AWS Organizations
| eventName | Description | Sample | Rule |
|---|---|---|---|
| any | Catch-all entry for AWS Organizations rules that match the service but not a specific eventName. | N | N |
| Describe | Retrieves information about the organization that the calling account belongs to. | Y | Y |
| Describe | Retrieves the resource-based policy that is attached to the organization's management account. | Y | Y |
| Leave | Removes the current member account from its parent organization, making it a standalone account. | Y | Y |
| List | Lists all the accounts in the organization. | Y | Y |
| List | Lists the accounts in an organizational unit or the root that is specified as the parent. | Y | Y |
| List | Returns a list of AWS services for which AWS Organizations has enabled integration (trusted access) with the organization. | Y | Y |
| List | Lists the AWS accounts that are designated as delegated administrators for the specified AWS service in the organization. | Y | Y |
| List | Lists the AWS services for which the specified account is a delegated administrator in the organization. | Y | Y |
| List | Lists the organizational units (OUs) in a parent root or OU. | Y | Y |
| List | Retrieves the list of all policies in an organization of a specified type. | Y | Y |
| List | Lists the roots that are defined in the organization. | Y | Y |
| Remove | Removes a member account from its parent organization; can only be called from the management account. | N | Y |
| Accept | Accepts a handshake by sending an ACCEPTED response to the sender. | Y | N |
| Attach | Attaches a policy to a root, an organizational unit (OU), or an individual account. | N | N |
| Cancel | Cancels a Handshake. | N | N |
| Close | Closes an Amazon Web Services member account within an organization. | N | Y |
| Create | Creates an Amazon Web Services account that is automatically a member of the organization whose credentials made the request. | N | N |
| Create | This action is available if all of the following are true: You're authorized to create accounts in the Amazon Web Services GovCloud (US) Region. | N | N |
| Create | Creates an Amazon Web Services organization. | N | N |
| Create | Creates an organizational unit (OU) within a root or parent OU. | N | N |
| Create | Creates a policy of a specified type that you can attach to a root, an organizational unit (OU), or an individual Amazon Web Services account. | N | N |
| Decline | Declines a Handshake. | N | N |
| Delete | Deletes the organization. | Y | N |
| Delete | Deletes an organizational unit (OU) from a root or another OU. | N | N |
| Delete | Deletes the specified policy from your organization. | N | N |
| Delete | Deletes the resource policy from your organization. | Y | N |
| Deregister | Removes the specified member Amazon Web Services account as a delegated administrator for the specified Amazon Web Services service. | N | N |
| Describe | Retrieves Organizations-related information about the specified account. | Y | N |
| Describe | Retrieves the current status of an asynchronous request to create an account. | N | N |
| Describe | Returns the contents of the effective policy for specified policy type and account. | Y | N |
| Describe | Returns details for a handshake. | N | N |
| Describe | Retrieves information about an organizational unit (OU). | N | N |
| Describe | Retrieves information about a policy. | Y | N |
| Describe | Returns details for a transfer. | N | N |
| Detach | Detaches a policy from a target root, organizational unit (OU), or account. | N | N |
| Disable | Disables the integration of an Amazon Web Services service (the service that is specified by ServicePrincipal) with Organizations. | Y | N |
| Disable | Disables an organizational policy type in a root. | N | N |
| Enable | Enables all features in an organization. | N | N |
| Enable | Provides an Amazon Web Services service (the service that is specified by ServicePrincipal) with permissions to view the structure of an organization, create a service-linked role in all the accounts in the organization, and allow the servi. | N | N |
| Enable | Enables a policy type in a root. | N | N |
| Invite | Sends an invitation to another account to join your organization as a member account. | N | N |
| Invite | Sends an invitation to another organization's management account to designate your account with the specified responsibilities for their organization. | N | N |
| List | Lists all the accounts in an organization that have invalid effective policies. | Y | N |
| List | Lists all of the organizational units (OUs) or accounts that are contained in the specified parent OU or root. | N | N |
| List | Lists the account creation requests that match the specified status that is currently being tracked for the organization. | Y | N |
| List | Lists all the validation errors on an effective policy for a specified account and policy type. | N | N |
| List | Lists the recent handshakes that you have received. | Y | N |
| List | Lists the recent handshakes that you have sent. | Y | N |
| List | Lists transfers that allow you to manage the specified responsibilities for another organization. | Y | N |
