1
}
}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCSUD2OWV6",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:13:16Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeVpcEndpointServiceConfigurations
#Description
Describes the VPC endpoint service configurations in your account (your services).
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "628238ec-ac92-4875-a158-15c667144d81",
"eventName": "DescribeVpcEndpointServiceConfigurations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:13:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "b246466b-52e5-4ffe-bb9e-04b42885a79a",
"requestParameters": {
"DescribeVpcEndpointServiceConfigurationsRequest": {
"MaxResults": 1000
}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCSUD2OWV6",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:13:16Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeVpcEndpointServicePermissions
#Description
Describes the principals (service consumers) that are permitted to discover your VPC endpoint service.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.DryRunOperation",
"errorMessage": "Request would have succeeded, but DryRun flag is set.",
"eventID": "10d1ab88-079e-4fbb-9767-c24662cc6008",
"eventName": "DescribeVpcEndpointServicePermissions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-11-10T12:01:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "c0d80764-7fe3-4dcb-93ba-4c94d5ad1ca7",
"requestParameters": {
"DescribeVpcEndpointServicePermissionsRequest": {
"ServiceId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "43.254.0.31",
"userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeVpcEndpointServices
#Description
Describes all supported AWS services that can be specified when creating a VPC endpoint.
Example CloudTrail Event #
{
"awsRegion": "ap-south-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventCategory": "Management",
"eventID": "1f2d8d59-9e54-4890-9c25-3660ef877c28",
"eventName": "DescribeVpcEndpointServices",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-04-13T11:35:22Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "111111111111",
"requestID": "97ba7cdd-b188-4ec7-af8b-ee78bb52fe8a",
"requestParameters": {
"DescribeVpcEndpointServicesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "95.90.195.80",
"userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:user/cloudsploit",
"principalId": "AIDAYTOGP2RLMDEPWZWMJ",
"type": "IAMUser",
"userName": "cloudsploit"
}
}
References #
DescribeVpcPeeringConnections
#Description
Describes one or more of your VPC peering connections.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "7308ba6e-285a-4a91-82e3-dd7287bb2fe6",
"eventName": "DescribeVpcPeeringConnections",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:13:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "7a599722-580d-4522-8783-1f80d98bec63",
"requestParameters": {
"filterSet": {},
"maxResults": 1000,
"vpcPeeringConnectionIdSet": {}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCSUD2OWV6",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:13:16Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeVpnConcentrators
#Description
Describes one or more of your VPN concentrators.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "ea50ee7e-50c1-427f-b560-305fdd605949",
"eventName": "DescribeVpnConcentrators",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "86ad15ec-75ec-4fe9-9bca-ab0392d43988",
"requestParameters": {
"DescribeVpnConcentratorsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeVpnConnections
#Description
Describes one or more of your VPN connections.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "27c3dc94-3ee3-492a-b5f8-980cd779071c",
"eventName": "DescribeVpnConnections",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:13:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "16105444-3ba0-49c1-96c3-af8ea024a56d",
"requestParameters": {
"filterSet": {},
"vpnConnectionSet": {}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCSUD2OWV6",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:13:16Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DescribeVpnGateways
#Description
Describes one or more of your virtual private gateways.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "0f1005c9-210f-407e-86de-a5006d4782f4",
"eventName": "DescribeVpnGateways",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:13:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "85709788-8d91-428e-82f6-8f5c39524563",
"requestParameters": {
"filterSet": {},
"vpnGatewaySet": {}
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCSUD2OWV6",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:13:16Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DetachClassicLinkVpc
#Description
Unlinks (detaches) a linked EC2-Classic instance from a VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidInstanceID.Malformed",
"errorMessage": "The instance ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "27a9b25d-dbd2-43c4-88ea-f5bb1faa5e3f",
"eventName": "DetachClassicLinkVpc",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:40Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f92e2b41-cdb4-4f02-a657-dfb22815e6ac",
"requestParameters": {
"instanceId": "dw-probe",
"vpcId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches AcceptVpcPeeringConnection, AttachClassicLinkVpc, CreateVpc, DeleteVpc, DisableVpcClassicLink, EnableVpcClassicLink, ModifyVpcAttribute, RejectVpcPeeringConnection
DetachImageWatermark
#Description
Removes a watermark from the specified AMI.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidAMIID.Malformed",
"errorMessage": "The image ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "5f8db8e8-eca7-4a7e-8a62-599048ac3964",
"eventName": "DetachImageWatermark",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:40Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0cb00722-1d96-4da6-9966-d06335e9d44d",
"requestParameters": {
"DetachImageWatermarkRequest": {
"ImageId": "dw-probe",
"WatermarkKey": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DetachInternetGateway
#Description
Detaches an Internet gateway from a VPC, disabling connectivity between the Internet and the VPC.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "391942a4-c330-4d17-9497-343e28c0b8a1",
"eventName": "DetachInternetGateway",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:12:05Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "40a130e8-f287-4bb9-8d8a-0be8dd7cffd8",
"requestParameters": {
"internetGatewayId": "igw-02a84e4222d62e16b",
"vpcId": "vpc-06fe1a64761a0f720"
},
"responseElements": {
"_return": true,
"requestId": "40a130e8-f287-4bb9-8d8a-0be8dd7cffd8"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches AttachInternetGateway, CreateCustomerGateway, CreateInternetGateway, DeleteCustomerGateway, DeleteInternetGateway
References #
DetachNetworkInterface
#Description
Detaches a network interface from an instance.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.InvalidAttachmentID.NotFound",
"errorMessage": "The interface attachment 'eni-attach-02aca13293a6fe1b9' does not exist.",
"eventCategory": "Management",
"eventID": "39fba6c9-a3ab-406b-9b67-e43e05cd0899",
"eventName": "DetachNetworkInterface",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:09:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "024edddb-94cf-4d36-9aed-7abc1ebf71d3",
"requestParameters": {
"attachmentId": "eni-attach-02aca13293a6fe1b9",
"force": true
},
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
DetachVerifiedAccessTrustProvider
#Description
Detaches the specified Amazon Web Services Verified Access trust provider from the specified Amazon Web Services Verified Access instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVerifiedAccessTrustProviderId.NotFound",
"errorMessage": "VerifiedAccessTrustProvider dw-probe does not exist",
"eventCategory": "Management",
"eventID": "c41d6b8f-514d-4546-b89b-b7a7feed5661",
"eventName": "DetachVerifiedAccessTrustProvider",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:40Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "43b84fdb-4c04-458f-ac6a-e9ed7d7e9fd4",
"requestParameters": {
"DetachVerifiedAccessTrustProviderRequest": {
"ClientToken": "4c2c34dc-0477-4503-ab04-4c3e84e03c1d",
"VerifiedAccessInstanceId": "dw-probe",
"VerifiedAccessTrustProviderId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DetachVolume
#Description
Detaches an Amazon EBS volume from an instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation. Encoded authorization failure message: HYJFvwruKwBtMwIhS15T8i9rGXMn-2WgMxuVssxwqEdBjV8gZgFV12dK4KpKJWxJy8fVrBt6GP-G8HVY_HE8Y0wm0nHZr53vtC13RKPBJ9We8o90FgshcH7gkJLVixFD1dBFF_PwCEUr51WbCVA75bAn1DGW1g70siNFfutnKuQIgim7G4wq--3lmV4nydaRLMlGnie36viGWBpFffQKDMgstqaNqwlr7HuO9mhBtxw-ppy_N59gnvfYq2EyBDhl1KjmqfvrtYGxpdwySciIAq1BlTpC2kHGZ-dEKJiVr4pUlckewHB6220uJqgfgdMOj_cQu7zcKjYIlGy0cXJZ5BZuZB1bN8P-UgBieZEzrshEciCzHfnQ3Z-67LfLygzCg6mNVXq5lqgmvgSwqJMZ020Wl5grGrz-IDGBNgL1u0iZyOCLvutRvTuWuQU5E8Oa6ye7JNyeAA5QNNT-uwUel0b1HqoeerjVUwAOmwBKoVJnBLBEB9GdwssJzXv3mOqgdMK-A02kh98hick5ad5zwIRzorUiQoZvytdzd37GZjKEcT61okgE-Y8U-Q_YS6NkN3Jvc59ClLchepxeXInFFop5824phdyPHIb7YehpHYR6kmoUzKJJK_P9ogCef88X3fOOu23hfUVXK-bLJVb9gZoYEX7xUal1GPF5H8XknwEvSIisIkQP8IfrsHo_Cgh6",
"eventID": "2e4c49af-a5c9-4686-8cdd-b326edee9ec4",
"eventName": "DetachVolume",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-07-27T12:01:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "661dea5e-265d-4e0e-82ba-122c8adcf6d3",
"requestParameters": {
"force": false,
"volumeId": "vol-8e100f305b7a6fef3"
},
"responseElements": null,
"sourceIPAddress": "253.6.241.250",
"userAgent": "aws-cli/1.15.4 Python/2.7.6 Linux/4.4.0-75-generic botocore/1.10.4",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DetachVpnGateway
#Description
Detaches a virtual private gateway from a VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpnGatewayID.NotFound",
"errorMessage": "The vpnGateway ID 'dw-probe' does not exist",
"eventCategory": "Management",
"eventID": "fc887de2-f567-42db-a718-d23bc2833a7b",
"eventName": "DetachVpnGateway",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8e0c8694-7aea-4737-9485-25617ce0711a",
"requestParameters": {
"vpcId": "dw-probe",
"vpnGatewayId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableAddressTransfer
#Description
Disables Elastic IP address transfer.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidElasticIpID.NotFound",
"errorMessage": "The allocation ID 'dw-probe' does not exist",
"eventCategory": "Management",
"eventID": "24605631-0a7e-4daf-ac63-bc13d09a644f",
"eventName": "DisableAddressTransfer",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d4a50b68-dc8b-49a1-9b5d-86a85942b805",
"requestParameters": {
"DisableAddressTransferRequest": {
"AllocationId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableAllowedImagesSettings
#Description
Disables Allowed AMIs for your account in the specified Amazon Web Services Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "579403dc-1da2-4b77-9abf-73c1d5987f75",
"eventName": "DisableAllowedImagesSettings",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:43:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a1effc51-a9ed-405d-ae90-95995ed77d61",
"requestParameters": {
"DisableAllowedImagesSettingsRequest": ""
},
"responseElements": {
"DisableAllowedImagesSettingsResponse": {
"allowedImagesSettingsState": "disabled",
"requestId": "a1effc51-a9ed-405d-ae90-95995ed77d61",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableAwsNetworkPerformanceMetricSubscription
#Description
Disables Infrastructure Performance metric subscriptions.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.MissingParameter",
"errorMessage": "Missing required parameter: Source",
"eventCategory": "Management",
"eventID": "3861ad9d-3682-4cbb-8a09-f54e0a017e1a",
"eventName": "DisableAwsNetworkPerformanceMetricSubscription",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:45:17Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "3c092b3c-17ae-4bab-8adf-4f0972ac320d",
"requestParameters": {
"DisableAwsNetworkPerformanceMetricSubscriptionRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableCapacityManager
#Description
Disables EC2 Capacity Manager for your account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.CapacityManager.Disabled",
"errorMessage": "Capacity Manager isn't enabled for this account.",
"eventCategory": "Management",
"eventID": "b45118f6-5ce1-4546-b567-3738cd3064c9",
"eventName": "DisableCapacityManager",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:45:17Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f44eb21b-d9fb-4387-8642-a0a9698b6e90",
"requestParameters": {
"DisableCapacityManagerRequest": {
"ClientToken": "e34262b0-f35d-4b63-a639-839b3b037fc7"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableFastLaunch
#Description
Discontinue Windows fast launch for a Windows AMI, and clean up existing pre-provisioned snapshots.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRequest",
"errorMessage": "2 validation errors detected: Value 'dw-probe' at 'imageId' failed to satisfy constraint: Member must have length greater than or equal to 12; Value 'dw-probe' at 'imageId' failed to satisfy constraint: Member must satisfy regular expression pattern: ami-[a-z0-9]+",
"eventCategory": "Management",
"eventID": "8c659b80-cbd1-42a3-8405-c177842588d4",
"eventName": "DisableFastLaunch",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "49251be9-d0c9-4b76-9a3f-e3c77932fac1",
"requestParameters": {
"DisableFastLaunchRequest": {
"ImageId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableFastSnapshotRestores
#Description
Disables fast snapshot restores for the specified snapshots in the specified Availability Zones.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.MissingParameter",
"errorMessage": "AvailabilityZone or AvailabilityZoneId must be specified in the request, but not both.",
"eventCategory": "Management",
"eventID": "02e026bf-1566-4f05-abf9-0474dfc1bd57",
"eventName": "DisableFastSnapshotRestores",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:41Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c33b2126-353f-4dd6-b88e-3b3459f01b2e",
"requestParameters": {
"DisableFastSnapshotRestoresRequest": {
"SourceSnapshotId": {
"content": "dw-probe",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableImage
#Description
Sets the AMI state to disabled and removes all launch permissions from the AMI.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidAMIID.Malformed",
"errorMessage": "The image ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "8b04835f-fe70-4699-88fa-e1bc09357d0b",
"eventName": "DisableImage",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0c986b31-8de4-4c80-b1d4-fac46e6f0bec",
"requestParameters": {
"DisableImageRequest": {
"ImageId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableImageBlockPublicAccess
#Description
Disables block public access for AMIs at the account level in the specified Amazon Web Services Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "fac4fc0a-ca0d-4d61-b8f2-65148eb70deb",
"eventName": "DisableImageBlockPublicAccess",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:43:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0b23bfcb-9572-43d3-ae3c-be9f04c78886",
"requestParameters": {
"DisableImageBlockPublicAccessRequest": ""
},
"responseElements": {
"DisableImageBlockPublicAccessResponse": {
"imageBlockPublicAccessState": "unblocked",
"requestId": "0b23bfcb-9572-43d3-ae3c-be9f04c78886",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableImageDeprecation
#Description
Cancels the deprecation of the specified AMI.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidAMIID.Malformed",
"errorMessage": "The image ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "9eab49db-9cf3-4449-9681-2dddf0efac5e",
"eventName": "DisableImageDeprecation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "dbdc9084-fa7f-4856-a0c4-b106e423f757",
"requestParameters": {
"DisableImageDeprecationRequest": {
"ImageId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableImageDeregistrationProtection
#Description
Disables deregistration protection for an AMI.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidAMIID.Malformed",
"errorMessage": "The image ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "3c9b4ff4-4def-4a74-b65b-91db4498b747",
"eventName": "DisableImageDeregistrationProtection",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:42Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ee222e83-cb4f-4f85-9c88-8d4af7d0d6fa",
"requestParameters": {
"DisableImageDeregistrationProtectionRequest": {
"ImageId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableInstanceSqlHaStandbyDetections
#Description
Disable Amazon EC2 instances running in an SQL Server High Availability cluster from SQL Server High Availability instance standby detection monitoring.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidInstanceID.Malformed",
"errorMessage": "The instance ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "546c0416-f9a9-4485-bc1d-40d41018f8d3",
"eventName": "DisableInstanceSqlHaStandbyDetections",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8d3b4c14-8ee3-4d20-a108-a12ead4786b3",
"requestParameters": {
"DisableInstanceSqlHaStandbyDetectionsRequest": {
"InstanceId": {
"content": "dw-probe",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableIpamOrganizationAdminAccount
#Description
Disable the IPAM account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "The delegated admin account ID is not valid.",
"eventCategory": "Management",
"eventID": "71bc1cf2-4234-47a9-abc1-eeb819448b67",
"eventName": "DisableIpamOrganizationAdminAccount",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c58fdd8e-97b7-40d2-a429-66a4dee813c8",
"requestParameters": {
"DisableIpamOrganizationAdminAccountRequest": {
"DelegatedAdminAccountId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableIpamPolicy
#Description
Disables an IPAM policy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamPolicyId.Malformed",
"errorMessage": "The ipam-policy ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "dd7730c9-c586-4d9a-a485-032eac1f985e",
"eventName": "DisableIpamPolicy",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:43Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2014a946-ef9f-4f09-83a8-9a1d36c7e2e2",
"requestParameters": {
"DisableIpamPolicyRequest": {
"IpamPolicyId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableRouteServerPropagation
#Description
Disables route propagation from a route server to a specified route table.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRouteServerId.Malformed",
"errorMessage": "The route-server ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "a5e73bd7-a773-4380-8f4b-f76528303ed5",
"eventName": "DisableRouteServerPropagation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9edb2345-b6ca-46be-8369-503984fbe578",
"requestParameters": {
"DisableRouteServerPropagationRequest": {
"RouteServerId": "dw-probe",
"RouteTableId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableSerialConsoleAccess
#Description
Disables access to the EC2 serial console of all instances for your account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "cb948f0c-2ed1-4143-b1c1-3b2215a06e1b",
"eventName": "DisableSerialConsoleAccess",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:43:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b3bff592-2c14-425c-95d0-11325d5b4477",
"requestParameters": {
"DisableSerialConsoleAccessRequest": ""
},
"responseElements": {
"DisableSerialConsoleAccessResponse": {
"requestId": "b3bff592-2c14-425c-95d0-11325d5b4477",
"serialConsoleAccessEnabled": false,
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableSnapshotBlockPublicAccess
#Description
Disables the block public access for snapshots setting at the account level for the specified Amazon Web Services Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "fb41b99d-95a1-4ec6-9279-b1b6795be53f",
"eventName": "DisableSnapshotBlockPublicAccess",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:43:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "aaff370c-216d-48c7-bde0-dbb0bba64071",
"requestParameters": {
"DisableSnapshotBlockPublicAccessRequest": ""
},
"responseElements": {
"DisableSnapshotBlockPublicAccessResponse": {
"requestId": "aaff370c-216d-48c7-bde0-dbb0bba64071",
"state": "unblocked",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableTransitGatewayRouteTablePropagation
#Description
Disables the specified resource attachment from propagating routes to the specified propagation route table.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRouteTableId.Malformed",
"errorMessage": "Invalid Transit Gateway Route Table id dw-probe.",
"eventCategory": "Management",
"eventID": "05fad80f-5b01-43f0-be00-e22f4f52b648",
"eventName": "DisableTransitGatewayRouteTablePropagation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "094ab4e4-35a0-4941-aee4-4a58ccf0eb88",
"requestParameters": {
"DisableTransitGatewayRouteTablePropagationRequest": {
"TransitGatewayRouteTableId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableVgwRoutePropagation
#Description
Disables a virtual private gateway (VGW) from propagating routes to a specified route table of a VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRouteTableID.NotFound",
"errorMessage": "The routeTable ID 'dw-probe' does not exist",
"eventCategory": "Management",
"eventID": "a6ca8fa1-1bbe-40c9-921e-5a30e1efc6d6",
"eventName": "DisableVgwRoutePropagation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5f545c51-7424-4633-926b-2bf7b8fd5aa5",
"requestParameters": {
"gatewayId": "dw-probe",
"routeTableId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisableVpcClassicLink
#Description
Disables ClassicLink for a VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpcId.Malformed",
"errorMessage": "The vpc ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "e5a2f3b0-32f8-4fb6-aafa-fc309d8643f9",
"eventName": "DisableVpcClassicLink",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a30df1d0-6141-4cec-99e2-a727cee6ce71",
"requestParameters": {
"vpcId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches AcceptVpcPeeringConnection, AttachClassicLinkVpc, CreateVpc, DeleteVpc, DetachClassicLinkVpc, EnableVpcClassicLink, ModifyVpcAttribute, RejectVpcPeeringConnection
DisableVpcClassicLinkDnsSupport
#Description
Disables ClassicLink DNS support for a VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.MissingParameter",
"errorMessage": "The request must contain the parameter vpcId",
"eventCategory": "Management",
"eventID": "1c9d654e-5094-4b30-a83f-73165426f7e0",
"eventName": "DisableVpcClassicLinkDnsSupport",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:45:18Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "fab69118-a65d-4a96-983c-a20f9e4a9994",
"requestParameters": {
"DisableVpcClassicLinkDnsSupportRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateAddress
#Description
Disassociates an Elastic IP address from the instance or network interface it's associated with.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.MissingParameter",
"errorMessage": "Either public IP or association id must be specified",
"eventCategory": "Management",
"eventID": "ecc55b76-96f9-4bee-9819-5873221dcce2",
"eventName": "DisassociateAddress",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:45:18Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c048216f-74d8-4868-bcc1-911f4915eb96",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateCapacityReservationBillingOwner
#Description
Cancels a pending request to assign billing of the unused capacity of a Capacity Reservation to a consumer account, or revokes a request that has already been accepted.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidCapacityReservationId.Malformed",
"errorMessage": "Capacity Reservation ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "3cca8200-7fae-46cb-b773-c83fe6729440",
"eventName": "DisassociateCapacityReservationBillingOwner",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6a0221cc-d8a7-4392-8fa4-78513e2c8968",
"requestParameters": {
"DisassociateCapacityReservationBillingOwnerRequest": {
"CapacityReservationId": "dw-probe",
"UnusedReservationBillingOwnerId": "dddddddddddd"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateClientVpnTargetNetwork
#Description
Disassociates a target network from the specified Client VPN endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidClientVpnEndpointId.NotFound",
"errorMessage": "The client-vpn-endpoint ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "e1af69b9-0c39-4466-9722-bd666cca97b9",
"eventName": "DisassociateClientVpnTargetNetwork",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9854b8c0-49ab-4eae-ae22-8a11d4fae8a0",
"requestParameters": {
"DisassociateClientVpnTargetNetworkRequest": {
"AssociationId": "dw-probe",
"ClientVpnEndpointId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateEnclaveCertificateIamRole
#Description
Disassociates an IAM role from an Certificate Manager (ACM) certificate.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidCertificateArn.Malformed",
"errorMessage": "The request must contain a valid certificate arn",
"eventCategory": "Management",
"eventID": "5ee02384-4539-4902-a8f4-fc80691ef9d1",
"eventName": "DisassociateEnclaveCertificateIamRole",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0f7104c6-8bf7-4340-8a97-5e748c42604b",
"requestParameters": {
"DisassociateEnclaveCertificateIamRoleRequest": {
"CertificateArn": "dw-probe",
"RoleArn": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateIamInstanceProfile
#Description
Disassociates an IAM instance profile from a running or stopped instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "Invalid Id: dw-probe",
"eventCategory": "Management",
"eventID": "b274b5d3-c009-4faa-8a87-69cfbabc837a",
"eventName": "DisassociateIamInstanceProfile",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "dfbcb412-4b42-4dd1-9030-691fa06b8ff7",
"requestParameters": {
"DisassociateIamInstanceProfileRequest": {
"AssociationId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
DisassociateInstanceEventWindow
#Description
Disassociates one or more targets from an event window.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.MissingParameter",
"errorMessage": "The request must include the AssociationTarget parameter. Add the required parameter and retry the request.",
"eventCategory": "Management",
"eventID": "db13a59d-1b57-4138-a374-0eca0b3d7af8",
"eventName": "DisassociateInstanceEventWindow",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ce3fb886-16cb-428d-9cb4-51184b48bb69",
"requestParameters": {
"DisassociateInstanceEventWindowRequest": {
"InstanceEventWindowId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
DisassociateIpamByoasn
#Description
Remove the association between your Autonomous System Number (ASN) and your BYOIP CIDR.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidCidr.NotFound",
"errorMessage": "The requested CIDR could not be found in IPAM.",
"eventCategory": "Management",
"eventID": "f513a1e5-22e7-49da-8614-ac91b6f06fb8",
"eventName": "DisassociateIpamByoasn",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2c829acb-5af1-44bb-aa37-7cf363e4e5c7",
"requestParameters": {
"DisassociateIpamByoasnRequest": {
"Asn": "dw-probe",
"Cidr": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateIpamResourceDiscovery
#Description
Disassociates a resource discovery from an Amazon VPC IPAM.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamResourceDiscoveryAssociationId.Malformed",
"errorMessage": "The ipam-resource-discovery-association ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "55290604-8f53-491c-a436-3122bd3842a2",
"eventName": "DisassociateIpamResourceDiscovery",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "bb4d4fdc-7efa-4bf0-a159-397b13158468",
"requestParameters": {
"DisassociateIpamResourceDiscoveryRequest": {
"IpamResourceDiscoveryAssociationId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateNatGatewayAddress
#Description
Disassociates secondary Elastic IP addresses (EIPs) from a public NAT gateway.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.NatGatewayMalformed",
"errorMessage": "The natgateway ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "1de493ef-4cf5-4f7a-86fa-c57591e6169d",
"eventName": "DisassociateNatGatewayAddress",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "fe8fcca5-b86a-4764-bfb1-ba235aa70d26",
"requestParameters": {
"DisassociateNatGatewayAddressRequest": {
"AssociationId": {
"content": "dw-probe",
"tag": 1
},
"NatGatewayId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateRouteServer
#Description
Disassociates a route server from a VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRouteServerId.Malformed",
"errorMessage": "The route-server ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "3842e46c-7882-466e-8ee2-87bb93aa9c2f",
"eventName": "DisassociateRouteServer",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "692c6fe9-b8a4-4cd6-9bf9-f03705141b2c",
"requestParameters": {
"DisassociateRouteServerRequest": {
"RouteServerId": "dw-probe",
"VpcId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateSecurityGroupVpc
#Description
Disassociates a security group from a VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpcId.Malformed",
"errorMessage": "The vpc ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "2f836f82-d6fe-4f06-9d7c-dab5d83cba23",
"eventName": "DisassociateSecurityGroupVpc",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c0bba649-2ed2-403e-a983-ee8d4297423f",
"requestParameters": {
"DisassociateSecurityGroupVpcRequest": {
"GroupId": "dw-probe",
"VpcId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateSubnetCidrBlock
#Description
Disassociates a CIDR block from a subnet.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidSubnetCidrBlockAssociationId.Malformed",
"errorMessage": "The subnet CIDR block with association ID dw-probe is malformed",
"eventCategory": "Management",
"eventID": "f3ab2a67-301a-4ffc-87e5-12663e3e4ce0",
"eventName": "DisassociateSubnetCidrBlock",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7c9e4755-83f7-4b76-a01f-89597cddbc95",
"requestParameters": {
"DisassociateSubnetCidrBlockRequest": {
"AssociationId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateTransitGatewayMulticastDomain
#Description
Disassociates the specified subnets from the transit gateway multicast domain.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayMulticastDomainId.Malformed",
"errorMessage": "Invalid Transit Gateway Multicast Domain id dw-probe.",
"eventCategory": "Management",
"eventID": "0d14298e-8875-4076-a3e5-f26aebd9359f",
"eventName": "DisassociateTransitGatewayMulticastDomain",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "733c16c4-ba18-4a9f-96fc-b678810387a6",
"requestParameters": {
"DisassociateTransitGatewayMulticastDomainRequest": {
"SubnetIds": {
"content": "dw-probe",
"tag": 1
},
"TransitGatewayAttachmentId": "dw-probe",
"TransitGatewayMulticastDomainId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateTransitGatewayPolicyTable
#Description
Removes the association between an an attachment and a policy table.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayPolicyTableId.Malformed",
"errorMessage": "Invalid Transit Gateway Policy Table id dw-probe.",
"eventCategory": "Management",
"eventID": "c5e07b67-91df-452a-9952-a53fe8abe757",
"eventName": "DisassociateTransitGatewayPolicyTable",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0149e87d-e433-4dc9-9596-344a4f7ba653",
"requestParameters": {
"DisassociateTransitGatewayPolicyTableRequest": {
"TransitGatewayAttachmentId": "dw-probe",
"TransitGatewayPolicyTableId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateTransitGatewayRouteTable
#Description
Disassociates a resource attachment from a transit gateway route table.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRouteTableId.Malformed",
"errorMessage": "Invalid Transit Gateway Route Table id dw-probe.",
"eventCategory": "Management",
"eventID": "6c782e35-d5ea-4144-b977-e5f2c9cc07e6",
"eventName": "DisassociateTransitGatewayRouteTable",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:47Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b5158537-2e96-4921-a187-b0ca79c3a448",
"requestParameters": {
"DisassociateTransitGatewayRouteTableRequest": {
"TransitGatewayAttachmentId": "dw-probe",
"TransitGatewayRouteTableId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateTrunkInterface
#Description
Removes an association between a branch network interface with a trunk network interface.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.OperationNotPermitted",
"errorMessage": "User 123456789012 is not permitted to perform this operation",
"eventCategory": "Management",
"eventID": "7146f051-bd4b-429e-bf3d-bab7fd2d1dc7",
"eventName": "DisassociateTrunkInterface",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "49112bf4-fb43-4d3e-92a5-eef0ec1ffbc7",
"requestParameters": {
"DisassociateTrunkInterfaceRequest": {
"AssociationId": "dw-probe",
"ClientToken": "880034cd-3c62-465c-b6a4-4d06a6289dba"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisassociateVpcCidrBlock
#Description
Disassociates a CIDR block from a VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpcCidrBlockAssociationId.Malformed",
"errorMessage": "The vpc CIDR block with association ID dw-probe is malformed",
"eventCategory": "Management",
"eventID": "2cb13068-890f-40fd-90d1-946e71a4e9c7",
"eventName": "DisassociateVpcCidrBlock",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4ac86607-639b-4fb5-8027-9085467a0eb6",
"requestParameters": {
"DisassociateVpcCidrBlockRequest": {
"AssociationId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
EnableAddressTransfer
#Description
Enables Elastic IP address transfer.
EnableAllowedImagesSettings
#Description
Enables Allowed AMIs for your account in the specified Amazon Web Services Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "757ea468-81ab-4f9a-9f1e-e7083557d1b6",
"eventName": "EnableAllowedImagesSettings",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:43:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "327a587e-795a-4be9-9c6f-19219706e2cd",
"requestParameters": {
"EnableAllowedImagesSettingsRequest": {
"AllowedImagesSettingsState": "audit-mode"
}
},
"responseElements": {
"EnableAllowedImagesSettingsResponse": {
"allowedImagesSettingsState": "audit-mode",
"requestId": "327a587e-795a-4be9-9c6f-19219706e2cd",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
EnableAwsNetworkPerformanceMetricSubscription
#Description
Enables Infrastructure Performance subscriptions.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "2c24fa3c-43bf-401d-8ec7-d0e4a4e47406",
"eventName": "EnableAwsNetworkPerformanceMetricSubscription",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:46:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8f39469a-2964-4b7d-a47d-e2401c21f81c",
"requestParameters": {
"EnableAwsNetworkPerformanceMetricSubscriptionRequest": {
"Destination": "us-east-1",
"Metric": "aggregate-latency",
"Source": "us-west-1",
"Statistic": "p50"
}
},
"responseElements": {
"EnableAwsNetworkPerformanceMetricSubscriptionResponse": {
"output": true,
"requestId": "8f39469a-2964-4b7d-a47d-e2401c21f81c",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
EnableCapacityManager
#Description
Enables EC2 Capacity Manager for your account.
EnableEbsEncryptionByDefault
#Description
Enables EBS encryption by default for your account in the current Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "febe1bcf-da4c-46f1-b943-06a8027b0234",
"eventName": "EnableEbsEncryptionByDefault",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:43:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8c3d5071-9a8d-4d2e-a193-7ba04a78ba14",
"requestParameters": {
"EnableEbsEncryptionByDefaultRequest": ""
},
"responseElements": {
"EnableEbsEncryptionByDefaultResponse": {
"ebsEncryptionByDefault": true,
"requestId": "8c3d5071-9a8d-4d2e-a193-7ba04a78ba14",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
EnableFastLaunch
#Description
When you enable Windows fast launch for a Windows AMI, images are pre-provisioned, using snapshots to launch instances up to 65% faster.
EnableFastSnapshotRestores
#Description
Enables fast snapshot restores for the specified snapshots in the specified Availability Zones.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f9a27ec1-9f14-476f-ae21-ba7d1427d22a",
"eventName": "EnableFastSnapshotRestores",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:42:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "78244183-c9d4-4c9e-b343-7bbb0b350769",
"requestParameters": {
"EnableFastSnapshotRestoresRequest": {
"AvailabilityZone": {
"content": "us-west-1a",
"tag": 1
},
"SourceSnapshotId": {
"content": "snap-0ae577a47e091fcaa",
"tag": 1
}
}
},
"responseElements": {
"EnableFastSnapshotRestoresResponse": {
"requestId": "78244183-c9d4-4c9e-b343-7bbb0b350769",
"successful": {
"item": {
"availabilityZone": "us-west-1a",
"availabilityZoneId": "usw1-az1",
"enablingTime": "2026-06-29T22:42:02.187Z",
"ownerId": "123456789012",
"snapshotId": "snap-0ae577a47e091fcaa",
"state": "enabling",
"stateTransitionReason": "Client.UserInitiated"
}
},
"unsuccessful": "",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
EnableImage
#Description
Re-enables a disabled AMI.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "3c9862f6-bd90-464a-88ac-737f5d16de95",
"eventName": "EnableImage",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:45:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7f4e68ca-6332-4e39-a43b-0aece6ee8138",
"requestParameters": {
"EnableImageRequest": {
"ImageId": "ami-0d80fdb354d9dd786"
}
},
"responseElements": {
"EnableImageResponse": {
"requestId": "7f4e68ca-6332-4e39-a43b-0aece6ee8138",
"return": true,
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
EnableImageBlockPublicAccess
#Description
Enables block public access for AMIs at the account level in the specified Amazon Web Services Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "b474c8fc-d23a-40f3-a786-e54dc15cb192",
"eventName": "EnableImageBlockPublicAccess",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:43:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d62f881c-ac89-456e-b86d-3f82b62c75fa",
"requestParameters": {
"EnableImageBlockPublicAccessRequest": {
"ImageBlockPublicAccessState": "block-new-sharing"
}
},
"responseElements": {
"EnableImageBlockPublicAccessResponse": {
"imageBlockPublicAccessState": "block-new-sharing",
"requestId": "d62f881c-ac89-456e-b86d-3f82b62c75fa",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
EnableImageDeprecation
#Description
Enables deprecation of the specified AMI at the specified date and time.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "b0cea53b-210e-4b43-96e3-dd8ec5ade16e",
"eventName": "EnableImageDeprecation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:45:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5fcfcb9d-71c5-4d12-a474-894fe11d2e6b",
"requestParameters": {
"EnableImageDeprecationRequest": {
"DeprecateAt": "2027-06-29T22:45:35Z",
"ImageId": "ami-0d80fdb354d9dd786"
}
},
"responseElements": {
"EnableImageDeprecationResponse": {
"requestId": "5fcfcb9d-71c5-4d12-a474-894fe11d2e6b",
"return": true,
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
EnableImageDeregistrationProtection
#Description
Enables deregistration protection for an AMI.
EnableInstanceSqlHaStandbyDetections
#Description
Enable Amazon EC2 instances running in an SQL Server High Availability cluster for SQL Server High Availability instance standby detection monitoring.
EnableIpamOrganizationAdminAccount
#Description
Enable an Organizations member account as the IPAM admin account.
EnableIpamPolicy
#Description
Enables an IPAM policy.
EnableReachabilityAnalyzerOrganizationSharing
#Description
Establishes a trust relationship between Reachability Analyzer and Organizations.
EnableRouteServerPropagation
#Description
Defines which route tables the route server can update with routes.
EnableSnapshotBlockPublicAccess
#Description
Enables or modifies the block public access for snapshots setting at the account level for the specified Amazon Web Services Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "38c04daa-96ba-46d6-8d30-7d0fd0a33274",
"eventName": "EnableSnapshotBlockPublicAccess",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:43:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "cbe4aabc-0d4b-4078-8f8a-9fa492575ad5",
"requestParameters": {
"EnableSnapshotBlockPublicAccessRequest": {
"State": "block-new-sharing"
}
},
"responseElements": {
"EnableSnapshotBlockPublicAccessResponse": {
"requestId": "cbe4aabc-0d4b-4078-8f8a-9fa492575ad5",
"state": "block-new-sharing",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
EnableTransitGatewayRouteTablePropagation
#Description
Enables the specified attachment to propagate routes to the specified propagation route table.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "6a42b894-08a6-496b-8d24-f7a86487d00b",
"eventName": "EnableTransitGatewayRouteTablePropagation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:47:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "09a443da-853f-4834-b023-ebc8e5a37b4d",
"requestParameters": {
"EnableTransitGatewayRouteTablePropagationRequest": {
"TransitGatewayAttachmentId": "tgw-attach-08d8a09ccdcb3d355",
"TransitGatewayRouteTableId": "tgw-rtb-0f5c12c8b5c90a1a1"
}
},
"responseElements": {
"EnableTransitGatewayRouteTablePropagationResponse": {
"propagation": {
"resourceId": "vpc-00c0dad452596a616",
"resourceType": "vpc",
"state": "enabled",
"transitGatewayAttachmentId": "tgw-attach-08d8a09ccdcb3d355",
"transitGatewayRouteTableId": "tgw-rtb-0f5c12c8b5c90a1a1"
},
"requestId": "09a443da-853f-4834-b023-ebc8e5a37b4d",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
EnableVgwRoutePropagation
#Description
Enables a virtual private gateway (VGW) to propagate routes to the specified route table of a VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.Gateway.NotAttached",
"errorMessage": "resource vgw-03b7415aef1ba49a5",
"eventCategory": "Management",
"eventID": "0db1bdd8-38c9-47a1-b4f3-4b35160c8571",
"eventName": "EnableVgwRoutePropagation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:46:04Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f5cc6ebe-db89-4120-89ea-35c66b1c8300",
"requestParameters": {
"gatewayId": "vgw-03b7415aef1ba49a5",
"routeTableId": "rtb-06b1ec38aa8ffb600"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
EnableVolumeIO
#Description
Enables I/O operations for a volume that had I/O operations disabled because the data on the volume was potentially inconsistent.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "32c6b3cd-2c72-4adc-9a98-9e45d969ae44",
"eventName": "EnableVolumeIO",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-01-18T18:31:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "e2d0f0f8-ea81-4e33-a8dd-a5ba4e52c2df",
"requestParameters": {
"volumeId": "vol-8e100f305b7a6fef3"
},
"responseElements": null,
"sourceIPAddress": "184.93.254.21",
"userAgent": "aws-cli/1.14.18 Python/2.7.3 Linux/3.18.0-kali1-amd64 botocore/1.8.22",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
EnableVpcClassicLink
#Description
Enables a VPC for ClassicLink.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches AcceptVpcPeeringConnection, AttachClassicLinkVpc, CreateVpc, DeleteVpc, DetachClassicLinkVpc, DisableVpcClassicLink, ModifyVpcAttribute, RejectVpcPeeringConnection
EnableVpcClassicLinkDnsSupport
#Description
Enables a VPC to support DNS hostname resolution for ClassicLink.
ExportClientVpnClientCertificateRevocationList
#Description
Downloads the client certificate revocation list for the specified Client VPN endpoint.
ExportClientVpnClientConfiguration
#Description
Downloads the contents of the Client VPN endpoint configuration file for the specified Client VPN endpoint.
ExportTransitGatewayRoutes
#Description
Exports routes from the specified transit gateway route table to the specified S3 bucket.
ExportVerifiedAccessInstanceClientConfiguration
#Description
Exports the client configuration for a Verified Access instance.
GetActiveVpnTunnelStatus
#Description
Returns the currently negotiated security parameters for an active VPN tunnel, including IKE version, DH groups, encryption algorithms, and integrity algorithms.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpnConnectionID.NotFound",
"errorMessage": "The vpn-connection ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "7252d7a6-6382-4a27-b0df-da8af7d3dbe5",
"eventName": "GetActiveVpnTunnelStatus",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c1d5251e-3b84-41ea-bcb0-8781e7cfea6c",
"requestParameters": {
"GetActiveVpnTunnelStatusRequest": {
"VpnConnectionId": "dw-probe",
"VpnTunnelOutsideIpAddress": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetAllowedImagesSettings
#Description
Gets the current state of the Allowed AMIs setting and the list of Allowed AMIs criteria at the account level in the specified Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f63faadf-d3c3-4dfb-bb88-483e24d21421",
"eventName": "GetAllowedImagesSettings",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "87dad9b0-fe76-4aa2-8ab4-cc2b84f04c97",
"requestParameters": {
"GetAllowedImagesSettingsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetAssociatedEnclaveCertificateIamRoles
#Description
Returns the IAM roles that are associated with the specified ACM (ACM) certificate.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidCertificateArn.Malformed",
"errorMessage": "The request must contain a valid certificate arn",
"eventCategory": "Management",
"eventID": "3a10495e-9cd4-45ed-b32f-fd615f9bc1b5",
"eventName": "GetAssociatedEnclaveCertificateIamRoles",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "d7e48616-dc1f-4f12-b7d7-287e09a10702",
"requestParameters": {
"GetAssociatedEnclaveCertificateIamRolesRequest": {
"CertificateArn": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetAssociatedIpv6PoolCidrs
#Description
Gets information about the IPv6 CIDR block associations for a specified IPv6 address pool.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "9bbc54e2-f669-42bb-9c07-8c5cf62a34f6",
"eventName": "GetAssociatedIpv6PoolCidrs",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-05-19T17:44:18Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "5f73d087-c13f-48e4-a60b-949917a501c1",
"requestParameters": {
"GetAssociatedIpv6PoolCidrsRequest": {
"PoolId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "255.251.4.254",
"userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetAwsNetworkPerformanceData
#Description
Gets network performance data.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.MissingParameter",
"errorMessage": "Missing data queries parameter",
"eventCategory": "Management",
"eventID": "d8394840-4c37-4cba-81cc-327a5452e930",
"eventName": "GetAwsNetworkPerformanceData",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:53Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "374f379b-8962-403f-80fa-43ddc6e3fe5d",
"requestParameters": {
"GetAwsNetworkPerformanceDataRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetCapacityManagerAttributes
#Description
Retrieves the current configuration and status of EC2 Capacity Manager for your account, including enablement status, Organizations access settings, and data ingestion status.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.CapacityManager.Disabled",
"errorMessage": "Capacity Manager isn't enabled for this account.",
"eventCategory": "Management",
"eventID": "1ee1e079-a5fa-4dd0-a05c-2b367fe7a13e",
"eventName": "GetCapacityManagerAttributes",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:53Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "cb75c4c9-f297-4b70-a5ab-a1ae05fcd2ed",
"requestParameters": {
"GetCapacityManagerAttributesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetCapacityManagerMetricData
#Description
Retrieves capacity usage metrics for your EC2 resources.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterCombination",
"errorMessage": "EndTime must be after StartTime.",
"eventCategory": "Management",
"eventID": "b05142fe-6d1d-4f1c-9e30-f7a88e176d60",
"eventName": "GetCapacityManagerMetricData",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "4a23670d-eaea-48d9-a481-5e772a11463a",
"requestParameters": {
"GetCapacityManagerMetricDataRequest": {
"EndTime": "2020-01-01T00:00:00Z",
"MetricName": {
"content": "reservation-total-capacity-hrs-vcpu",
"tag": 1
},
"Period": 3600,
"StartTime": "2020-01-01T00:00:00Z"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetCapacityManagerMetricDimensions
#Description
Retrieves the available dimension values for capacity metrics within a specified time range.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterCombination",
"errorMessage": "EndTime must be after StartTime.",
"eventCategory": "Management",
"eventID": "78fc28d6-96af-441a-9e62-8c439a52dbdf",
"eventName": "GetCapacityManagerMetricDimensions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:12Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "28d77001-3f78-46b9-a8dc-0ad13b2b5ba5",
"requestParameters": {
"GetCapacityManagerMetricDimensionsRequest": {
"EndTime": "2020-01-01T00:00:00Z",
"GroupBy": {
"content": "resource-region",
"tag": 1
},
"MetricName": {
"content": "reservation-total-capacity-hrs-vcpu",
"tag": 1
},
"StartTime": "2020-01-01T00:00:00Z"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetCapacityManagerMonitoredTagKeys
#Description
Retrieves the tag keys that are currently being monitored by EC2 Capacity Manager.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.CapacityManager.Disabled",
"errorMessage": "Capacity Manager isn't enabled for this account.",
"eventCategory": "Management",
"eventID": "854673dd-d9b8-48d0-a228-4b0464e0a800",
"eventName": "GetCapacityManagerMonitoredTagKeys",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:53Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "d549ca48-5b44-4a17-bc5b-af819c71a6f4",
"requestParameters": {
"GetCapacityManagerMonitoredTagKeysRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetCapacityReservationUsage
#Description
Gets usage information about a Capacity Reservation.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.InvalidCapacityReservationId.Malformed",
"errorMessage": "The capacity-reservation ID 'dummy_data' is malformed",
"eventID": "85e9371b-d48d-43af-aee1-a631a6da8242",
"eventName": "GetCapacityReservationUsage",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-05-19T17:44:18Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "d7425e64-98e3-4c05-9b35-7329f9766df9",
"requestParameters": {
"GetCapacityReservationUsageRequest": {
"CapacityReservationId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "255.251.4.254",
"userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetCoipPoolUsage
#Description
Describes the allocations from the specified customer-owned address pool.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "080f4663-1dcb-44ba-aa9f-d1a55d592480",
"eventName": "GetCoipPoolUsage",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-05-19T17:44:18Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "8e8bfc66-eac7-4ad6-9b6b-54a770a17c55",
"requestParameters": {
"GetCoipPoolUsageRequest": {
"PoolId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "255.251.4.254",
"userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetConsoleOutput
#Description
Gets the console output for the specified instance.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "e13e1ac7-2a1d-43b7-b7ab-ec0d91d52fb5",
"eventName": "GetConsoleOutput",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-07-07T17:29:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "4cd4c8c2-ca0f-4f21-8c28-283bca3b03a2",
"requestParameters": {
"instanceId": "i-0630822f0d30a09ee"
},
"responseElements": null,
"sourceIPAddress": "3.142.206.200",
"userAgent": "Boto3/1.17.24 Python/3.6.13 Linux/4.19.0-17-cloud-amd64 Botocore/1.20.98",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI37S4KUWNVD",
"accountId": "797507667711",
"arn": "arn:aws:sts::797507667711:assumed-role/Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG/1625678983.751919",
"principalId": "AROA3TLZJI37S6HPJWVJ2:1625678983.751919",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T17:29:43Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:role/Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG",
"principalId": "AROA3TLZJI37S6HPJWVJ2",
"type": "Role",
"userName": "Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
References #
GetConsoleScreenshot
#Description
Retrieve a JPG-format screenshot of a running instance to help with troubleshooting.
Example CloudTrail Event #
{
"awsRegion": "us-east-2",
"eventCategory": "Management",
"eventID": "b5a1e7d2-5dd8-4fc4-ab50-7ac38ea52292",
"eventName": "GetConsoleScreenshot",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-07-07T17:29:44Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "797507667711",
"requestID": "f6270591-e0a0-471d-8470-600e7af128ec",
"requestParameters": {
"GetConsoleScreenshotRequest": {
"InstanceId": "i-0630822f0d30a09ee",
"WakeUp": true
}
},
"responseElements": null,
"sourceIPAddress": "3.142.206.200",
"userAgent": "Boto3/1.17.24 Python/3.6.13 Linux/4.19.0-17-cloud-amd64 Botocore/1.20.98",
"userIdentity": {
"accessKeyId": "ASIA3TLZJI37S4KUWNVD",
"accountId": "797507667711",
"arn": "arn:aws:sts::797507667711:assumed-role/Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG/1625678983.751919",
"principalId": "AROA3TLZJI37S6HPJWVJ2:1625678983.751919",
"sessionContext": {
"attributes": {
"creationDate": "2021-07-07T17:29:43Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {
"accountId": "797507667711",
"arn": "arn:aws:iam::797507667711:role/Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG",
"principalId": "AROA3TLZJI37S6HPJWVJ2",
"type": "Role",
"userName": "Cado-Response-myCadoResponseRole-1TT3JQ6EQN4FG"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
References #
GetDeclarativePoliciesReportSummary
#Description
Retrieves a summary of the account status report.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidDeclarativePoliciesReportId.Malformed",
"errorMessage": "The declarative-policies-report ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "b27de176-3784-4a20-8676-d678a56cb970",
"eventName": "GetDeclarativePoliciesReportSummary",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "259338a6-8301-44ef-8c20-ae9931e5398f",
"requestParameters": {
"GetDeclarativePoliciesReportSummaryRequest": {
"ReportId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetDefaultCreditSpecification
#Description
Describes the default credit option for CPU usage of a burstable performance instance family.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "10acc567-5ea8-4c0c-93a2-993d94ff614c",
"eventName": "GetDefaultCreditSpecification",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-05-19T17:44:18Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "182f8680-f2ea-44c2-b968-06adcc483ea1",
"requestParameters": {
"GetDefaultCreditSpecificationRequest": {
"InstanceFamily": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "255.251.4.254",
"userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetEnabledIpamPolicy
#Description
Gets the enabled IPAM policy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "592083cd-54ba-4cf0-92f8-ce5ece76952f",
"eventName": "GetEnabledIpamPolicy",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "e182b5fb-0127-4b7c-87ab-45d94b9bd325",
"requestParameters": {
"GetEnabledIpamPolicyRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetFlowLogsIntegrationTemplate
#Description
Generates a CloudFormation template that streamlines and automates the integration of VPC flow logs with Amazon Athena.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.MissingParameter",
"errorMessage": "The request must include the IntegrateServices parameter. Add the required parameter and retry the request.",
"eventCategory": "Management",
"eventID": "918c5973-f60d-4bb8-8caa-59851bc6395d",
"eventName": "GetFlowLogsIntegrationTemplate",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "40c15f61-4e5b-4b66-9e49-c9075995cfd3",
"requestParameters": {
"GetFlowLogsIntegrationTemplateRequest": {
"ConfigDeliveryS3DestinationArn": "dw-probe",
"FlowLogId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetGroupsForCapacityReservation
#Description
Lists the resource groups to which a Capacity Reservation has been added.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation. Encoded authorization failure message: n2jmViN2L53KhPN33l5uB0J3hLP-5h_UpLkGl58BorOtWmGe5NcK_hyEGTgUTgKCL0-NRHIylkMjMqBowGfKSZKdMxEowsEgYjNr9MOA-zDTTSMfSIsqeGbBZJ05z-9t_ZzSI3z2zCIaYDPz5alpA-Tau9cIl0s46fZ8y2KXkppUK7Y5JZYi5uz9JQRTB2ErbVOzl87Er4gArXkRbq4hKrQU_bbj_0Lsdr32mXhXYtabwD9BAb9HyyD5q2xFpnkhetM-BsWkoGQaapaG-CFuSsx1v5KE8_AAeGxgp-C4rLBiOXQrP1kxTCaGGveDqJf4xF_pI0r6QfFPpGHiF0o4wZxMxKx0w1yJYKcwGVEzNnoopjIgNgMa_e7UoFkE1tjOGBjrCPnirSo2_3uUhSI4o1YrvWgbTEt77hXM7b8Kp-dvUlgL9RL8UMmc8kX9tyvu3isLlBWHUcRbTgWdhuRubA5H2hgGIS7pdwsp_5ZLkP3G-_qu4pzzLf1c9UbOMjza-87I_DTJAaQ77f9Lpg",
"eventID": "53461c-6ff0-4191-8e7b-6a2372c3f29a",
"eventName": "GetGroupsForCapacityReservation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-09-21T04:27:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "815d0b4d-d306-4bc9-9dbb-accaae76eba7",
"requestParameters": {
"GetGroupsForCapacityReservationRequest": {
"CapacityReservationId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "9.240.250.1",
"userAgent": "Boto3/1.14.51 Python/3.8.5 Linux/4.19.76-linuxkit Botocore/1.17.51",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetHostReservationPurchasePreview
#Description
Preview a reservation purchase with configurations that match those of your Dedicated Host.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "087620b4e-bd3c-4069-a85b-72e9cacd78ef",
"eventName": "GetHostReservationPurchasePreview",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-11-10T12:01:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "469424d7e-cd01-4fb6-95ff-e7cfb5420da3",
"requestParameters": {
"GetHostReservationPurchasePreviewRequest": {
"HostIdSet": {
"content": "test",
"tag": 1
},
"OfferingId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "43.254.0.31",
"userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetImageAncestry
#Description
Retrieves the ancestry chain of the specified AMI, tracing its lineage back to the root AMI.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidAMIID.Malformed",
"errorMessage": "The image ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "81f35a16-f14e-4c4c-baf5-6f0d3d3769de",
"eventName": "GetImageAncestry",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "1943b873-3770-464a-9e57-e73463a7e170",
"requestParameters": {
"GetImageAncestryRequest": {
"ImageId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetImageBlockPublicAccessState
#Description
Gets the current state of block public access for AMIs at the account level in the specified Amazon Web Services Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "27e3c5cf-2b24-46b5-8ea6-3ee64fcec7f8",
"eventName": "GetImageBlockPublicAccessState",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "faa3de84-68f5-4cd6-88ba-043c71bc907e",
"requestParameters": {
"GetImageBlockPublicAccessStateRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetInstanceMetadataDefaults
#Description
Gets the default instance metadata service (IMDS) settings that are set at the account level in the specified Amazon Web Services Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "a30fd4b4-fe76-4ac9-8c14-c5aed5c865be",
"eventName": "GetInstanceMetadataDefaults",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "ea13785b-1982-467f-ae2c-79bf9f391036",
"requestParameters": {
"GetInstanceMetadataDefaultsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetInstanceTpmEkPub
#Description
Gets the public endorsement key associated with the Nitro Trusted Platform Module (NitroTPM) for the specified instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidInstanceID.Malformed",
"errorMessage": "The instance ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "721a1d56-6dd3-42bf-9d26-58735d7ccdbe",
"eventName": "GetInstanceTpmEkPub",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "20e34ea8-84a1-431c-8920-0288a0d7bc40",
"requestParameters": {
"GetInstanceTpmEkPubRequest": {
"InstanceId": "dw-probe",
"KeyFormat": "der",
"KeyType": "rsa-2048"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetInstanceTypesFromInstanceRequirements
#Description
Returns a list of instance types with the specified instance attributes.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "a203bf35-fd03-46a1-bb9e-f5c7a8bdb898",
"eventName": "GetInstanceTypesFromInstanceRequirements",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "cb02e203-e1d5-4866-9e51-7dc577802136",
"requestParameters": {
"GetInstanceTypesFromInstanceRequirementsRequest": {
"ArchitectureType": {
"content": "i386",
"tag": 1
},
"InstanceRequirements": {
"MemoryMiB": {
"Min": 1
},
"VCpuCount": {
"Min": 1
}
},
"VirtualizationType": {
"content": "hvm",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetInstanceUefiData
#Description
A binary representation of the UEFI variable store.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidInstanceID.Malformed",
"errorMessage": "The instance ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "4a5cf493-aa10-4ac2-9dba-b0ac121c829e",
"eventName": "GetInstanceUefiData",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:13Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "a3379a42-c24c-489a-823a-bae06543dddc",
"requestParameters": {
"GetInstanceUefiDataRequest": {
"InstanceId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetIpamAddressHistory
#Description
Retrieve historical information about a CIDR within an IPAM scope.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamScopeId.Malformed",
"errorMessage": "The ipam-scope ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "ef9b4a65-d82b-4785-8ce3-9e6a8d2f3f84",
"eventName": "GetIpamAddressHistory",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "9a36fa65-a5e5-459c-90be-e683b30099f6",
"requestParameters": {
"GetIpamAddressHistoryRequest": {
"Cidr": "dw-probe",
"IpamScopeId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetIpamDiscoveredAccounts
#Description
Gets IPAM discovered accounts.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamResourceDiscoveryId.Malformed",
"errorMessage": "The specified IPAM resource discovery ID is not valid. Specify an IPAM resource discovery ID in the form ipam-res-disco-xxxxxxxxxxxxxxxxx.",
"eventCategory": "Management",
"eventID": "968d6ccd-90eb-4b96-8c48-e80e6bb99f51",
"eventName": "GetIpamDiscoveredAccounts",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "4ea46af2-5449-48a2-b06e-472da04fd19e",
"requestParameters": {
"GetIpamDiscoveredAccountsRequest": {
"DiscoveryRegion": "dw-probe",
"IpamResourceDiscoveryId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetIpamDiscoveredPublicAddresses
#Description
Gets the public IP addresses that have been discovered by IPAM.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamResourceDiscoveryId.Malformed",
"errorMessage": "The ipam-resource-discovery ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "e5926711-037b-4739-af22-ad5a5b736a6a",
"eventName": "GetIpamDiscoveredPublicAddresses",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "dc270a67-9ca8-4430-8542-3dd4e52e45ad",
"requestParameters": {
"GetIpamDiscoveredPublicAddressesRequest": {
"AddressRegion": "dw-probe",
"IpamResourceDiscoveryId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetIpamDiscoveredResourceCidrs
#Description
Returns the resource CIDRs that are monitored as part of a resource discovery.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamResourceDiscoveryId.Malformed",
"errorMessage": "The specified IPAM resource discovery ID is not valid. Specify an IPAM resource discovery ID in the form ipam-res-disco-xxxxxxxxxxxxxxxxx.",
"eventCategory": "Management",
"eventID": "1831c654-afe5-4a7a-9d9b-43339c00adff",
"eventName": "GetIpamDiscoveredResourceCidrs",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "5c33db58-87d5-46f6-8e32-a946c0c5b1a1",
"requestParameters": {
"GetIpamDiscoveredResourceCidrsRequest": {
"IpamResourceDiscoveryId": "dw-probe",
"ResourceRegion": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetIpamPolicyAllocationRules
#Description
Gets the allocation rules for an IPAM policy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamPolicyId.Malformed",
"errorMessage": "The ipam-policy ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "69c3fa61-c8ba-4f7f-9e05-e2192e93908a",
"eventName": "GetIpamPolicyAllocationRules",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "7958f433-5e45-4b81-be25-b7d51e699ef6",
"requestParameters": {
"GetIpamPolicyAllocationRulesRequest": {
"IpamPolicyId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetIpamPolicyOrganizationTargets
#Description
Gets the Amazon Web Services Organizations targets for an IPAM policy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamPolicyId.Malformed",
"errorMessage": "The ipam-policy ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "95f70605-0f76-4c10-959e-993342b2a793",
"eventName": "GetIpamPolicyOrganizationTargets",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "d6af9561-42d6-458f-9ecf-a3b70e3358c5",
"requestParameters": {
"GetIpamPolicyOrganizationTargetsRequest": {
"IpamPolicyId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetIpamPoolAllocations
#Description
Get a list of all the CIDR allocations in an IPAM pool.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamPoolId.Malformed",
"errorMessage": "The specified IPAM pool ID is not valid. Specify an IPAM pool ID in the form ipam-pool-xxxxxxxxxxxxxxxxx.",
"eventCategory": "Management",
"eventID": "3fb029cf-a3cc-477b-90a1-be216a4072d4",
"eventName": "GetIpamPoolAllocations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "fdf2fc96-b808-4aab-ac99-7fd39327ced0",
"requestParameters": {
"GetIpamPoolAllocationsRequest": {
"IpamPoolId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetIpamPoolCidrs
#Description
Get the CIDRs provisioned to an IPAM pool.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamPoolId.Malformed",
"errorMessage": "The specified IPAM pool ID is not valid. Specify an IPAM pool ID in the form ipam-pool-xxxxxxxxxxxxxxxxx.",
"eventCategory": "Management",
"eventID": "0811c7b7-7b80-45d4-8cac-172679451e95",
"eventName": "GetIpamPoolCidrs",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "aae9b16a-144a-4190-8c1a-b1749a8f15f5",
"requestParameters": {
"GetIpamPoolCidrsRequest": {
"IpamPoolId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetIpamPrefixListResolverRules
#Description
Retrieves the CIDR selection rules for an IPAM prefix list resolver.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamPrefixListResolverId.Malformed",
"errorMessage": "The ipam-prefix-list-resolver ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "35fc83d3-c269-4b87-babe-a2af901efce2",
"eventName": "GetIpamPrefixListResolverRules",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "e82de3a1-ef4f-4b6b-ad40-7484f1d34628",
"requestParameters": {
"GetIpamPrefixListResolverRulesRequest": {
"IpamPrefixListResolverId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetIpamPrefixListResolverVersionEntries
#Description
Retrieves the CIDR entries for a specific version of an IPAM prefix list resolver.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamPrefixListResolverId.Malformed",
"errorMessage": "The ipam-prefix-list-resolver ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "30af075d-f564-4945-bc83-eb59da83c24e",
"eventName": "GetIpamPrefixListResolverVersionEntries",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "71d23c0f-1e7e-4536-b51f-5570633b41c7",
"requestParameters": {
"GetIpamPrefixListResolverVersionEntriesRequest": {
"IpamPrefixListResolverId": "dw-probe",
"IpamPrefixListResolverVersion": 1
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetIpamPrefixListResolverVersions
#Description
Retrieves version information for an IPAM prefix list resolver.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamPrefixListResolverId.Malformed",
"errorMessage": "The ipam-prefix-list-resolver ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "4e05c503-8d1e-4c18-a9aa-dcd651898642",
"eventName": "GetIpamPrefixListResolverVersions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:16Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "0182edda-dcb2-4452-aa17-a9807e5edefd",
"requestParameters": {
"GetIpamPrefixListResolverVersionsRequest": {
"IpamPrefixListResolverId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetIpamResourceCidrs
#Description
Returns resource CIDRs managed by IPAM in a given scope.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamScopeId.Malformed",
"errorMessage": "The specified IPAM scope ID is not valid. Specify an IPAM scope ID in the form ipam-scope-xxxxxxxxxxxxxxxxx.",
"eventCategory": "Management",
"eventID": "9839bd9d-2d22-4b48-95dc-1403a02c0ab2",
"eventName": "GetIpamResourceCidrs",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:16Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "f451aba3-d9a3-4850-a5b5-83ceb70fca40",
"requestParameters": {
"GetIpamResourceCidrsRequest": {
"IpamScopeId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetLaunchTemplateData
#Description
Retrieves the configuration data of the specified instance.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "c5afea9e-09db-444c-97a3-545459a6aa",
"eventName": "GetLaunchTemplateData",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-11-10T12:01:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "755bb977-df50-4cd3-b2d6-5fdd3f2d0fc2",
"requestParameters": {
"GetLaunchTemplateDataRequest": {
"InstanceId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "43.254.0.31",
"userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetManagedPrefixListAssociations
#Description
Gets information about the resources that are associated with the specified managed prefix list.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "fa18e079-2317-437e-9a46-4fe99e6e6e4a",
"eventName": "GetManagedPrefixListAssociations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-07-20T15:26:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "41bef85a-e95e-484d-8168-5de2dfe831315",
"requestParameters": {
"GetManagedPrefixListAssociationsRequest": {
"PrefixListId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "105.204.6.57",
"userAgent": "Boto3/1.14.20 Python/3.8.2 Linux/5.4.0-40-generic Botocore/1.17.20",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
GetManagedPrefixListEntries
#Description
Gets information about the entries for a specified managed prefix list.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation. Encoded authorization failure message: yAKdGWY5sn5xqtrskcTboMjjYWXJ6k7LqCK7yT-GFmfFW8uKSqKdx4cObEbgAwxL7KPebKYCF7U35p6v1b1nPUUSdaefFU11gx1AybkcufCTQ3ov8GGTJ-03smp4qdcnJHZQLdgcbVtcMwUowvSsT760fHrsonB4JryJYkhnVw0FImJDvaczS1SmAlYR3aNHa5aDe5bBafAvHd0MU1u3bZkxz8DLBvdbV2k5OGE8iXTN5bi6F6Gm0yLNgb2ZtXlw7uysXDStcr-l2bL57shyyi9uixsbuGe1Fxst9Z8Wx3WaAxxqVUY2sFYu7bH6oe0wpz2XnPmeOuafVevAi9Izo5s41WVomRqU4zs2CCI1ZFQM2xtl6IlHZkERPmCLquUVVz9UHHn77FlDEpCwGfGrGxibMvGAO3ANN0cSMLy37pUTe0VDlCk9CMndFj8XIZSe7EilTsVtKfnoMd5LmcU91GFO4TM2s8p-tNt95JqbcdCj62QlnFO0IN64A4HC1MMS8MZAgJ8EWGlpbeP_kRo",
"eventID": "275f2526-1284-4bc0-b71d-8d13a21ab87a",
"eventName": "GetManagedPrefixListEntries",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-07-20T15:26:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "2ddc2b23-1a72-470b-9333-fd8a486dd10f",
"requestParameters": {
"GetManagedPrefixListEntriesRequest": {
"PrefixListId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "105.204.6.57",
"userAgent": "Boto3/1.14.20 Python/3.8.2 Linux/5.4.0-40-generic Botocore/1.17.20",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
GetManagedResourceVisibility
#Description
Retrieves the managed resource visibility configuration for the account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "3544a2d1-1aa4-47ef-a30c-82a51c43dc84",
"eventName": "GetManagedResourceVisibility",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "52f579a7-0389-42a1-8a15-deab0a2ff002",
"requestParameters": {
"GetManagedResourceVisibilityRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetNetworkInsightsAccessScopeAnalysisFindings
#Description
Gets the findings for the specified Network Access Scope analysis.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "dw-probe is not a valid NetworkInsightsAccessScopeAnalysisId.",
"eventCategory": "Management",
"eventID": "ed754418-43dc-45c5-8a51-b4d0064ae315",
"eventName": "GetNetworkInsightsAccessScopeAnalysisFindings",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:16Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "953f5adc-8531-42ea-a4c8-ad24d822ec4a",
"requestParameters": {
"GetNetworkInsightsAccessScopeAnalysisFindingsRequest": {
"NetworkInsightsAccessScopeAnalysisId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetNetworkInsightsAccessScopeContent
#Description
Gets the content for the specified Network Access Scope.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "dw-probe is not a valid NetworkInsightsAccessScopeId.",
"eventCategory": "Management",
"eventID": "ccaa3962-7656-4930-9d61-b43e11af1889",
"eventName": "GetNetworkInsightsAccessScopeContent",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:16Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "52ebab74-0430-45a9-82f9-fc70e8a5f753",
"requestParameters": {
"GetNetworkInsightsAccessScopeContentRequest": {
"NetworkInsightsAccessScopeId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetReservedInstancesExchangeQuote
#Description
Returns details about the values and term of your specified Convertible Reserved Instances.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "5d669dd7-a4d8-4b7b-adee-bf6fa7dbc032",
"eventName": "GetReservedInstancesExchangeQuote",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-11-10T12:01:53Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "0830e907-c5a7-4a85-84b3-c8f878ca30c2",
"requestParameters": {
"GetReservedInstancesExchangeQuoteRequest": {
"ReservedInstanceId": {
"content": "test",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "43.254.0.31",
"userAgent": "Boto3/1.7.48 Python/3.6.7 Linux/4.4.0-53329-Microsoft Botocore/1.10.48",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetRouteServerAssociations
#Description
Gets information about the associations for the specified route server.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRouteServerId.Malformed",
"errorMessage": "The route-server ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "8799992a-3d77-42ea-97b4-74f5e5c80956",
"eventName": "GetRouteServerAssociations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:17Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "39e1d15f-7009-4901-a2b9-f8947bc0602d",
"requestParameters": {
"GetRouteServerAssociationsRequest": {
"RouteServerId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetRouteServerPropagations
#Description
Gets information about the route propagations for the specified route server.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRouteServerId.Malformed",
"errorMessage": "The route-server ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "2cc34321-5e45-4bdf-8a17-b9f7cd085b48",
"eventName": "GetRouteServerPropagations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:17Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "d180cebf-0de0-48cd-aff4-6bf965927a24",
"requestParameters": {
"GetRouteServerPropagationsRequest": {
"RouteServerId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetRouteServerRoutingDatabase
#Description
Gets the routing database for the specified route server.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRouteServerId.Malformed",
"errorMessage": "The route-server ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "fed53428-66c2-488b-aaaa-fd1b0c2fb2a1",
"eventName": "GetRouteServerRoutingDatabase",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:17Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "1d5938cd-5941-48fe-9caa-66a1b4baa87f",
"requestParameters": {
"GetRouteServerRoutingDatabaseRequest": {
"RouteServerId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetSecurityGroupsForVpc
#Description
Gets security groups that can be associated by the Amazon Web Services account making the request with network interfaces in the specified VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpcId.Malformed",
"errorMessage": "The vpc ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "19741f83-5b0f-414d-b97d-80afb52eabe5",
"eventName": "GetSecurityGroupsForVpc",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:17Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "bf81fdf7-6c67-4814-802b-d603bc44b0f0",
"requestParameters": {
"GetSecurityGroupsForVpcRequest": {
"VpcId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetSerialConsoleAccessStatus
#Description
Retrieves the access status of your account to the EC2 serial console of all instances.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "8a0e1ed4-37a2-4499-9733-a0e39174f698",
"eventName": "GetSerialConsoleAccessStatus",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "1fa55ef6-ebdd-4399-8708-2d5b226f701b",
"requestParameters": {
"GetSerialConsoleAccessStatusRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetSnapshotBlockPublicAccessState
#Description
Gets the current state of block public access for snapshots setting for the account and Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "6c97b418-864d-453e-8f18-2d8da3b5fd12",
"eventName": "GetSnapshotBlockPublicAccessState",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "8312e87a-cfde-4e00-b568-3e131d47bf8f",
"requestParameters": {
"GetSnapshotBlockPublicAccessStateRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetSpotPlacementScores
#Description
Calculates the Spot placement score for a Region or Availability Zone based on the specified target capacity and compute requirements.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.MissingParameter",
"errorMessage": "The request must contain either InstanceTypes or InstanceRequirements, but not both.",
"eventCategory": "Management",
"eventID": "dd7b9b65-b185-46bd-b019-344c1b05bc4f",
"eventName": "GetSpotPlacementScores",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:17Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "f680b345-b516-48f6-8a63-843e5b6d05e6",
"requestParameters": {
"GetSpotPlacementScoresRequest": {
"TargetCapacity": 1
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetSubnetCidrReservations
#Description
Gets information about the subnet CIDR reservations.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "Invalid value 'dw-probe' for subnetId.",
"eventCategory": "Management",
"eventID": "233da6a8-0353-43df-8f3f-b8714c4a41d2",
"eventName": "GetSubnetCidrReservations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:18Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "25f42b9f-4418-4799-a131-6bd5804bc338",
"requestParameters": {
"GetSubnetCidrReservationsRequest": {
"SubnetId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetTransitGatewayAttachmentPropagations
#Description
Lists the route tables to which the specified resource attachment propagates routes.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "6bb0f9c8-6b0c-4403-81a6-3dcfe145217de",
"eventName": "GetTransitGatewayAttachmentPropagations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-05-19T17:44:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "c7784b3c-33c7-4476-88f7-63de2daa476b",
"requestParameters": {
"GetTransitGatewayAttachmentPropagationsRequest": {
"TransitGatewayAttachmentId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "255.251.4.254",
"userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetTransitGatewayMeteringPolicyEntries
#Description
Retrieves the entries for a transit gateway metering policy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayMeteringPolicyIdMalformedException",
"errorMessage": "The transit-gateway-metering-policy ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "87a4c79d-ae21-4068-9aa3-787bb24b45b0",
"eventName": "GetTransitGatewayMeteringPolicyEntries",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:18Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "40316bed-1afc-4db3-8101-c294aabcfe60",
"requestParameters": {
"GetTransitGatewayMeteringPolicyEntriesRequest": {
"TransitGatewayMeteringPolicyId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetTransitGatewayMulticastDomainAssociations
#Description
Gets information about the associations for the transit gateway multicast domain.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "7a08a086-801c-400a-9920-92ec7a0b6a33",
"eventName": "GetTransitGatewayMulticastDomainAssociations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-05-19T17:44:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "f84ffe43-b30b-402d-98f3-2cad954190ba",
"requestParameters": {
"GetTransitGatewayMulticastDomainAssociationsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "255.251.4.254",
"userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetTransitGatewayPolicyTableAssociations
#Description
Gets a list of the transit gateway policy table associations.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayPolicyTableId.Malformed",
"errorMessage": "The transit-gateway-policy-table ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "63d7a1bc-de46-46f5-bbe3-1e42eacc007f",
"eventName": "GetTransitGatewayPolicyTableAssociations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:18Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "adb43c76-258e-447a-9f8f-c68e9bbf11b5",
"requestParameters": {
"GetTransitGatewayPolicyTableAssociationsRequest": {
"TransitGatewayPolicyTableId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetTransitGatewayPolicyTableEntries
#Description
Returns a list of transit gateway policy table entries.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayPolicyTableId.Malformed",
"errorMessage": "The transit-gateway-policy-table ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "8eb1e2b1-186d-452e-8d4a-2f2e4f7d5bfe",
"eventName": "GetTransitGatewayPolicyTableEntries",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:18Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "3f5db42d-b6d4-4c7d-a165-8e3281468ce6",
"requestParameters": {
"GetTransitGatewayPolicyTableEntriesRequest": {
"TransitGatewayPolicyTableId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetTransitGatewayPrefixListReferences
#Description
Gets information about the prefix list references in a specified transit gateway route table.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "0a9ec832-e2af-4dbb-9e16-f23c80e7a373",
"eventName": "GetTransitGatewayPrefixListReferences",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-09-21T04:27:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "76ad76e7-221e-49c6-a6d1-cd9ebbe426993",
"requestParameters": {
"GetTransitGatewayPrefixListReferencesRequest": {
"TransitGatewayRouteTableId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "9.240.250.1",
"userAgent": "Boto3/1.14.51 Python/3.8.5 Linux/4.19.76-linuxkit Botocore/1.17.51",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetTransitGatewayRouteTablePropagations
#Description
Gets information about the route table propagations for the specified transit gateway route table.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "9eae5a5a-5d5c-435b-82a9-b8bf0d194ff8",
"eventName": "GetTransitGatewayRouteTablePropagations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2020-05-19T17:44:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "1dc285747-2084-4339-be75-a1b22a227785f",
"requestParameters": {
"GetTransitGatewayRouteTablePropagationsRequest": {
"TransitGatewayRouteTableId": "dummy_data"
}
},
"responseElements": null,
"sourceIPAddress": "255.251.4.254",
"userAgent": "Boto3/1.13.12 Python/3.6.9 Linux/5.3.0-1017-aws Botocore/1.16.12",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
GetVerifiedAccessEndpointPolicy
#Description
Get the Verified Access policy associated with the endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVerifiedAccessEndpointId.NotFound",
"errorMessage": "VerifiedAccessEndpoint dw-probe does not exist",
"eventCategory": "Management",
"eventID": "abfd5096-d6b6-46ca-93dc-5687422ad972",
"eventName": "GetVerifiedAccessEndpointPolicy",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:18Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "336fba56-08aa-4489-beb7-3379fce9c545",
"requestParameters": {
"GetVerifiedAccessEndpointPolicyRequest": {
"VerifiedAccessEndpointId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetVerifiedAccessEndpointTargets
#Description
Gets the targets for the specified network CIDR endpoint for Verified Access.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVerifiedAccessEndpointId.NotFound",
"errorMessage": "VerifiedAccessEndpoint dw-probe does not exist",
"eventCategory": "Management",
"eventID": "e91dd203-7eab-4621-8bfd-ab57ef2adaa6",
"eventName": "GetVerifiedAccessEndpointTargets",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "4c409015-e9d2-415a-b2ef-1b991aa4b15c",
"requestParameters": {
"GetVerifiedAccessEndpointTargetsRequest": {
"VerifiedAccessEndpointId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetVerifiedAccessGroupPolicy
#Description
Shows the contents of the Verified Access policy associated with the group.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVerifiedAccessGroupId.NotFound",
"errorMessage": "VerifiedAccessGroup dw-probe does not exist",
"eventCategory": "Management",
"eventID": "a11eaecd-1a02-41b3-b29f-213f1c8f3568",
"eventName": "GetVerifiedAccessGroupPolicy",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "8257e787-438d-43c7-bdef-b629a3dd4869",
"requestParameters": {
"GetVerifiedAccessGroupPolicyRequest": {
"VerifiedAccessGroupId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetVpcResourcesBlockingEncryptionEnforcement
#Description
Gets information about resources in a VPC that are blocking encryption enforcement.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpcId.Malformed",
"errorMessage": "The vpc ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "f85ac521-c612-4b8a-83ce-3a0caf824b95",
"eventName": "GetVpcResourcesBlockingEncryptionEnforcement",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "bd594b0a-36a1-4eee-85c6-bca352a67d9f",
"requestParameters": {
"GetVpcResourcesBlockingEncryptionEnforcementRequest": {
"VpcId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetVpnConnectionDeviceSampleConfiguration
#Description
Download an Amazon Web Services-provided sample configuration file to be used with the customer gateway device specified for your Site-to-Site VPN connection.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpnConnectionDeviceTypeId.NotFound",
"errorMessage": "Invalid vpn connection device type id specified.",
"eventCategory": "Management",
"eventID": "14376254-f878-4ccb-ba18-1d361713505a",
"eventName": "GetVpnConnectionDeviceSampleConfiguration",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "105b35e3-98f6-40a2-bcd8-e2e1d421d051",
"requestParameters": {
"GetVpnConnectionDeviceSampleConfigurationRequest": {
"VpnConnectionDeviceTypeId": "dw-probe",
"VpnConnectionId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetVpnConnectionDeviceTypes
#Description
Obtain a list of customer gateway devices for which sample configuration files can be provided.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "9aa190e0-7396-4541-b82b-d4caa88327dc",
"eventName": "GetVpnConnectionDeviceTypes",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "64fcecb6-fd51-4b70-9d57-3deb573d05b4",
"requestParameters": {
"GetVpnConnectionDeviceTypesRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
GetVpnTunnelReplacementStatus
#Description
Get details of available tunnel endpoint maintenance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpnConnectionID.NotFound",
"errorMessage": "The vpnConnection ID 'dw-probe' does not exist",
"eventCategory": "Management",
"eventID": "b09a1e0b-cfb7-48ee-bc77-24448292ebce",
"eventName": "GetVpnTunnelReplacementStatus",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "6b03969e-5a56-42c0-9da3-724c83cd1893",
"requestParameters": {
"GetVpnTunnelReplacementStatusRequest": {
"VpnConnectionId": "dw-probe",
"VpnTunnelOutsideIpAddress": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ImportClientVpnClientCertificateRevocationList
#Description
Uploads a client certificate revocation list to the specified Client VPN endpoint.
ImportImage
#Description
Import single or multi-volume disk images or Amazon EBS snapshots into an Amazon Machine Image (AMI).
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
aws::errorCode (panther rule field) | ne | Client.DryRunOperation | 1 rule | panther |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1204↳ also matches CreateStoreImageTask, CopyFpgaImage, CopyImage, CreateFpgaImage, CreateImage, CreateRestoreImageTask
ImportInstance
#Description
Creates an import instance task using metadata from the specified disk image.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
ImportSnapshot
#Description
Import a disk into an Amazon Elastic Block Store (Amazon EBS) snapshot.
ImportVolume
#Description
Creates an import volume task using metadata from the specified disk image.
ListImagesInRecycleBin
#Description
Lists one or more AMIs that are currently in the Recycle Bin.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "e2c1d1cb-fadb-46eb-a5d2-814137afcde4",
"eventName": "ListImagesInRecycleBin",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "57feb0cf-94b5-452d-8e11-6fc0265101d2",
"requestParameters": {
"ListImagesInRecycleBinRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListSnapshotsInRecycleBin
#Description
Lists one or more snapshots that are currently in the Recycle Bin.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "079eef97-f422-4a7d-9f2c-0b9a79766434",
"eventName": "ListSnapshotsInRecycleBin",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "c33211c9-ab85-4bdc-a027-d05e181d5623",
"requestParameters": {
"ListSnapshotsInRecycleBinRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListVolumesInRecycleBin
#Description
Lists one or more volumes that are currently in the Recycle Bin.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "e0d4e541-2a68-4f80-af00-123ae158081c",
"eventName": "ListVolumesInRecycleBin",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:31:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "37af0e01-8ab9-4520-a1ae-91264a8963e1",
"requestParameters": {
"ListVolumesInRecycleBinRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
LockSnapshot
#Description
Locks an Amazon EBS snapshot in either governance or compliance mode to protect it against accidental or malicious deletions for a specific duration.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f79852db-0c57-4a52-8bac-ad195b623d9b",
"eventName": "LockSnapshot",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:42:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "91315e94-65fd-47e5-a442-b3e1f0c14ec3",
"requestParameters": {
"LockSnapshotRequest": {
"LockDuration": 1,
"LockMode": "governance",
"SnapshotId": "snap-0c0fb4e5cd0eee943"
}
},
"responseElements": {
"LockSnapshotResponse": {
"lockCreatedOn": "2026-06-29T22:42:01.690Z",
"lockDuration": 1,
"lockDurationStartTime": "2026-06-29T22:42:01.690Z",
"lockExpiresOn": "2026-06-30T22:42:01.690Z",
"lockState": "governance",
"requestId": "91315e94-65fd-47e5-a442-b3e1f0c14ec3",
"snapshotId": "snap-0c0fb4e5cd0eee943",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyAddressAttribute
#Description
Modifies an attribute of the specified Elastic IP address.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidAllocationID.NotFound",
"errorMessage": "The allocation ID 'dw-probe' does not exist",
"eventCategory": "Management",
"eventID": "c4279fa1-6468-4b37-b94e-d713f8fd2dfc",
"eventName": "ModifyAddressAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ee20b5af-c3ac-4b51-b343-409b594a34c3",
"requestParameters": {
"ModifyAddressAttributeRequest": {
"AllocationId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyAvailabilityZoneGroup
#Description
Changes the opt-in status of the specified zone group for your account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidAZGroup.NotFound",
"errorMessage": "Invalid Availability Zone group provided",
"eventCategory": "Management",
"eventID": "33f4acca-d340-4ab2-9e52-d69259452bf2",
"eventName": "ModifyAvailabilityZoneGroup",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:48Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c1f2a362-aeaa-410c-a9ee-0036efd8a62e",
"requestParameters": {
"ModifyAvailabilityZoneGroupRequest": {
"GroupName": "dw-probe",
"OptInStatus": "opted-in"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyCapacityReservation
#Description
Modifies a Capacity Reservation's capacity, instance eligibility, and the conditions under which it is to be released.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidCapacityReservationId.Malformed",
"errorMessage": "Capacity Reservation ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "0ddd927b-1882-4e2e-b05b-d4453970827b",
"eventName": "ModifyCapacityReservation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b3c4ce0a-8102-4cb4-93b9-6034d6e1b69a",
"requestParameters": {
"ModifyCapacityReservationRequest": {
"CapacityReservationId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyCapacityReservationFleet
#Description
Modifies a Capacity Reservation Fleet.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidCapacityReservationFleetId.Malformed",
"errorMessage": "The capacity-reservation-fleet ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "628aac8c-1318-48f8-b6a1-9d34d90b147e",
"eventName": "ModifyCapacityReservationFleet",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "68e7f3fc-ba7f-47dc-b6a4-e7b0aa8498f7",
"requestParameters": {
"ModifyCapacityReservationFleetRequest": {
"CapacityReservationFleetId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyClientVpnEndpoint
#Description
Modifies the specified Client VPN endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidClientVpnEndpointId.NotFound",
"errorMessage": "The client-vpn-endpoint ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "abe430e5-52ef-4df6-bb4a-6da3ee4f3028",
"eventName": "ModifyClientVpnEndpoint",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "bbef9c62-f40c-4579-ad7d-5f1313b3c519",
"requestParameters": {
"ModifyClientVpnEndpointRequest": {
"ClientVpnEndpointId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyDefaultCreditSpecification
#Description
Modifies the default credit option for CPU usage of burstable performance instances.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "The CpuCredits parameter requires a value of either Standard or Unlimited. Change the value and try again.",
"eventCategory": "Management",
"eventID": "4ab56216-ec4c-4542-993f-862d11e14ca5",
"eventName": "ModifyDefaultCreditSpecification",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:49Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4ac57f66-bce1-4656-823e-4f81f5a072e4",
"requestParameters": {
"ModifyDefaultCreditSpecificationRequest": {
"CpuCredits": "dw-probe",
"InstanceFamily": "t2"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyEbsDefaultKmsKeyId
#Description
Changes the default KMS key for EBS encryption by default for your account in this Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "Invalid keyId 'dw-probe'",
"eventCategory": "Management",
"eventID": "a367bf43-a953-4611-a133-75e3ba12ef32",
"eventName": "ModifyEbsDefaultKmsKeyId",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e3f5c9ee-b251-4a0c-96e1-571795ca8c8a",
"requestParameters": {
"ModifyEbsDefaultKmsKeyIdRequest": {
"KmsKeyId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyFleet
#Description
Modifies the specified EC2 Fleet.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidFleetId.Malformed",
"errorMessage": "Provided Fleet Id Malformed",
"eventCategory": "Management",
"eventID": "da4df8df-f8be-45aa-a25e-d57918caa683",
"eventName": "ModifyFleet",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6ab2f13c-4b60-4a41-89f9-1a665398c0dd",
"requestParameters": {
"ModifyFleetRequest": {
"FleetId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyFpgaImageAttribute
#Description
Modifies the specified attribute of the specified Amazon FPGA Image (AFI).
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.UnsupportedOperation",
"errorMessage": "The functionality you requested is not available in this region.",
"eventCategory": "Management",
"eventID": "95c5fee5-8e25-42fa-b9ea-5c2e0101e648",
"eventName": "ModifyFpgaImageAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d39f3e02-6cfa-463c-8115-a345bf92b6ca",
"requestParameters": {
"ModifyFpgaImageAttributeRequest": {
"FpgaImageId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyHosts
#Description
Modify the auto-placement setting of a Dedicated host.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f330d400-fd0a-4d79-969d-e54dae101c1e",
"eventName": "ModifyHosts",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d6574d82-79ba-4a03-b3d3-5fd84bc5531b",
"requestParameters": {
"ModifyHostsRequest": {
"HostId": {
"content": "dw-probe",
"tag": 1
}
}
},
"responseElements": {
"ModifyHostsResponse": {
"requestId": "d6574d82-79ba-4a03-b3d3-5fd84bc5531b",
"successful": "",
"unsuccessful": {
"item": {
"error": {
"code": "Client.InvalidHostID.Malformed",
"message": "The specified Dedicated host IDs ['dw-probe'] are not valid."
},
"resourceId": "dw-probe"
}
},
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyIdentityIdFormat
#Description
Modifies the ID format of a resource for a specified IAM user, IAM role, or the root user for an account; or all IAM users, IAM roles, and the root user for an account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "b6018819-d387-43d2-9dca-f86435142d20",
"eventName": "ModifyIdentityIdFormat",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "635ea9a5-8617-4050-a1a8-e22c893ed898",
"requestParameters": {
"ModifyIdentityIdFormatRequest": {
"PrincipalArn": "dw-probe",
"Resource": "dw-probe",
"UseLongIds": false
}
},
"responseElements": {
"ModifyIdentityIdFormatResponse": {
"requestId": "635ea9a5-8617-4050-a1a8-e22c893ed898",
"return": true,
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyIdFormat
#Description
Modifies the ID format for the specified resource on a per-region basis.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "bbedb9d1-b916-4b3d-b14f-c5a7582b6006",
"eventName": "ModifyIdFormat",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "dde49649-0a4b-498e-846c-10aeaf1899da",
"requestParameters": {
"resource": "dw-probe",
"useLongIds": false
},
"responseElements": {
"_return": true,
"requestId": "dde49649-0a4b-498e-846c-10aeaf1899da"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyInstanceCapacityReservationAttributes
#Description
Modifies the Capacity Reservation settings for a stopped instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "Required field \"instance-id\" missing or malformed.",
"eventCategory": "Management",
"eventID": "0ab69c83-423a-4f0b-89eb-3b5d0cadd9a1",
"eventName": "ModifyInstanceCapacityReservationAttributes",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e062c873-5dd9-44e2-a06b-7e013de988a6",
"requestParameters": {
"ModifyInstanceCapacityReservationAttributesRequest": {
"InstanceId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
ModifyInstanceConnectEndpoint
#Description
Modifies the specified EC2 Instance Connect Endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidInstanceConnectEndpointId.Malformed",
"errorMessage": "The instance-connect-endpoint ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "b316e87c-8143-48d0-9afe-79b4693f4eed",
"eventName": "ModifyInstanceConnectEndpoint",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:50Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2422a05e-c772-468d-9908-2f5f58702b2e",
"requestParameters": {
"ModifyInstanceConnectEndpointRequest": {
"InstanceConnectEndpointId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyInstanceCpuOptions
#Description
By default, all vCPUs for the instance type are active when you launch an instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidInstanceID.Malformed",
"errorMessage": "The instance ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "cae2ee33-1864-4d51-b7f9-7a2f242012d1",
"eventName": "ModifyInstanceCpuOptions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2dac5ac6-6db4-49c1-8d2b-7bacd890421f",
"requestParameters": {
"ModifyInstanceCpuOptionsRequest": {
"InstanceId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyInstanceCreditSpecification
#Description
Modifies the credit option for CPU usage on a running or stopped burstable performance instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidInstanceID.Malformed",
"errorMessage": "The instance ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "e2edb421-bec6-429a-a8f4-37f14c8ee6b9",
"eventName": "ModifyInstanceCreditSpecification",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "fe2c798d-5421-40a3-9f8a-94929e72eefd",
"requestParameters": {
"ModifyInstanceCreditSpecificationRequest": {
"InstanceCreditSpecification": {
"InstanceId": "dw-probe",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
ModifyInstanceEventStartTime
#Description
Modifies the start time for a scheduled Amazon EC2 instance event.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidInstanceID.Malformed",
"errorMessage": "The instance ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "0235115e-533b-441b-8a79-2123efa16af9",
"eventName": "ModifyInstanceEventStartTime",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:51Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "783a6804-7784-4689-aab7-3ac84cfde418",
"requestParameters": {
"ModifyInstanceEventStartTimeRequest": {
"InstanceEventId": "dw-probe",
"InstanceId": "dw-probe",
"NotBefore": "2020-01-01T00:00:00Z"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
ModifyInstanceEventWindow
#Description
Modifies the specified event window.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidInstanceEventWindowId.Malformed",
"errorMessage": "The instance-event-window ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "43225947-9121-4b2c-9cb0-d68a5afe0b1c",
"eventName": "ModifyInstanceEventWindow",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a009c721-6630-4efd-9b0d-b9e7791dc996",
"requestParameters": {
"ModifyInstanceEventWindowRequest": {
"InstanceEventWindowId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
ModifyInstanceMaintenanceOptions
#Description
Modifies the recovery behavior of your instance to disable simplified automatic recovery or set the recovery behavior to default.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidInstanceID.Malformed",
"errorMessage": "The instance ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "ad7f3182-169e-43dc-add3-3865a8142477",
"eventName": "ModifyInstanceMaintenanceOptions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "eef1f3a4-c07f-42e7-befc-70b01bbfd675",
"requestParameters": {
"ModifyInstanceMaintenanceOptionsRequest": {
"InstanceId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
ModifyInstanceMetadataDefaults
#Description
Modifies the default instance metadata service (IMDS) settings at the account level in the specified Amazon Web Services Region.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "d97d67d6-ee8a-42a0-a5ed-284d93706aa7",
"eventName": "ModifyInstanceMetadataDefaults",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:40:26Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8a67a582-c580-4d79-90b2-c353afafbb44",
"requestParameters": {
"ModifyInstanceMetadataDefaultsRequest": {
"HttpEndpoint": "enabled",
"HttpTokens": "optional",
"InstanceMetadataTags": "disabled"
}
},
"responseElements": {
"ModifyInstanceMetadataDefaultsResponse": {
"requestId": "8a67a582-c580-4d79-90b2-c353afafbb44",
"return": true,
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyInstanceMetadataOptions
#Description
Modify the instance metadata parameters on a running or stopped instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidInstanceID.Malformed",
"errorMessage": "The instance ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "28065793-2eff-4e65-b150-de60c4e53dab",
"eventName": "ModifyInstanceMetadataOptions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b35a3525-78e7-4484-b15c-1a6228a9f256",
"requestParameters": {
"ModifyInstanceMetadataOptionsRequest": {
"InstanceId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
ModifyInstanceNetworkPerformanceOptions
#Description
Change the configuration of the network performance options for an existing instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidInstanceID.Malformed",
"errorMessage": "The instance ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "6defc50a-8083-4425-bdb2-362fad475636",
"eventName": "ModifyInstanceNetworkPerformanceOptions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:53Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c938a197-41b6-4ac6-a7aa-347448a7fa52",
"requestParameters": {
"ModifyInstanceNetworkPerformanceOptionsRequest": {
"BandwidthWeighting": "default",
"InstanceId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyInstancePlacement
#Description
Set the instance affinity value for a specific stopped instance and modify the instance tenancy setting.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidInstanceID.Malformed",
"errorMessage": "The given virtId: dw-probe is not valid",
"eventCategory": "Management",
"eventID": "4fae0b9f-62ef-4ec3-9584-6c24895abe47",
"eventName": "ModifyInstancePlacement",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:53Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "32f4f45f-13b5-4912-8f68-7e853b2a908a",
"requestParameters": {
"ModifyInstancePlacementRequest": {
"InstanceId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
ModifyIpam
#Description
Modify the configurations of an IPAM.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamId.Malformed",
"errorMessage": "The specified IPAM Id is not valid. Specify an IPAM Id in the form ipam-xxxxxxxxxxxxxxxxx.",
"eventCategory": "Management",
"eventID": "7db95047-3d8d-40b3-8a85-b3aa13f2b57e",
"eventName": "ModifyIpam",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:53Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5bf02d1f-cecb-4f5f-9936-6b42e88fb7d9",
"requestParameters": {
"ModifyIpamRequest": {
"IpamId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyIpamPolicyAllocationRules
#Description
Modifies the allocation rules in an IPAM policy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamPolicyId.Malformed",
"errorMessage": "The ipam-policy ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "6057eb31-ab32-402e-883f-e34bb146983c",
"eventName": "ModifyIpamPolicyAllocationRules",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "97ea21fd-7dae-4424-9bdd-e458ab9b7252",
"requestParameters": {
"ModifyIpamPolicyAllocationRulesRequest": {
"IpamPolicyId": "dw-probe",
"Locale": "dw-probe",
"ResourceType": "alb"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyIpamPool
#Description
Modify the configurations of an IPAM pool.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamPoolId.Malformed",
"errorMessage": "The specified IPAM pool ID is not valid. Specify an IPAM pool ID in the form ipam-pool-xxxxxxxxxxxxxxxxx.",
"eventCategory": "Management",
"eventID": "48389a1a-3dfd-4609-88af-1f3ebd19e941",
"eventName": "ModifyIpamPool",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8420e9c8-a8ec-4655-ba71-b350e6b3e191",
"requestParameters": {
"ModifyIpamPoolRequest": {
"IpamPoolId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyIpamPoolAllocation
#Description
Modifies the description of an IPAM pool allocation.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamPoolAllocationId.Malformed",
"errorMessage": "The ipam-pool-allocation ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "04547ae5-655d-45c0-8e1d-ec7a8c5fc2f1",
"eventName": "ModifyIpamPoolAllocation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e1ab85d4-8e73-4ad3-8e4b-c299b953fb50",
"requestParameters": {
"ModifyIpamPoolAllocationRequest": {
"IpamPoolAllocationId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyIpamPrefixListResolver
#Description
Modifies an IPAM prefix list resolver.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamPrefixListResolverId.Malformed",
"errorMessage": "The ipam-prefix-list-resolver ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "764ff86b-9f4d-453d-a9bd-67c6dc548f23",
"eventName": "ModifyIpamPrefixListResolver",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "09685d86-c1da-4a95-a446-3c8b20453681",
"requestParameters": {
"ModifyIpamPrefixListResolverRequest": {
"IpamPrefixListResolverId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyIpamPrefixListResolverTarget
#Description
Modifies an IPAM prefix list resolver target.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamPrefixListResolverTargetId.Malformed",
"errorMessage": "The ipam-prefix-list-resolver-target ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "e5c9025b-4fd0-47c5-aaf2-a19098542f42",
"eventName": "ModifyIpamPrefixListResolverTarget",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "28b81725-91da-4e45-92f6-cada18431f6f",
"requestParameters": {
"ModifyIpamPrefixListResolverTargetRequest": {
"ClientToken": "f69d0826-27af-44a1-b04b-62dc8a4476f3",
"IpamPrefixListResolverTargetId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyIpamResourceCidr
#Description
Modify a resource CIDR.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamScopeId.Malformed",
"errorMessage": "The ipam-scope ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "359cd2bd-3de5-4d05-b5fd-b718d812a2f1",
"eventName": "ModifyIpamResourceCidr",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6d66a53d-12fc-4a67-9164-333a451ace0e",
"requestParameters": {
"ModifyIpamResourceCidrRequest": {
"CurrentIpamScopeId": "dw-probe",
"Monitored": false,
"ResourceCidr": "dw-probe",
"ResourceId": "dw-probe",
"ResourceRegion": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyIpamResourceDiscovery
#Description
Modifies a resource discovery.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamResourceDiscoveryId.Malformed",
"errorMessage": "The specified IPAM resource discovery ID is not valid. Specify an IPAM resource discovery ID in the form ipam-res-disco-xxxxxxxxxxxxxxxxx.",
"eventCategory": "Management",
"eventID": "c7333481-6948-4dc8-bb18-eb4ab4a8abd3",
"eventName": "ModifyIpamResourceDiscovery",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "eb6e12e6-e5eb-4111-a11d-99b471a26fe8",
"requestParameters": {
"ModifyIpamResourceDiscoveryRequest": {
"IpamResourceDiscoveryId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyIpamScope
#Description
Modify an IPAM scope.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamScopeId.Malformed",
"errorMessage": "The specified IPAM scope ID is not valid. Specify an IPAM scope ID in the form ipam-scope-xxxxxxxxxxxxxxxxx.",
"eventCategory": "Management",
"eventID": "f14b69c5-5fc4-49f5-a34a-700c77ca05a1",
"eventName": "ModifyIpamScope",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d1c458aa-b130-475e-bd05-849e0db6db66",
"requestParameters": {
"ModifyIpamScopeRequest": {
"IpamScopeId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyLaunchTemplate
#Description
Modifies a launch template.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "89ad7824-5ba4-420d-87c9-bcb42944f32d",
"eventName": "ModifyLaunchTemplate",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:59:23Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0cf3ea49-eb3f-4135-b0d3-ed0d013d82b3",
"requestParameters": {
"ModifyLaunchTemplateRequest": {
"ClientToken": "aaf53eb7-d047-4886-8196-a7045aab3688",
"LaunchTemplateId": "lt-0e15e74d047fa83a3",
"SetDefaultVersion": 1
}
},
"responseElements": {
"ModifyLaunchTemplateResponse": {
"launchTemplate": {
"createTime": "1970-01-01T00:00:00.000Z",
"createdBy": "arn:aws:iam::123456789012:user/sample-user",
"defaultVersionNumber": 1,
"latestVersionNumber": 2,
"launchTemplateId": "lt-0e15e74d047fa83a3",
"launchTemplateName": "dwfix-lt",
"operator": {
"managed": false
}
},
"requestId": "0cf3ea49-eb3f-4135-b0d3-ed0d013d82b3",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyLocalGatewayRoute
#Description
Modifies the specified local gateway route.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidLocalGatewayRouteTableID.Malformed",
"errorMessage": "Invalid LocalGateway Route Table id dw-probe",
"eventCategory": "Management",
"eventID": "f75e0318-c1e2-4b87-896b-f60fa35cdc96",
"eventName": "ModifyLocalGatewayRoute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "b358cf9c-293a-45b9-98a0-13c6d8193379",
"requestParameters": {
"ModifyLocalGatewayRouteRequest": {
"LocalGatewayRouteTableId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyManagedPrefixList
#Description
Modifies the specified managed prefix list.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidPrefixListId.Malformed",
"errorMessage": "The prefix-list ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "ad4d12a1-873b-4482-a19a-118f5c90b741",
"eventName": "ModifyManagedPrefixList",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "dd33ad26-e997-4ce1-81da-74a899bff550",
"requestParameters": {
"ModifyManagedPrefixListRequest": {
"PrefixListId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyManagedResourceVisibility
#Description
Modifies the managed resource visibility configuration for the account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "9af05b60-902b-4302-a677-2f98e4f5d11a",
"eventName": "ModifyManagedResourceVisibility",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:56Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e7debbd9-ca51-4dca-bf39-2f058e1cd79e",
"requestParameters": {
"ModifyManagedResourceVisibilityRequest": {
"DefaultVisibility": "hidden"
}
},
"responseElements": {
"ModifyManagedResourceVisibilityResponse": {
"requestId": "e7debbd9-ca51-4dca-bf39-2f058e1cd79e",
"visibility": {
"defaultVisibility": "hidden"
},
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyNetworkInterfaceAttribute
#Description
Modifies the specified network interface attribute.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidNetworkInterfaceId.Malformed",
"errorMessage": "Invalid id: \"dw-probe\" (expecting \"eni-...\")",
"eventCategory": "Management",
"eventID": "144e63fb-e45a-4695-b9fd-f245fb822470",
"eventName": "ModifyNetworkInterfaceAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:56Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "85f4ac78-2955-44b4-aadc-422228309da0",
"requestParameters": {
"networkInterfaceId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyPrivateDnsNameOptions
#Description
Modifies the options for instance hostnames for the specified instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.UnknownResource",
"errorMessage": "User (123456789012) does not own a resource dw-probe .",
"eventCategory": "Management",
"eventID": "cb61fed4-0623-490a-b39d-a2fbe0e8eb4e",
"eventName": "ModifyPrivateDnsNameOptions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:56Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "fbaf5f9a-82b3-4846-a283-3a3dcccf7232",
"requestParameters": {
"ModifyPrivateDnsNameOptionsRequest": {
"InstanceId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyPublicIpDnsNameOptions
#Description
Modify public hostname options for a network interface.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidNetworkInterfaceId.Malformed",
"errorMessage": "The network-interface ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "ca3959e0-40d5-45ff-b8f9-04bf4c67abe6",
"eventName": "ModifyPublicIpDnsNameOptions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "cc1d40bc-f00f-4fe0-802d-86b3d1f76ffc",
"requestParameters": {
"ModifyPublicIpDnsNameOptionsRequest": {
"HostnameType": "public-dual-stack-dns-name",
"NetworkInterfaceId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyReservedInstances
#Description
Modifies the Availability Zone, instance count, instance type, or network platform (EC2-Classic or EC2-VPC) of your Reserved Instances.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "Invalid value 'dw-probe' for ReservedInstancesId.",
"eventCategory": "Management",
"eventID": "ed846192-e56b-4846-a138-8d682ae43395",
"eventName": "ModifyReservedInstances",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "73ce093d-a65d-46a6-bcca-923edfed251f",
"requestParameters": {
"reservedInstancesSet": {
"items": [
{
"reservedInstancesId": "dw-probe"
}
]
},
"targetConfigurationSet": {}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyRouteServer
#Description
Modifies the configuration of an existing route server.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRouteServerId.Malformed",
"errorMessage": "The route-server ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "605f3046-9b2d-4d2a-a5d0-21de8d12c58d",
"eventName": "ModifyRouteServer",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6cb127be-9dfe-44b2-934d-e89cb9a05848",
"requestParameters": {
"ModifyRouteServerRequest": {
"RouteServerId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifySnapshotTier
#Description
Archives an Amazon EBS snapshot.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "Value (dw-probe) for parameter snapshotId is invalid.",
"eventCategory": "Management",
"eventID": "b687ab62-3f09-4da6-a11d-062d618905bb",
"eventName": "ModifySnapshotTier",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7b0d0787-47be-4af0-97fc-75f2480a8653",
"requestParameters": {
"ModifySnapshotTierRequest": {
"SnapshotId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifySpotFleetRequest
#Description
Modifies the specified Spot fleet request.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "1 validation error detected: Value 'dw-probe' at 'spotFleetRequestId' failed to satisfy constraint: Member must satisfy regular expression pattern: ^(sfr|fleet)-[a-z0-9-]{36}\\b",
"eventCategory": "Management",
"eventID": "a635fe1c-e64c-453c-9062-1fc0bdf886ea",
"eventName": "ModifySpotFleetRequest",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "88e90951-53ea-4179-b991-e97bbcc722d8",
"requestParameters": {
"ModifySpotFleetRequestRequest": {
"SpotFleetRequestId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifySubnetAttribute
#Description
Modifies a subnet attribute.
Example CloudTrail Event #
{
"awsRegion": "eu-central-1",
"eventCategory": "Management",
"eventID": "3729db59-9c67-4575-b459-469159529934",
"eventName": "ModifySubnetAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-01-12T08:23:55Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "111111111111",
"requestID": "288dc4d2-ad01-4f99-affd-306a6713724a",
"requestParameters": {
"mapPublicIpOnLaunch": {
"value": true
},
"subnetId": "subnet-0b7135186b73850ed"
},
"responseElements": {
"_return": true,
"requestId": "288dc4d2-ad01-4f99-affd-306a6713724a"
},
"sourceIPAddress": "95.90.199.65",
"userAgent": "aws-sdk-go/1.36.19 (go1.15.5; darwin; amd64) APN/1.0 HashiCorp/1.0 Terraform/0.14.4 (+https://www.terraform.io)",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLJ2OYSF6E",
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:user/patrick_cli",
"principalId": "AIDAYTOGP2RLNALZHZ6KX",
"type": "IAMUser",
"userName": "patrick_cli"
}
}
References #
ModifyTrafficMirrorFilterNetworkServices
#Description
Allows or restricts mirroring network services.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTrafficMirrorFilterId.NotFound",
"errorMessage": "The traffic-mirror-filter ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "c1631c9a-b583-43e5-86a5-889ddcca6097",
"eventName": "ModifyTrafficMirrorFilterNetworkServices",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d128e4e9-9be7-405f-bb48-b98d9a180bd6",
"requestParameters": {
"ModifyTrafficMirrorFilterNetworkServicesRequest": {
"TrafficMirrorFilterId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1040↳ also matches CreateTrafficMirrorSession, CreateTrafficMirrorFilter, CreateTrafficMirrorFilterRule, CreateTrafficMirrorTarget, DeleteTrafficMirrorFilter, DeleteTrafficMirrorFilterRule, and 4 more
ModifyTrafficMirrorFilterRule
#Description
Modifies the specified Traffic Mirror rule.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "Invalid ID: dw-probe. Filter rule ID must be 21 characters!",
"eventCategory": "Management",
"eventID": "23290aeb-a6c1-4ff2-aab8-c7a0ee58d711",
"eventName": "ModifyTrafficMirrorFilterRule",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "da81aad2-dfc6-4290-bc12-106768150b66",
"requestParameters": {
"ModifyTrafficMirrorFilterRuleRequest": {
"TrafficMirrorFilterRuleId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1040↳ also matches CreateTrafficMirrorSession, CreateTrafficMirrorFilter, CreateTrafficMirrorFilterRule, CreateTrafficMirrorTarget, DeleteTrafficMirrorFilter, DeleteTrafficMirrorFilterRule, and 4 more
ModifyTrafficMirrorSession
#Description
Modifies a Traffic Mirror session.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "Invalid ID: dw-probe",
"eventCategory": "Management",
"eventID": "199e2f20-1d71-4ca6-8631-f0e37d29c640",
"eventName": "ModifyTrafficMirrorSession",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "dc83bab4-482e-4a03-bbec-7fd434679e24",
"requestParameters": {
"ModifyTrafficMirrorSessionRequest": {
"TrafficMirrorSessionId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1040↳ also matches CreateTrafficMirrorSession, CreateTrafficMirrorFilter, CreateTrafficMirrorFilterRule, CreateTrafficMirrorTarget, DeleteTrafficMirrorFilter, DeleteTrafficMirrorFilterRule, and 4 more
ModifyTransitGateway
#Description
Modifies the specified transit gateway.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayID.Malformed",
"errorMessage": "The transit-gateway ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "b5f51599-2228-44bb-a26c-42df098ed306",
"eventName": "ModifyTransitGateway",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a313fe15-b8f7-4ca3-aad4-4d8b50b72b65",
"requestParameters": {
"ModifyTransitGatewayRequest": {
"TransitGatewayId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyTransitGatewayMeteringPolicy
#Description
Modifies a transit gateway metering policy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayMeteringPolicyIdMalformedException",
"errorMessage": "The transit-gateway-metering-policy ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "fb699eed-5dc7-4e35-8f13-52d79779aae0",
"eventName": "ModifyTransitGatewayMeteringPolicy",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "48d4f159-554a-4fd7-8c56-f9d751fe9a93",
"requestParameters": {
"ModifyTransitGatewayMeteringPolicyRequest": {
"TransitGatewayMeteringPolicyId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyTransitGatewayPrefixListReference
#Description
Modifies a reference (route) to a prefix list in a specified transit gateway route table.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRouteTableId.Malformed",
"errorMessage": "Invalid Transit Gateway Route Table id dw-probe.",
"eventCategory": "Management",
"eventID": "2c937f57-d884-44d9-8602-a486d6f6fbf7",
"eventName": "ModifyTransitGatewayPrefixListReference",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8ce310d5-c7ea-4fb6-866a-976298883b18",
"requestParameters": {
"ModifyTransitGatewayPrefixListReferenceRequest": {
"PrefixListId": "dw-probe",
"TransitGatewayRouteTableId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyTransitGatewayVpcAttachment
#Description
Modifies the specified VPC attachment.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayAttachmentID.Malformed",
"errorMessage": "Invalid Transit Gateway Attachment id.",
"eventCategory": "Management",
"eventID": "1fc6c2fa-cfbb-4761-9705-c621bf0f9532",
"eventName": "ModifyTransitGatewayVpcAttachment",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "3a61e488-e27b-4eb9-a1ca-841f14d90b7a",
"requestParameters": {
"ModifyTransitGatewayVpcAttachmentRequest": {
"TransitGatewayAttachmentId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVerifiedAccessEndpoint
#Description
Modifies the configuration of the specified Amazon Web Services Verified Access endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVerifiedAccessEndpointId.NotFound",
"errorMessage": "VerifiedAccessEndpoint dw-probe does not exist",
"eventCategory": "Management",
"eventID": "942830f7-fe9a-4d53-9f50-778d1c56fb24",
"eventName": "ModifyVerifiedAccessEndpoint",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:22:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5299a833-25f4-41f9-be29-0df160ff4617",
"requestParameters": {
"ModifyVerifiedAccessEndpointRequest": {
"ClientToken": "f357b3d2-89a6-4a2e-940d-7a2b609e031b",
"VerifiedAccessEndpointId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVerifiedAccessEndpointPolicy
#Description
Modifies the specified Amazon Web Services Verified Access endpoint policy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVerifiedAccessEndpointId.NotFound",
"errorMessage": "VerifiedAccessEndpoint dw-probe does not exist",
"eventCategory": "Management",
"eventID": "f95e350e-0c16-4f97-a824-b59217eece22",
"eventName": "ModifyVerifiedAccessEndpointPolicy",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0a96cd63-5b0e-49ed-8c97-b1e3ca094175",
"requestParameters": {
"ModifyVerifiedAccessEndpointPolicyRequest": {
"ClientToken": "211c7b52-5704-42bd-b6a1-ffd177cff40c",
"VerifiedAccessEndpointId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVerifiedAccessGroup
#Description
Modifies the specified Amazon Web Services Verified Access group configuration.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVerifiedAccessGroupId.NotFound",
"errorMessage": "VerifiedAccessGroup dw-probe does not exist",
"eventCategory": "Management",
"eventID": "ee6e4f70-ccc9-480a-84ed-b36d0a30727d",
"eventName": "ModifyVerifiedAccessGroup",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d3184b3f-da51-4aab-abbf-23de854d269c",
"requestParameters": {
"ModifyVerifiedAccessGroupRequest": {
"ClientToken": "406000c4-a073-4acc-ba04-1a3b899074e5",
"VerifiedAccessGroupId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVerifiedAccessGroupPolicy
#Description
Modifies the specified Amazon Web Services Verified Access group policy.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVerifiedAccessGroupId.NotFound",
"errorMessage": "VerifiedAccessGroup dw-probe does not exist",
"eventCategory": "Management",
"eventID": "6e5ac594-1794-43f0-849c-0101389e8de7",
"eventName": "ModifyVerifiedAccessGroupPolicy",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:00Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6fdc429a-6aa3-4c78-b85b-cf6789fcf944",
"requestParameters": {
"ModifyVerifiedAccessGroupPolicyRequest": {
"ClientToken": "5dc5b740-1a8a-4f4e-87da-59ccc3dfa9ad",
"VerifiedAccessGroupId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVerifiedAccessInstance
#Description
Modifies the configuration of the specified Amazon Web Services Verified Access instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVerifiedAccessInstanceId.NotFound",
"errorMessage": "VerifiedAccessInstance dw-probe does not exist",
"eventCategory": "Management",
"eventID": "9d1e2e45-b658-4d19-9fb6-98261a958825",
"eventName": "ModifyVerifiedAccessInstance",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "156cc931-574d-4051-bd34-b5ca7d720834",
"requestParameters": {
"ModifyVerifiedAccessInstanceRequest": {
"ClientToken": "660a53b7-3852-4e28-9f9c-4aeb94abefd0",
"VerifiedAccessInstanceId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVerifiedAccessInstanceLoggingConfiguration
#Description
Modifies the logging configuration for the specified Amazon Web Services Verified Access instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.MissingParameter",
"errorMessage": "The request must include the AccessLogs parameter. Add the required parameter and retry the request.",
"eventCategory": "Management",
"eventID": "64abdd3d-c074-4689-a02c-508a50e0715c",
"eventName": "ModifyVerifiedAccessInstanceLoggingConfiguration",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c7a896fb-e8fd-4833-a4c6-f6d190aa3e9e",
"requestParameters": {
"ModifyVerifiedAccessInstanceLoggingConfigurationRequest": {
"ClientToken": "29558dd6-3e38-4741-a874-ddf330827ac2",
"VerifiedAccessInstanceId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVerifiedAccessTrustProvider
#Description
Modifies the configuration of the specified Amazon Web Services Verified Access trust provider.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVerifiedAccessTrustProviderId.NotFound",
"errorMessage": "VerifiedAccessTrustProvider dw-probe does not exist",
"eventCategory": "Management",
"eventID": "d6f05df2-de74-45df-aa1b-7525806cc1f0",
"eventName": "ModifyVerifiedAccessTrustProvider",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "be94e0ab-ba97-4994-971c-2a48bbb0ba3d",
"requestParameters": {
"ModifyVerifiedAccessTrustProviderRequest": {
"ClientToken": "14541c05-dd2f-4169-b750-b36c66a82b2a",
"VerifiedAccessTrustProviderId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVolume
#Description
You can modify several parameters of an existing EBS volume, including volume size, volume type, and IOPS capacity.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "Value (dw-probe) for parameter volumeId is invalid. Expected: 'vol-...'.",
"eventCategory": "Management",
"eventID": "bfade3d0-436f-48cc-bfd2-968156ba8816",
"eventName": "ModifyVolume",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c849979b-6ef3-4a82-a580-95c122b9b5a3",
"requestParameters": {
"ModifyVolumeRequest": {
"VolumeId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVolumeAttribute
#Description
Modifies a volume attribute.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVolumeID.Malformed",
"errorMessage": "The volume ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "9c9e9d71-84e0-4da7-82ad-2fc04b79a952",
"eventName": "ModifyVolumeAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "2464768a-f319-44f2-9939-72d5c9f6fab6",
"requestParameters": {
"volumeId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVpcAttribute
#Description
Modifies the specified attribute of the specified VPC.
Example CloudTrail Event #
{
"awsRegion": "eu-central-1",
"eventCategory": "Management",
"eventID": "c4fab597-8681-4053-854d-52a9e4203180",
"eventName": "ModifyVpcAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-01-12T08:23:38Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "111111111111",
"requestID": "a7d9d49e-839c-476b-bd1b-7732f4c4ca4e",
"requestParameters": {
"enableDnsHostnames": {
"value": true
},
"vpcId": "vpc-0cba59db5968227e2"
},
"responseElements": {
"_return": true,
"requestId": "a7d9d49e-839c-476b-bd1b-7732f4c4ca4e"
},
"sourceIPAddress": "95.90.199.65",
"userAgent": "aws-sdk-go/1.36.19 (go1.15.5; darwin; amd64) APN/1.0 HashiCorp/1.0 Terraform/0.14.4 (+https://www.terraform.io)",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLJ2OYSF6E",
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:user/patrick_cli",
"principalId": "AIDAYTOGP2RLNALZHZ6KX",
"type": "IAMUser",
"userName": "patrick_cli"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches AcceptVpcPeeringConnection, AttachClassicLinkVpc, CreateVpc, DeleteVpc, DetachClassicLinkVpc, DisableVpcClassicLink, EnableVpcClassicLink, RejectVpcPeeringConnection
References #
ModifyVpcBlockPublicAccessExclusion
#Description
Modify VPC Block Public Access (BPA) exclusions.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.VpcBlockPublicAccessExclusionId.Malformed",
"errorMessage": "The vpc-block-public-access-exclusion ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "b44bfd50-7203-4ce7-b184-13c5acf913f2",
"eventName": "ModifyVpcBlockPublicAccessExclusion",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a27599de-17e3-48c9-aa70-7bc68bf903b8",
"requestParameters": {
"ModifyVpcBlockPublicAccessExclusionRequest": {
"ExclusionId": "dw-probe",
"InternetGatewayExclusionMode": "allow-bidirectional"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVpcBlockPublicAccessOptions
#Description
Modify VPC Block Public Access (BPA) options.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "9900fd1f-4201-46d2-a89a-a56584a75a2d",
"eventName": "ModifyVpcBlockPublicAccessOptions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f607c613-50c1-4e64-879d-5dba99d957b4",
"requestParameters": {
"ModifyVpcBlockPublicAccessOptionsRequest": {
"InternetGatewayBlockMode": "off"
}
},
"responseElements": {
"ModifyVpcBlockPublicAccessOptionsResponse": {
"requestId": "f607c613-50c1-4e64-879d-5dba99d957b4",
"vpcBlockPublicAccessOptions": {
"awsAccountId": "123456789012",
"awsRegion": "us-west-1",
"exclusionsAllowed": "allowed",
"internetGatewayBlockMode": "off",
"managedBy": "account",
"reason": "Default State",
"state": "default-state"
},
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVpcEncryptionControl
#Description
Modifies the encryption control configuration for a VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpcEncryptionControlId.Malformed",
"errorMessage": "The vpc-encryption-control ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "1fba7331-9301-400b-8053-fc6fe6b5b236",
"eventName": "ModifyVpcEncryptionControl",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "3e4e6618-cb53-48fb-8036-c431b099d8ce",
"requestParameters": {
"ModifyVpcEncryptionControlRequest": {
"VpcEncryptionControlId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVpcEndpoint
#Description
Modifies attributes of a specified VPC endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpcEndpointId.Malformed",
"errorMessage": "Invalid Id: 'dw-probe' (expecting 'vpce-...; the Id may only contain lowercase alphanumeric characters and a single dash')",
"eventCategory": "Management",
"eventID": "a2c60b37-5df0-48f1-9ab3-ae5cc1b4b6a4",
"eventName": "ModifyVpcEndpoint",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1723908b-b1d3-4007-b6fe-a6c0c53a4805",
"requestParameters": {
"ModifyVpcEndpointRequest": {
"VpcEndpointId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVpcEndpointConnectionNotification
#Description
Modifies a connection notification for VPC endpoint or VPC endpoint service.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameter",
"errorMessage": "Invalid Id: 'dw-probe' (expecting 'vpce-nfn-...; the Id may only contain lowercase alphanumeric characters and two dashes')",
"eventCategory": "Management",
"eventID": "4a73741d-e9da-4329-b56e-e0beeab65cec",
"eventName": "ModifyVpcEndpointConnectionNotification",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9110051c-4eaa-4a60-9a67-39d49feb0156",
"requestParameters": {
"ModifyVpcEndpointConnectionNotificationRequest": {
"ConnectionNotificationId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVpcEndpointServiceConfiguration
#Description
Modifies the attributes of the specified VPC endpoint service configuration.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpcEndpointServiceId.Malformed",
"errorMessage": "Invalid Id: 'dw-probe' (expecting 'vpce-svc-...; the Id may only contain lowercase alphanumeric characters and two dashes')",
"eventCategory": "Management",
"eventID": "877e532c-9f0f-4933-aaf4-b0474211055d",
"eventName": "ModifyVpcEndpointServiceConfiguration",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:03Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "0761782a-a0e6-47c4-92ad-d77a5e200799",
"requestParameters": {
"ModifyVpcEndpointServiceConfigurationRequest": {
"ServiceId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVpcEndpointServicePayerResponsibility
#Description
Modifies the payer responsibility for your VPC endpoint service.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.UnsupportedOperation",
"errorMessage": "You must be explicitly allowlisted to call this API.",
"eventCategory": "Management",
"eventID": "5b9e175a-ad74-4c2e-a9f6-306dc4311497",
"eventName": "ModifyVpcEndpointServicePayerResponsibility",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:04Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "716d0417-2dd6-4044-bfd5-5d835ec3676f",
"requestParameters": {
"ModifyVpcEndpointServicePayerResponsibilityRequest": {
"PayerResponsibility": "ServiceOwner",
"ServiceId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVpcEndpointServicePermissions
#Description
Modifies the permissions for your VPC endpoint service.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpcEndpointServiceId.Malformed",
"errorMessage": "Invalid Id: 'dw-probe' (expecting 'vpce-svc-...; the Id may only contain lowercase alphanumeric characters and two dashes')",
"eventCategory": "Management",
"eventID": "08a0e6f8-1cea-4eec-8ce8-a106e38c8d33",
"eventName": "ModifyVpcEndpointServicePermissions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:04Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d76557be-f982-41e7-bf6d-f685896adccf",
"requestParameters": {
"ModifyVpcEndpointServicePermissionsRequest": {
"ServiceId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVpcPeeringConnectionOptions
#Description
Modifies the VPC peering connection options on one side of a VPC peering connection.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpcPeeringConnectionId.Malformed",
"errorMessage": "The peering ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "9bbe6334-8c5f-4c4d-a6f4-43675f8675f9",
"eventName": "ModifyVpcPeeringConnectionOptions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:04Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ce076e12-d0c4-45e1-9334-69371346103e",
"requestParameters": {
"ModifyVpcPeeringConnectionOptionsRequest": {
"VpcPeeringConnectionId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVpcTenancy
#Description
Modifies the instance tenancy attribute of the specified VPC.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpcId.Malformed",
"errorMessage": "The vpc ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "f21b4e2c-76ed-48c4-8fcb-24d223b40270",
"eventName": "ModifyVpcTenancy",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:04Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8cae0838-c0b7-4055-8d2e-63e2a3bcdfa3",
"requestParameters": {
"ModifyVpcTenancyRequest": {
"InstanceTenancy": "default",
"VpcId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVpnConnection
#Description
Modifies the customer gateway or the target gateway of an Amazon Web Services Site-to-Site VPN connection.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameter",
"errorMessage": "Parameter vpnConnectionId=dw-probe has an invalid format.",
"eventCategory": "Management",
"eventID": "e300197d-d17c-43fe-849b-8af3c3f9df83",
"eventName": "ModifyVpnConnection",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:04Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "1382eaf4-07bd-4ccb-8a01-619d63a7351e",
"requestParameters": {
"ModifyVpnConnectionRequest": {
"VpnConnectionId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVpnConnectionOptions
#Description
Modifies the connection options for your Site-to-Site VPN connection.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpnConnectionID.NotFound",
"errorMessage": "The vpnConnection ID 'dw-probe' does not exist",
"eventCategory": "Management",
"eventID": "c15a21ad-68bb-455c-a8ec-a10c20c3bf04",
"eventName": "ModifyVpnConnectionOptions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:05Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "aa7957b3-e68a-4e54-ac26-762158a8b4d2",
"requestParameters": {
"ModifyVpnConnectionOptionsRequest": {
"VpnConnectionId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVpnTunnelCertificate
#Description
Modifies the VPN tunnel endpoint certificate.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "Value (dw-probe) for parameter vpnTunnelOutsideIpAddress is invalid.",
"eventCategory": "Management",
"eventID": "fd6e1743-d30f-426f-af3d-da2710453e9e",
"eventName": "ModifyVpnTunnelCertificate",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:05Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "48cdfcf8-4f18-423b-acad-055916f19fa4",
"requestParameters": {
"ModifyVpnTunnelCertificateRequest": {
"VpnConnectionId": "dw-probe",
"VpnTunnelOutsideIpAddress": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ModifyVpnTunnelOptions
#Description
Modifies the options for a VPN tunnel in an Amazon Web Services Site-to-Site VPN connection.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameter",
"errorMessage": "Parameter vpnConnectionId=dw-probe has an invalid format.",
"eventCategory": "Management",
"eventID": "95690e34-35b8-4a7d-abca-c3ab81fe27c6",
"eventName": "ModifyVpnTunnelOptions",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:05Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "405ebdaa-e2b0-4bb7-8cde-003383d2129e",
"requestParameters": {
"ModifyVpnTunnelOptionsRequest": {
"VpnConnectionId": "dw-probe",
"VpnTunnelOutsideIpAddress": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
MonitorInstances
#Description
Enables monitoring for a running instance.
Example CloudTrail Event #
{
"awsRegion": "eu-central-1",
"eventCategory": "Management",
"eventID": "7598220f-8422-4a10-a22f-18cd62ae43a1",
"eventName": "MonitorInstances",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2021-01-12T08:24:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "111111111111",
"requestID": "9abce318-3267-42a2-95c1-51c9f67da8d7",
"requestParameters": {
"instancesSet": {
"items": [
{
"instanceId": "i-0a1bb25cf91ffe954"
}
]
}
},
"responseElements": {
"instancesSet": {
"items": [
{
"instanceId": "i-0a1bb25cf91ffe954",
"monitoring": {
"state": "enabled"
}
}
]
},
"requestId": "9abce318-3267-42a2-95c1-51c9f67da8d7"
},
"sourceIPAddress": "95.90.199.65",
"userAgent": "aws-sdk-go/1.36.19 (go1.15.5; darwin; amd64) APN/1.0 HashiCorp/1.0 Terraform/0.14.4 (+https://www.terraform.io)",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLJ2OYSF6E",
"accountId": "111111111111",
"arn": "arn:aws:iam::111111111111:user/patrick_cli",
"principalId": "AIDAYTOGP2RLNALZHZ6KX",
"type": "IAMUser",
"userName": "patrick_cli"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
References #
MoveAddressToVpc
#Description
Moves an Elastic IP address from the EC2-Classic platform to the EC2-VPC platform.
MoveByoipCidrToIpam
#Description
Move a BYOIPv4 CIDR to IPAM from a public IPv4 pool.
MoveCapacityReservationInstances
#Description
Move available capacity from a source Capacity Reservation to a destination Capacity Reservation.
ProvisionByoipCidr
#Description
Provisions an IPv4 or IPv6 address range for use with your Amazon Web Services resources through bring your own IP addresses (BYOIP) and creates a corresponding address pool.
ProvisionIpamByoasn
#Description
Provisions your Autonomous System Number (ASN) for use in your Amazon Web Services account.
ProvisionIpamPoolCidr
#Description
Provision a CIDR to an IPAM pool.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "9d240ea0-2f75-43af-9d33-512867de78c5",
"eventName": "ProvisionIpamPoolCidr",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:48:30Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e621cd26-ece7-488c-b9e7-47e5d84db1b7",
"requestParameters": {
"ProvisionIpamPoolCidrRequest": {
"Cidr": "10.99.0.0/16",
"ClientToken": "ea06295a-c4fc-44a6-8435-56496d9ec034",
"IpamPoolId": "ipam-pool-0b5795c40ef5b6d99"
}
},
"responseElements": {
"ProvisionIpamPoolCidrResponse": {
"ipamPoolCidr": {
"cidr": "10.99.0.0/16",
"ipamPoolCidrId": "ipam-pool-cidr-00a9fa47cce7f4a0a9bdbda8809e6cc1f",
"netmaskLength": 16,
"state": "pending-provision"
},
"requestId": "e621cd26-ece7-488c-b9e7-47e5d84db1b7",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ProvisionPublicIpv4PoolCidr
#Description
Provision a CIDR to a public IPv4 pool.
PurchaseCapacityBlock
#Description
Purchase the Capacity Block for use with your account.
PurchaseCapacityBlockExtension
#Description
Purchase the Capacity Block extension for use with your account.
PurchaseHostReservation
#Description
Purchase a reservation with configurations that match those of your Dedicated Host.
PurchaseReservedInstancesOffering
#Description
Purchases a Reserved Instance for use with your account.
PurchaseScheduledInstances
#Description
Purchases one or more Scheduled Instances with the specified schedule.
RebootInstances
#Description
Requests a reboot of one or more instances.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation. Encoded authorization failure message: V6s_RP0ptFCww-lvtvVv7zgAGy8WG7W8jY6WnnqYko8kkc4G2ZOCfJyzJD2RKKr3Al2C7huwVfZASBvZWsZyO5DEBgx3XfeUuqjA-doRcJXAnWAWKn1IIP-B49mKZB8HdQXjPAZs2Fov48mjqfCTp56eKQHwBqqq6gBT-sWrtybayc0AHiaS1Clvnc-gR1gqtikZcrnev0qWPCSnT8iZseNFGyOgLHLo8hJlSz_vjQ0lSEqhQ4shpz83ZVngiGyr6ZqGxa-e15vdsnk2myxL6H9LlRxsztJwMQJGRNooO7fmmljJmPZ1RvPgkSB1noWt24wrh21wbDBxxD_X2N4UBcjxY-7EAzd1VxXwQztDJIPaZo4TCN53CvbmKgaJBp4U8H4lXCOD1Sw4J3urmixCgHY3pljMHMf9JSFqEQkGsR-nM3q7KLdiiix2OayiEQgPKlqhTy1wvsuhCuNnDJjM2Ve44ncF6VPNAQEpz1rNJLcUVXEUQv-D9JsvZJ2C5bGAaSIcGstB_q-J1cjUa3-u2gF-vVb6SfFMAclIvxPgK4U0VX_a6-jh5Qmp6GLFasY16jKo-rWQGje9rN3Z7n69yRo7O2UiPU7xvKjqrUgj8th00xDjX9kDxh4OFw-Fa7BncOlAP2XSQM4dbQfz0_YQZcacU7rU7GNm_ZlvsA7d8uzOH6huDcPLWzhFlHE",
"eventID": "e2de6c85-f52a-4252-8a9e-bad0e837640c",
"eventName": "RebootInstances",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2018-11-16T18:35:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "3208b295-f6c6-4be5-8794-a2c58e42c259",
"requestParameters": {
"instancesSet": {
"items": [
{
"instanceId": "i-aa2d3b42e5c6e801a"
}
]
}
},
"responseElements": null,
"sourceIPAddress": "0.35.253.179",
"userAgent": "aws-cli/1.14.58 Python/2.7.9 Windows/8 botocore/1.9.11",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
RegisterImage
#Description
Registers an AMI.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "fa0d7aad-7d72-46c4-a0cf-230834779e81",
"eventName": "RegisterImage",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:10:53Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "33421278-4323-41d0-92a9-f32b478dd054",
"requestParameters": {
"architecture": "x86_64",
"blockDeviceMapping": {
"items": [
{
"deviceName": "/dev/xvda",
"ebs": {
"deleteOnTermination": true,
"snapshotId": "snap-01ee6be9876379b3b",
"volumeSize": 1,
"volumeType": "standard"
}
}
]
},
"enaSupport": false,
"name": "stratus-red-team-share-ami-ami",
"rootDeviceName": "/dev/xvda",
"sriovNetSupport": "simple"
},
"responseElements": {
"imageId": "ami-0aa1d83d0b0985c86",
"requestId": "33421278-4323-41d0-92a9-f32b478dd054"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_b47d6b97-21d3-4b01-8937-6f0c23cb2d4b HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
RegisterInstanceEventNotificationAttributes
#Description
Registers a set of tag keys to include in scheduled event notifications for your resources.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "daf1d9f4-d9b2-4612-ba8e-2eaeb0d7c3f3",
"eventName": "RegisterInstanceEventNotificationAttributes",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:40:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c083c5b2-69b3-47d3-a06a-5f7c64632ccf",
"requestParameters": {
"RegisterInstanceEventNotificationAttributesRequest": {
"InstanceTagAttribute": {
"IncludeAllTagsOfInstance": true
}
}
},
"responseElements": {
"RegisterInstanceEventNotificationAttributesResponse": {
"instanceTagAttribute": {
"includeAllTagsOfInstance": true,
"instanceTagKeySet": ""
},
"requestId": "c083c5b2-69b3-47d3-a06a-5f7c64632ccf",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
RegisterTransitGatewayMulticastGroupMembers
#Description
Registers members (network interfaces) with the transit gateway multicast group.
RegisterTransitGatewayMulticastGroupSources
#Description
Registers sources (network interfaces) with the specified transit gateway multicast group.
RejectCapacityReservationBillingOwnership
#Description
Rejects a request to assign billing of the available capacity of a shared Capacity Reservation to your account.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidCapacityReservationId.Malformed",
"errorMessage": "Capacity Reservation ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "d167e705-0953-4e71-bb4e-934104dff1d8",
"eventName": "RejectCapacityReservationBillingOwnership",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:05Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "89a0de1f-4ed8-467d-8b24-8d0f0d256eec",
"requestParameters": {
"RejectCapacityReservationBillingOwnershipRequest": {
"CapacityReservationId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RejectTransitGatewayClientVpnAttachment
#Description
Rejects a Transit Gateway attachment request for a Client VPN endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayAttachmentID.Malformed",
"errorMessage": "The transit-gateway-attachment ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "52bb07fb-9fd0-40b7-892d-660ada9b9885",
"eventName": "RejectTransitGatewayClientVpnAttachment",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:06Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "9233c1f9-98d5-44ce-967b-f4238d20b76a",
"requestParameters": {
"RejectTransitGatewayClientVpnAttachmentRequest": {
"TransitGatewayAttachmentId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RejectTransitGatewayMulticastDomainAssociations
#Description
Rejects a request to associate cross-account subnets with a transit gateway multicast domain.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.MissingParameter",
"errorMessage": "Missing required parameter in request: TransitGatewayMulticastDomainId.",
"eventCategory": "Management",
"eventID": "687020de-b0c0-4842-922a-0b6d2b195879",
"eventName": "RejectTransitGatewayMulticastDomainAssociations",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:45:18Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8b90786e-3fa3-4d81-8329-17cf619dac5e",
"requestParameters": {
"RejectTransitGatewayMulticastDomainAssociationsRequest": ""
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RejectTransitGatewayPeeringAttachment
#Description
Rejects a transit gateway peering attachment request.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayAttachmentID.Malformed",
"errorMessage": "Invalid Transit Gateway Attachment id.",
"eventCategory": "Management",
"eventID": "aef49558-f7f2-405f-8bbc-fc7739526d7e",
"eventName": "RejectTransitGatewayPeeringAttachment",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:06Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e2ad3267-c96f-4ffa-bd35-e334960907d0",
"requestParameters": {
"RejectTransitGatewayPeeringAttachmentRequest": {
"TransitGatewayAttachmentId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RejectTransitGatewayVpcAttachment
#Description
Rejects a request to attach a VPC to a transit gateway.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayAttachmentID.Malformed",
"errorMessage": "Invalid Transit Gateway Attachment id.",
"eventCategory": "Management",
"eventID": "568cef2e-65d2-4ef6-8332-4ed2ebc99a69",
"eventName": "RejectTransitGatewayVpcAttachment",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:06Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a18cc887-4b66-4b22-9fdb-0bf911cfa094",
"requestParameters": {
"RejectTransitGatewayVpcAttachmentRequest": {
"TransitGatewayAttachmentId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RejectVpcEndpointConnections
#Description
Rejects VPC endpoint connection requests to your VPC endpoint service.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpcEndpointServiceId.Malformed",
"errorMessage": "Invalid Id: 'dw-probe' (expecting 'vpce-svc-...; the Id may only contain lowercase alphanumeric characters and two dashes')",
"eventCategory": "Management",
"eventID": "4aaf5246-696a-4881-9807-d8e46259d70d",
"eventName": "RejectVpcEndpointConnections",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:06Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5e17333c-d5a2-4ddd-8f0e-20d5cf5d9a1f",
"requestParameters": {
"RejectVpcEndpointConnectionsRequest": {
"ServiceId": "dw-probe",
"VpcEndpointId": {
"content": "dw-probe",
"tag": 1
}
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RejectVpcPeeringConnection
#Description
Rejects a VPC peering connection request.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidVpcPeeringConnectionId.Malformed",
"errorMessage": "The vpc-peering-connection ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "a318de83-b713-4356-bd9c-cedfa909bb7b",
"eventName": "RejectVpcPeeringConnection",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:07Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "f71f1db9-55a5-4e5b-99e7-957adc032484",
"requestParameters": {
"vpcPeeringConnectionId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches AcceptVpcPeeringConnection, AttachClassicLinkVpc, CreateVpc, DeleteVpc, DetachClassicLinkVpc, DisableVpcClassicLink, EnableVpcClassicLink, ModifyVpcAttribute
ReleaseAddress
#Description
Releases the specified Elastic IP address.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "540b0193-0d7f-4682-b665-9e6a6f734b1f",
"eventName": "ReleaseAddress",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:07:24Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "aec8cb85-7a00-4f0a-a8b4-ce023d4a8942",
"requestParameters": {
"allocationId": "eipalloc-09d58d8a1fc361502",
"networkBorderGroup": "us-east-1"
},
"responseElements": {
"_return": true,
"requestId": "aec8cb85-7a00-4f0a-a8b4-ce023d4a8942"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
References #
ReleaseHosts
#Description
When you no longer want to use a Dedicated host it can be released.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "0afe2854-457d-44cb-83ed-10d424e5366b",
"eventName": "ReleaseHosts",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:07Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "8e1028c9-a843-493e-89d9-026917fe43f9",
"requestParameters": {
"ReleaseHostsRequest": {
"HostId": {
"content": "dw-probe",
"tag": 1
}
}
},
"responseElements": {
"ReleaseHostsResponse": {
"requestId": "8e1028c9-a843-493e-89d9-026917fe43f9",
"successful": "",
"unsuccessful": {
"item": {
"error": {
"code": "Client.InvalidHostID.Malformed",
"message": "The specified Dedicated host IDs ['dw-probe'] are not valid."
},
"resourceId": "dw-probe"
}
},
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ReleaseIpamPoolAllocation
#Description
Release an allocation within an IPAM pool.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidIpamPoolId.Malformed",
"errorMessage": "The specified IPAM pool ID is not valid. Specify an IPAM pool ID in the form ipam-pool-xxxxxxxxxxxxxxxxx.",
"eventCategory": "Management",
"eventID": "adc30a63-aad8-42da-9f3e-04b384682cad",
"eventName": "ReleaseIpamPoolAllocation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:07Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "134ffb6b-7bcb-46ff-9662-09b7a99df8be",
"requestParameters": {
"ReleaseIpamPoolAllocationRequest": {
"Cidr": "dw-probe",
"IpamPoolAllocationId": "dw-probe",
"IpamPoolId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ReplaceIamInstanceProfileAssociation
#Description
Replaces an IAM instance profile for the specified running instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation. Encoded authorization failure message: 8EJjHUgzAIUK29zdJSWzOxy3pADpDZ568u_LfdbhSqijqHcrGJeQqNkFLAVM_dkpVlmTPuqzyvoFYvXa3CC3s4OE_S8ZSSxlX07PSof9PXgOnEEFWQr6c-A6ShlgFhvuJpmra4sDSv_k9UMT8eRpdfxS--ceCREJd2uFsg87FFjMBAqIRuxiZhRddWAs8QM3X9acWrTB19hOr6ZaMGjkiteQMgTu8reLVOLuvnouYg4LFoF-1R9xpRvqj6vncZC8_vzA09Mf-stImsB2tlKbm_X31vXGxgQK1JXSmZMMhQwtWh75cMQLkWo9egN7bb_5wOezRhEnxvr_VaTlTr7zQG096Qv7qE-tLTNXaYZNVjI23xU4TAW3l2J3f_9l5zUS7AqyM7G5MB6Vpbb_ayZUUDNNPpqIPFEYfm_JPEByPZD1aFlDiXHBGhYNSUKSza6GPn8-bqGYDL18Kc2laNhkfQp-PNHWWibvqMJrqfSq4I5kUBjSL28AgAEOjs30iQAU7xNQdPnKYw38RWZ7CPuWP56_XTH0fiibFVHSlbQILhTbwIiN2wgWNc7ybjeySZuy7V6-Xdv_XjfDR9tvK5veC4jJLkVYUVcAEwnhrYNmFNuqjBuZtrFPwzsqs0-tWCKHCCfPEMzBwJQB7Ic2yq7thzP1D8-o7jxvxHx-ti72N2aZl2Bo_AM7D0pRBe-3TNHYAX4rnqg-ucE",
"eventID": "1d6fd722-668b-46fc-8e03-0d5296ddd0be",
"eventName": "ReplaceIamInstanceProfileAssociation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2019-11-17T06:58:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "753e9f92-9850-4881-8859-b0301d6bdd37",
"requestParameters": {
"ReplaceIamInstanceProfileAssociationRequest": {
"AssociationId": "iip-assoc-56ccc7f0af6b28173",
"IamInstanceProfile": {
"Name": "instanceprofilename"
}
}
},
"responseElements": null,
"sourceIPAddress": "8.103.248.255",
"userAgent": "aws-cli/1.16.260 Python/3.7.3 Linux/5.0.0-32-generic botocore/1.12.250",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
ReplaceImageCriteriaInAllowedImagesSettings
#Description
Sets or replaces the criteria for Allowed AMIs.
ReplaceNetworkAclAssociation
#Description
Changes which network ACL a subnet is associated with.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "fd5b99ad-1b76-4c94-b04d-8108e3b22ae9",
"eventName": "ReplaceNetworkAclAssociation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:39:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "94e00318-b0e7-40f2-b016-75405234b478",
"requestParameters": {
"associationId": "aclassoc-0fd4ae72616ddbe51",
"networkAclId": "acl-04d473e8d2029fa23"
},
"responseElements": {
"newAssociationId": "aclassoc-02eb71d8668128857",
"requestId": "94e00318-b0e7-40f2-b016-75405234b478"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1562↳ also matches CreateNetworkAcl, CreateNetworkAclEntry, DeleteNetworkAcl, DeleteNetworkAclEntry, ReplaceNetworkAclEntry
ReplaceTransitGatewayRoute
#Description
Replaces the specified route in the specified transit gateway route table.
ReplaceVpnTunnel
#Description
Trigger replacement of specified VPN tunnel.
ReportInstanceStatus
#Description
Submits feedback about the status of an instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "bea294f0-9f6a-47c8-9831-553f9a3d673e",
"eventName": "ReportInstanceStatus",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:40:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "67fc0e0d-8a97-42a2-b193-e3beff54881c",
"requestParameters": {
"instancesSet": {
"items": [
{
"instanceId": "i-0a4c8f9124bcc1a50"
}
]
},
"reasonCodesSet": {
"items": [
{
"reasonCode": "instance-stuck-in-state"
}
]
},
"status": "ok"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
RequestSpotFleet
#Description
Creates a Spot fleet request.
RequestSpotInstances
#Description
Creates a Spot Instance request.
Example CloudTrail Event #
{
"awsRegion": "us-west-2",
"errorCode": "Client.UnauthorizedOperation",
"errorMessage": "You are not authorized to perform this operation.",
"eventID": "ab9ab691-61b8-48b7-9480-c99310",
"eventName": "RequestSpotInstances",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2019-05-20T09:29:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "bac37d14-c130-419f-aea7-6fd228eb80b1",
"requestParameters": {
"instanceCount": 1
},
"responseElements": null,
"sourceIPAddress": "240.48.251.119",
"userAgent": "aws-cli/1.16.158 Python/3.7.3 Linux/5.0.13-arch1-1-ARCH botocore/1.12.148",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
References #
ResetAddressAttribute
#Description
Resets the attribute of the specified IP address.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidAllocationID.NotFound",
"errorMessage": "The allocation ID 'dw-probe' does not exist",
"eventCategory": "Management",
"eventID": "80ff7048-bc65-4be5-8bb8-c84e98033805",
"eventName": "ResetAddressAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:07Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "d380ff12-62db-4fd9-959b-569d949b0c50",
"requestParameters": {
"ResetAddressAttributeRequest": {
"AllocationId": "dw-probe",
"Attribute": "domain-name"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ResetEbsDefaultKmsKeyId
#Description
Resets the default KMS key for EBS encryption for your account in this Region to the Amazon Web Services managed KMS key for EBS.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "be7720ac-2bd6-411c-9aeb-9fa25c259d03",
"eventName": "ResetEbsDefaultKmsKeyId",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:45:19Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "3f128fb5-a95b-4593-93e5-aa747762882c",
"requestParameters": {
"ResetEbsDefaultKmsKeyIdRequest": ""
},
"responseElements": {
"ResetEbsDefaultKmsKeyIdResponse": {
"kmsKeyId": "arn:aws:kms:us-west-1:123456789012:key/286ef80c-015b-4690-b517-43de4b604d27",
"requestId": "3f128fb5-a95b-4593-93e5-aa747762882c",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ResetFpgaImageAttribute
#Description
Resets the specified attribute of the specified Amazon FPGA Image (AFI) to its default value.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.UnsupportedOperation",
"errorMessage": "The functionality you requested is not available in this region.",
"eventCategory": "Management",
"eventID": "aaf4af93-a566-4a90-884e-477fee37bbdd",
"eventName": "ResetFpgaImageAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "a540df85-196c-4f17-a345-a563d0cce449",
"requestParameters": {
"ResetFpgaImageAttributeRequest": {
"FpgaImageId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ResetImageAttribute
#Description
Resets an attribute of an AMI to its default value.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidAMIID.Malformed",
"errorMessage": "Invalid id: \"dw-probe\" (expecting \"ami-...\")",
"eventCategory": "Management",
"eventID": "2abe44f1-5889-49cb-900a-2521c416fcbe",
"eventName": "ResetImageAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "940e158c-a415-4fa1-9d2a-10f45016af6e",
"requestParameters": {
"attributeType": "launchPermission",
"imageId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ResetInstanceAttribute
#Description
Resets an attribute of an instance to its default value.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterValue",
"errorMessage": "Value (instanceType) for parameter attribute is invalid. Unknown attribute.",
"eventCategory": "Management",
"eventID": "1e535919-8311-45ca-9cb5-68fb79f716c8",
"eventName": "ResetInstanceAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:08Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c20cb3c2-4cd2-4981-be6d-b4b6e98c1d74",
"requestParameters": {
"attribute": "instanceType",
"instanceId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
ResetNetworkInterfaceAttribute
#Description
Resets a network interface attribute.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidParameterCombination",
"errorMessage": "No attributes specified.",
"eventCategory": "Management",
"eventID": "24a43563-2864-431b-a500-0d98df34ccc8",
"eventName": "ResetNetworkInterfaceAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "66c4cdfe-2c6b-435f-981e-86c3e225384d",
"requestParameters": {
"networkInterfaceId": "dw-probe"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ResetSnapshotAttribute
#Description
Resets permission settings for the specified snapshot.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRequest",
"errorMessage": "The request received was invalid.",
"eventCategory": "Management",
"eventID": "a5d21b65-68d7-4217-92de-0efb837d4a90",
"eventName": "ResetSnapshotAttribute",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "416a3f53-91e2-42b4-8909-b7d481bc543d",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RestoreAddressToClassic
#Description
Restores an Elastic IP address that was previously moved to the EC2-VPC platform back to the EC2-Classic platform.
RestoreImageFromRecycleBin
#Description
Restores an AMI from the Recycle Bin.
RestoreManagedPrefixListVersion
#Description
Restores the entries from a previous version of a managed prefix list to a new version of the prefix list.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.PrefixListVersionMismatch",
"errorMessage": "The prefix list has the incorrect version number.",
"eventCategory": "Management",
"eventID": "2a2a2f96-8c43-41d9-9afd-ac4493d35837",
"eventName": "RestoreManagedPrefixListVersion",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:40:04Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "4cf91261-7938-4f13-abd1-b8163730f2c6",
"requestParameters": {
"RestoreManagedPrefixListVersionRequest": {
"CurrentVersion": 2,
"PrefixListId": "pl-0019d1157c40d82a7",
"PreviousVersion": 1
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RestoreSnapshotFromRecycleBin
#Description
Restores a snapshot from the Recycle Bin.
RestoreSnapshotTier
#Description
Restores an archived Amazon EBS snapshot for use temporarily or permanently, or modifies the restore period or restore type for a snapshot that was previously temporarily restored.
RestoreVolumeFromRecycleBin
#Description
Restores a volume from the Recycle Bin.
RevokeClientVpnIngress
#Description
Removes an ingress authorization rule from a Client VPN endpoint.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidClientVpnEndpointId.NotFound",
"errorMessage": "The client-vpn-endpoint ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "8ccc8ce1-2ac4-4e48-9cdc-4152727f402f",
"eventName": "RevokeClientVpnIngress",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "5f92deb8-82c7-47c8-8c70-241d9b527aae",
"requestParameters": {
"RevokeClientVpnIngressRequest": {
"ClientVpnEndpointId": "dw-probe",
"TargetNetworkCidr": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
RunInstances
#Description
Launches the specified number of instances using an AMI for which you have permissions.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "86eac0ac-8521-4126-aa32-a22f2b74d02e",
"eventName": "RunInstances",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T11:55:21Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "95b435ce-68af-4a4b-b89c-f653d8946ebc",
"requestParameters": {
"blockDeviceMapping": {},
"clientToken": "D37569A7-CF2F-4BD3-8DDE-F17AB408204D",
"creditSpecification": {
"cpuCredits": "unlimited"
},
"disableApiStop": false,
"disableApiTermination": false,
"ebsOptimized": false,
"hibernationOptions": {
"configured": false
},
"iamInstanceProfile": {
"name": "stratus-red-team-ec2-steal-credentials-instance"
},
"instanceType": "t3.micro",
"instancesSet": {
"items": [
{
"imageId": "ami-029eb80bc237bec6f",
"maxCount": 1,
"minCount": 1
}
]
},
"monitoring": {
"enabled": false
},
"networkInterfaceSet": {
"items": [
{
"deleteOnTermination": false,
"deviceIndex": 0,
"networkInterfaceId": "eni-076fa9fb98a2500a7"
}
]
},
"tagSpecificationSet": {
"items": [
{
"resourceType": "instance",
"tags": [
{
"key": "StratusRedTeam",
"value": "true"
}
]
}
]
}
},
"responseElements": {
"groupSet": {},
"instancesSet": {
"items": [
{
"amiLaunchIndex": 0,
"architecture": "x86_64",
"blockDeviceMapping": {},
"capacityReservationSpecification": {
"capacityReservationPreference": "open"
},
"clientToken": "D37569A7-CF2F-4BD3-8DDE-F17AB408204D",
"cpuOptions": {
"coreCount": 1,
"threadsPerCore": 2
},
"currentInstanceBootMode": "legacy-bios",
"ebsOptimized": false,
"enaSupport": true,
"enclaveOptions": {
"enabled": false
},
"groupSet": {
"items": [
{
"groupId": "sg-0b233157065b7d5e2"
}
]
},
"hibernationOptions": {
"configured": false
},
"hypervisor": "xen",
"iamInstanceProfile": {
"arn": "arn:aws:iam::123837392027:instance-profile/stratus-red-team-ec2-steal-credentials-instance",
"id": "AIPATFQR7NSCT5GZF5JGF"
},
"imageId": "ami-029eb80bc237bec6f",
"instanceId": "i-0dbc91f429e48eeed",
"instanceState": {
"code": 0,
"name": "pending"
},
"instanceType": "t3.micro",
"launchTime": 1688990121000,
"maintenanceOptions": {
"autoRecovery": "default"
},
"metadataOptions": {
"httpEndpoint": "enabled",
"httpProtocolIpv4": "enabled",
"httpProtocolIpv6": "disabled",
"httpPutResponseHopLimit": 1,
"httpTokens": "optional",
"instanceMetadataTags": "disabled",
"state": "pending"
},
"monitoring": {
"state": "disabled"
},
"networkInterfaceSet": {
"items": [
{
"attachment": {
"attachTime": 1688990121000,
"attachmentId": "eni-attach-00cac81742e39b87a",
"deleteOnTermination": false,
"deviceIndex": 0,
"networkCardIndex": 0,
"status": "attaching"
},
"groupSet": {
"items": [
{
"groupId": "sg-0b233157065b7d5e2"
}
]
},
"interfaceType": "interface",
"ipv6AddressesSet": {},
"macAddress": "12:c4:b6:95:a1:71",
"networkInterfaceId": "eni-076fa9fb98a2500a7",
"ownerId": "123837392027",
"privateIpAddress": "10.0.1.10",
"privateIpAddressesSet": {
"item": [
{
"primary": true,
"privateIpAddress": "10.0.1.10"
}
]
},
"sourceDestCheck": true,
"status": "in-use",
"subnetId": "subnet-0ed352584ab4aa265",
"tagSet": {},
"vpcId": "vpc-06fe1a64761a0f720"
}
]
},
"placement": {
"availabilityZone": "us-east-1a",
"tenancy": "default"
},
"privateDnsName": "ip-10-0-1-10.ec2.internal",
"privateDnsNameOptions": {
"enableResourceNameDnsAAAARecord": false,
"enableResourceNameDnsARecord": false,
"hostnameType": "ip-name"
},
"privateIpAddress": "10.0.1.10",
"productCodes": {},
"rootDeviceName": "/dev/xvda",
"rootDeviceType": "ebs",
"sourceDestCheck": true,
"stateReason": {
"code": "pending",
"message": "pending"
},
"subnetId": "subnet-0ed352584ab4aa265",
"tagSet": {
"items": [
{
"key": "StratusRedTeam",
"value": "true"
}
]
},
"virtualizationType": "hvm",
"vpcId": "vpc-06fe1a64761a0f720"
}
]
},
"ownerId": "123837392027",
"requestId": "95b435ce-68af-4a4b-b89c-f653d8946ebc",
"reservationId": "r-0ac0088de73525c3c"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) stratus-red-team_6a7ec681-49a5-4403-99a2-d3c1229e8063 HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Kusto #
T1583T1496Panther #
T1610T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more References #
RunScheduledInstances
#Description
Launches the specified Scheduled Instances.
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
SearchLocalGatewayRoutes
#Description
Searches for routes in the specified local gateway route table.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidLocalGatewayRouteTableID.Malformed",
"errorMessage": "The local-gateway-route-table ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "6721dc30-bb60-4b57-a7a7-fcf2e796c21f",
"eventName": "SearchLocalGatewayRoutes",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "73787cf8-5e1f-45b9-977d-d609d53d53c1",
"requestParameters": {
"SearchLocalGatewayRoutesRequest": {
"LocalGatewayRouteTableId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
SearchTransitGatewayMulticastGroups
#Description
Searches one or more transit gateway multicast groups and returns the group membership information.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidTransitGatewayMulticastDomainId.Malformed",
"errorMessage": "Invalid Transit Gateway Multicast Domain id dw-probe.",
"eventCategory": "Management",
"eventID": "ebf744f8-eae3-4a3e-915e-45d0e339fce7",
"eventName": "SearchTransitGatewayMulticastGroups",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "95faceaf-3feb-42f2-8b5d-cd39081ee7ce",
"requestParameters": {
"SearchTransitGatewayMulticastGroupsRequest": {
"TransitGatewayMulticastDomainId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
SearchTransitGatewayRoutes
#Description
Searches for routes in the specified transit gateway route table.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidRouteTableId.Malformed",
"errorMessage": "Invalid Transit Gateway Route Table id dw-probe.",
"eventCategory": "Management",
"eventID": "a858eb2a-5817-49b8-af80-c0d0cd8e5780",
"eventName": "SearchTransitGatewayRoutes",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T18:43:20Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "86b2a10e-facc-4725-abd9-7454eeba27ea",
"requestParameters": {
"SearchTransitGatewayRoutesRequest": {
"TransitGatewayRouteTableId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
SendDiagnosticInterrupt
#Description
Sends a diagnostic interrupt to the specified Amazon EC2 instance to trigger a kernel panic (on Linux instances), or a blue screen/stop error (on Windows instances).
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "d8f6f8f4-9f1a-4bd3-b799-2e10fe236268",
"eventName": "SendDiagnosticInterrupt",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:40:28Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "66fa8743-8716-4721-a6f4-bce5f825d736",
"requestParameters": {
"SendDiagnosticInterruptRequest": {
"InstanceId": "i-0a4c8f9124bcc1a50"
}
},
"responseElements": {
"SendDiagnosticInterruptResponse": {
"requestId": "66fa8743-8716-4721-a6f4-bce5f825d736",
"return": true,
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
StartDeclarativePoliciesReport
#Description
Generates an account status report.
StartNetworkInsightsAccessScopeAnalysis
#Description
Starts analyzing the specified Network Access Scope.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "002ed03e-885e-4694-8797-d1d4c5d7d398",
"eventName": "StartNetworkInsightsAccessScopeAnalysis",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:46:02Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ffa606dc-571b-4b3c-91a6-0c340a1a960b",
"requestParameters": {
"StartNetworkInsightsAccessScopeAnalysisRequest": {
"ClientToken": "b07a8413102f487c941db2ead4e53531",
"NetworkInsightsAccessScopeId": "nis-09c07334f0c179e68"
}
},
"responseElements": {
"StartNetworkInsightsAccessScopeAnalysisResponse": {
"networkInsightsAccessScopeAnalysis": {
"analyzedEniCount": 0,
"networkInsightsAccessScopeAnalysisArn": "arn:aws:ec2:us-west-1:123456789012:network-insights-access-scope-analysis/nisa-0dc1124eef8e941c8",
"networkInsightsAccessScopeAnalysisId": "nisa-0dc1124eef8e941c8",
"networkInsightsAccessScopeId": "nis-09c07334f0c179e68",
"startDate": "2026-06-29T22:46:02.441Z",
"status": "running"
},
"requestId": "ffa606dc-571b-4b3c-91a6-0c340a1a960b",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
StartNetworkInsightsAnalysis
#Description
Starts analyzing the specified path.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "4e866585-4cee-4ffd-a377-6740540dde92",
"eventName": "StartNetworkInsightsAnalysis",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:46:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c0bfa94c-4b09-4502-9a04-d011a011fe1e",
"requestParameters": {
"StartNetworkInsightsAnalysisRequest": {
"ClientToken": "5d89911309d44553bdd2883074b59ef1",
"NetworkInsightsPathId": "nip-01e67beb8a4227dca",
"TagSpecification": {
"ResourceType": "network-insights-analysis",
"Tag": [
{
"Key": "Name",
"Value": "dwfix-ec2-d393e412",
"tag": 1
},
{
"Key": "dwfix",
"Value": "1",
"tag": 2
}
],
"tag": 1
}
}
},
"responseElements": {
"StartNetworkInsightsAnalysisResponse": {
"networkInsightsAnalysis": {
"networkInsightsAnalysisArn": "arn:aws:ec2:us-west-1:123456789012:network-insights-analysis/nia-0ef9b1ad4688807e9",
"networkInsightsAnalysisId": "nia-0ef9b1ad4688807e9",
"networkInsightsPathId": "nip-01e67beb8a4227dca",
"startDate": "2026-06-29T22:46:01.170Z",
"status": "running",
"tagSet": {
"item": [
{
"key": "dwfix",
"value": "1"
},
{
"key": "Name",
"value": "dwfix-ec2-d393e412"
}
]
}
},
"requestId": "c0bfa94c-4b09-4502-9a04-d011a011fe1e",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
StartVpcEndpointServicePrivateDnsVerification
#Description
Initiates the verification process to prove that the service provider owns the private DNS name domain for the endpoint service.
TerminateClientVpnConnections
#Description
Terminates active Client VPN endpoint connections.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidClientVpnEndpointId.NotFound",
"errorMessage": "The client-vpn-endpoint ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "f945207d-45e5-4ec6-9d3d-6b06a54688d2",
"eventName": "TerminateClientVpnConnections",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:09Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "cd74fe20-51ac-4941-ab59-c17f66c929ab",
"requestParameters": {
"TerminateClientVpnConnectionsRequest": {
"ClientVpnEndpointId": "dw-probe"
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
TerminateInstances
#Description
Shuts down one or more instances.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "2d893b1d-e8f2-499b-a558-cb927d9b48ea",
"eventName": "TerminateInstances",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2023-07-10T12:08:06Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "df4f910a-c4dd-49eb-ab07-6d96fc5c142a",
"requestParameters": {
"instancesSet": {
"items": [
{
"instanceId": "i-0dbc91f429e48eeed"
}
]
}
},
"responseElements": {
"instancesSet": {
"items": [
{
"currentState": {
"code": 32,
"name": "shutting-down"
},
"instanceId": "i-0dbc91f429e48eeed",
"previousState": {
"code": 16,
"name": "running"
}
}
]
},
"requestId": "df4f910a-c4dd-49eb-ab07-6d96fc5c142a"
},
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.2"
},
"userAgent": "APN/1.0 HashiCorp/1.0 Terraform/1.1.2 (+https://www.terraform.io) terraform-provider-aws/3.76.1 (+https://registry.terraform.io/providers/hashicorp/aws) aws-sdk-go/1.44.157 (go1.19.3; linux; amd64) HashiCorp-terraform-exec/0.17.3",
"userIdentity": {
"accessKeyId": "AKIATFQR7NSC8Q4X20BJ",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more References #
UnassignIpv6Addresses
#Description
Unassigns the specified IPv6 addresses or Prefix Delegation prefixes from a network interface.
UnassignPrivateIpAddresses
#Description
Unassigns one or more secondary private IP addresses from a network interface.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "09fb2211-e234-4537-ab1d-48623bc2554e",
"eventName": "UnassignPrivateIpAddresses",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:45:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e5ed6bf6-735c-4d17-8050-791521e66f54",
"requestParameters": {
"ipv4Prefixes": {},
"networkInterfaceId": "eni-025f9aaa17cd9ff32",
"privateIpAddressesSet": {
"items": [
{
"privateIpAddress": "10.0.1.174"
}
]
}
},
"responseElements": {
"_return": true,
"requestId": "e5ed6bf6-735c-4d17-8050-791521e66f54"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UnassignPrivateNatGatewayAddress
#Description
Unassigns secondary private IPv4 addresses from a private NAT gateway.
UnlockSnapshot
#Description
Unlocks a snapshot that is locked in governance mode or that is locked in compliance mode but still in the cooling-off period.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "839ffd6e-1e29-4db7-a76f-e3a8825cc963",
"eventName": "UnlockSnapshot",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:42:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "7a9c7e4c-7d2c-403f-944b-08f6c6034e78",
"requestParameters": {
"UnlockSnapshotRequest": {
"SnapshotId": "snap-0c0fb4e5cd0eee943"
}
},
"responseElements": {
"UnlockSnapshotResponse": {
"requestId": "7a9c7e4c-7d2c-403f-944b-08f6c6034e78",
"snapshotId": "snap-0c0fb4e5cd0eee943",
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UnmonitorInstances
#Description
Disables monitoring for a running instance.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "f1713fbc-0362-4aba-b8f3-954c886c4561",
"eventName": "UnmonitorInstances",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:59:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6990c7dd-4a7e-4d90-9431-b70a5f1d5716",
"requestParameters": {
"instancesSet": {
"items": [
{
"instanceId": "i-08333cf57d87fa023"
}
]
}
},
"responseElements": {
"instancesSet": {
"items": [
{
"instanceId": "i-08333cf57d87fa023",
"monitoring": {
"state": "disabling"
}
}
]
},
"requestId": "6990c7dd-4a7e-4d90-9431-b70a5f1d5716"
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,D,n,Z cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Panther #
T1578↳ also matches AssociateIamInstanceProfile, CreateInstanceExportTask, ModifyInstanceAttribute, StartInstances, StopInstances, AssociateInstanceEventWindow, and 24 more
UpdateCapacityManagerMonitoredTagKeys
#Description
Activates or deactivates tag keys for monitoring by EC2 Capacity Manager.
UpdateCapacityManagerOrganizationsAccess
#Description
Updates the Organizations access setting for EC2 Capacity Manager.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.CapacityManager.Disabled",
"errorMessage": "Capacity Manager isn't enabled for this account.",
"eventCategory": "Management",
"eventID": "c07cf71d-b3fd-48cf-8abb-c60898897785",
"eventName": "UpdateCapacityManagerOrganizationsAccess",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "e95ca93d-0f57-4adc-931f-833f1edd374c",
"requestParameters": {
"UpdateCapacityManagerOrganizationsAccessRequest": {
"ClientToken": "106fd254-33fc-4c0a-876a-7e5d35c0d150",
"OrganizationsAccess": false
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateInterruptibleCapacityReservationAllocation
#Description
Modifies the number of instances allocated to an interruptible reservation, allowing you to add more capacity or reclaim capacity to your source Capacity Reservation.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"errorCode": "Client.InvalidCapacityReservationId.Malformed",
"errorMessage": "The capacity-reservation ID 'dw-probe' is malformed",
"eventCategory": "Management",
"eventID": "4b44c059-62a5-447f-943c-596f9a7bfb7d",
"eventName": "UpdateInterruptibleCapacityReservationAllocation",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T19:23:10Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "611eb9d1-8d1b-44dd-898a-5e979937bd6d",
"requestParameters": {
"UpdateInterruptibleCapacityReservationAllocationRequest": {
"CapacityReservationId": "dw-probe",
"TargetInstanceCount": 1
}
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateSecurityGroupRuleDescriptionsEgress
#Description
Updates the description of an egress (outbound) security group rule.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "da6f2f02-4740-48c4-bb93-6f7e11909d36",
"eventName": "UpdateSecurityGroupRuleDescriptionsEgress",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:39:59Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "50b66335-eaf8-4f00-b9b1-4c00e65e4a6e",
"requestParameters": {
"UpdateSecurityGroupRuleDescriptionsEgressRequest": {
"GroupId": "sg-0cfd1af7bf967b6fc",
"SecurityGroupRuleDescription": {
"Description": "HTTPS outbound",
"SecurityGroupRuleId": "sgr-0cc755a3be3a3211b",
"tag": 1
}
}
},
"responseElements": {
"UpdateSecurityGroupRuleDescriptionsEgressResponse": {
"requestId": "50b66335-eaf8-4f00-b9b1-4c00e65e4a6e",
"return": true,
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
UpdateSecurityGroupRuleDescriptionsIngress
#Description
Updates the description of an ingress (inbound) security group rule.
Example CloudTrail Event #
{
"awsRegion": "us-west-1",
"eventCategory": "Management",
"eventID": "829ee1ed-2b7f-4ac6-a88f-54b0cc63209e",
"eventName": "UpdateSecurityGroupRuleDescriptionsIngress",
"eventSource": "ec2.amazonaws.com",
"eventTime": "2026-06-29T22:39:58Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "6b07bb66-6961-4fc7-a4fc-dd267e624210",
"requestParameters": {
"UpdateSecurityGroupRuleDescriptionsIngressRequest": {
"GroupId": "sg-0cfd1af7bf967b6fc",
"SecurityGroupRuleDescription": {
"Description": "SSH from private network",
"SecurityGroupRuleId": "sgr-0977291ab4f93ff0b",
"tag": 1
}
}
},
"responseElements": {
"UpdateSecurityGroupRuleDescriptionsIngressResponse": {
"requestId": "6b07bb66-6961-4fc7-a4fc-dd267e624210",
"return": true,
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/"
}
},
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-west-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,n,b,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
WithdrawByoipCidr
#Description
Stops advertising an address range that is provisioned as an address pool.
BidEvictedEvent
#Description
BidEvictedEvent recorded by CloudTrail for Amazon EC2. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "267a19c7-d2d3-49fb-8be6-ca04ee3da7b9",
"eventSource": "ec2.amazonaws.com",
"eventName": "BidEvictedEvent",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"requestID": "69033b72-9327-3cf2-909f-ffeb40c5e6c9",
"userAgent": "ec2.amazonaws.com"
}
DeleteVpcResourceDeletion
#Description
DeleteVpcResourceDeletion recorded by CloudTrail for Amazon EC2. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "300f48f8-1120-41d9-b3f8-f39589129f8c",
"eventSource": "ec2.amazonaws.com",
"eventName": "DeleteVpcResourceDeletion",
"awsRegion": "ca-central-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"requestID": "c10241c5-6832-3a1e-a8b4-5f623bbb1e6c",
"userAgent": "ec2.amazonaws.com",
"resources": [
{
"accountId": "123456789012",
"type": "AWS::EC2::NetworkAcl",
"ARN": "arn:aws:ec2:ca-central-1:123456789012:network-acl/EXAMPLE"
},
{
"accountId": "123456789012",
"type": "AWS::EC2::RouteTable",
"ARN": "arn:aws:ec2:ca-central-1:123456789012:route-table/EXAMPLE"
},
{
"accountId": "123456789012",
"type": "AWS::EC2::SecurityGroup",
"ARN": "arn:aws:ec2:ca-central-1:123456789012:security-group/EXAMPLE"
}
]
}
DescribeVerifiedAccessInstanceWebAclAssociations
#Description
DescribeVerifiedAccessInstanceWebAclAssociations recorded by CloudTrail for Amazon EC2. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "ce3226ef-a11e-4a42-a89e-0db7469c22a5",
"eventSource": "ec2.amazonaws.com",
"eventName": "DescribeVerifiedAccessInstanceWebAclAssociations",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "ab0aeb00-ad0f-4c88-b15e-0cf79e15a967",
"userAgent": "wafv2.amazonaws.com"
}
AssociateApplicationStatusCheck
#Description
Associates an application status check with instances or tags.
BatchModifyIpamRoutingPolicyRegistrations
#Description
Modifies multiple routing policy registrations in a single operation.
CreateApplicationStatusCheck
#Description
Creates an application status check for monitoring the health of applications running on your instances.
CreateIpamInternetRegistryAssociation
#Description
Creates an association between an IPAM and a Regional Internet Registry (RIR) for Resource Public Key Infrastructure (RPKI) management.
CreateIpamRoutingPolicyRegistration
#Description
Creates a routing policy registration and publishes Route Origin Authorizations (ROAs) to the RPKI for the specified CIDR prefix and ASNs.
CreateTransitGatewayPolicyTableEntry
#Description
Creates an entry in a transit gateway policy table to route matching traffic to a specified route table.
DeleteApplicationStatusCheck
#Description
Deletes an application status check.
DeleteIpamInternetRegistryAssociation
#Description
Deletes an IPAM internet registry association.
DeleteIpamRoutingPolicyRegistration
#Description
Deletes a routing policy registration for a specified CIDR prefix.
DeleteTransitGatewayPolicyTableEntry
#Description
Deletes the specified transit gateway policy table entry.
DescribeAccountVpcEncryptionControl
#Description
Describes the account-level VPC Encryption Control configuration for your account.
DescribeApplicationStatus
#Description
Describes the application status for the specified instances.
DescribeApplicationStatusCheckAssociations
#Description
Describes the associations for one or more application status checks.
DescribeApplicationStatusChecks
#Description
Describes one or more application status checks.
DescribeIpamInternetRegistryAssociations
#Description
Describes one or more IPAM internet registry associations.
DisableApplicationStatusCheckSuppression
#Description
Disables suppression of application status checks for the specified instances.
DisassociateApplicationStatusCheck
#Description
Disassociates an application status check from instances or tags.
EnableApplicationStatusCheckSuppression
#Description
Suppresses application status checks for the specified instances.
EnableIpamInternetRegistryAssociation
#Description
Enables Resource Public Key Infrastructure (RPKI) on an existing IPAM internet registry association by providing BGP Public Key Infrastructure (BPKI) certificate details.
GetIpamDiscoveredRoutes
#Description
Retrieves Border Gateway Protocol (BGP) routes discovered by IPAM resource discovery for a specified Region.
GetIpamInternetRegistryAssociationAsns
#Description
Retrieves Autonomous System Numbers (ASNs) registered with an internet registry for an IPAM internet registry association.
GetIpamInternetRegistryAssociationCidrs
#Description
Retrieves IP address CIDRs registered with an internet registry for an IPAM internet registry association.
GetIpamRouteProtectionFindings
#Description
Retrieves route protection findings for an IPAM.
GetIpamRoutingPolicyRegistrationDeltas
#Description
Retrieves the history of routing policy registration changes for an IPAM internet registry association.
GetIpamRoutingPolicyRegistrations
#Description
Retrieves routing policy registrations for an IPAM internet registry association.
ModifyAccountVpcEncryptionControl
#Description
Modifies the account-level VPC Encryption Control configuration.
ModifyApplicationStatusCheck
#Description
Modifies an existing application status check.
ModifyIpamRoutingPolicyRegistration
#Description
Modifies an existing routing policy registration.
ModifyTransitGatewayPolicyTableEntry
#Description
Modifies the specified transit gateway policy table entry.
ModifyVpcEndpointPayerResponsibility
#Description
Modifies the billing account for VPC endpoint usage/charges.