| List | Lists transfers that allow an account outside your organization to manage the specified responsibilities for your organization. | Y | N |
| List | Lists the root or organizational units (OUs) that serve as the immediate parent of the specified child OU or account. | N | N |
| List | Lists the policies that are directly attached to the specified target root, organizational unit (OU), or account. | N | N |
| List | Lists tags that are attached to the specified resource. | N | N |
| List | Lists all the roots, organizational units (OUs), and accounts that the specified policy is attached to. | N | N |
| Move | Moves an account from its current source parent root or organizational unit (OU) to the specified destination parent root or OU. | N | N |
| Put | Creates or updates a resource policy. | N | N |
| Register | Enables the specified member account to administer the Organizations features of the specified Amazon Web Services service. | N | N |
| Tag | Adds one or more tags to the specified resource. | N | N |
| Terminate | Ends a transfer. | N | N |
| Untag | Removes any tags with the specified keys from the specified resource. | N | N |
| Update | Renames the specified organizational unit (OU). | N | N |
| Update | Updates an existing policy with a new name, description, or content. | N | N |
| Update | Updates a transfer. | N | N |
| Account | AccountJoinedOrganization recorded by CloudTrail for AWS Organizations. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
| Create | CreateAccountResult recorded by CloudTrail for AWS Organizations. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK. | N | N |
any: AWS Organizations (catch-all)
#Description
Catch-all entry for AWS Organizations rules that match the service but not a specific eventName.
DescribeOrganization
#Description
Retrieves information about the organization that the calling account belongs to.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "5b5575f9-d4ef-4651-86c1-7618d49689f5",
"eventName": "DescribeOrganization",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2023-07-10T12:28:21Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "6d37d964-2b01-4b18-ab97-46e3c4abc522",
"requestParameters": null,
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCS5BLNV76",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
cloud.account.id and user.name pair for these actions.T1087, T1087.004, T1580↳ also matches DescribeResourcePolicy, ListAccounts, ListAccountsForParent, ListAWSServiceAccessForOrganization, ListDelegatedAdministrators, ListDelegatedServicesForAccount, and 3 more
References #
DescribeResourcePolicy
#Description
Retrieves the resource-based policy that is attached to the organization's management account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AWSOrganizationsNotInUseException",
"eventCategory": "Management",
"eventID": "c23dff9f-55dc-4d22-84c9-87001731f885",
"eventName": "DescribeResourcePolicy",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2026-06-29T18:32:27Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "de6e0d1c-6af7-4b07-8b3b-c8567021512b",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
cloud.account.id and user.name pair for these actions.T1087, T1087.004, T1580↳ also matches DescribeOrganization, ListAccounts, ListAccountsForParent, ListAWSServiceAccessForOrganization, ListDelegatedAdministrators, ListDelegatedServicesForAccount, and 3 more
LeaveOrganization
#Description
Removes the current member account from its parent organization, making it a standalone account.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:sts::123837392027:assumed-role/stratus-red-team-leave-org-role/aws-go-sdk-1688990515440126480 is not authorized to perform: organizations:LeaveOrganization on resource: * because no identity-based policy allows the organizations:LeaveOrganization action",
"eventCategory": "Management",
"eventID": "be7f89b5-d456-4423-b3e6-0fb0b19bad7c",
"eventName": "LeaveOrganization",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2023-07-10T12:02:05Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123837392027",
"requestID": "0c762aa3-c5df-4a3b-8a14-5a3b3791ecbd",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "192.168.10.20",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "stratus-red-team_7d2a6913-ded3-49c6-a31c-0cdeebcc259c",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCVW2R4OHT",
"accountId": "123837392027",
"arn": "arn:aws:sts::123837392027:assumed-role/stratus-red-team-leave-org-role/aws-go-sdk-1688990515440126480",
"principalId": "AROATFQR7NSCRI4ZA26CX:aws-go-sdk-1688990515440126480",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:02:04Z",
"mfaAuthenticated": "false"
},
"sessionIssuer": {
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:role/stratus-red-team-leave-org-role",
"principalId": "AROATFQR7NSCRI4ZA26CX",
"type": "Role",
"userName": "stratus-red-team-leave-org-role"
},
"webIdFederationData": {}
},
"type": "AssumedRole"
}
}
Detection Rules #
Elastic #
T1531, T1562, T1562.001YARA-L #
T1562↳ also matches RemoveAccountFromOrganization Panther #
T1562.008, T1666References #
ListAccounts
#Description
Lists all the accounts in the organization.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "CallerValidation check failed",
"eventCategory": "Management",
"eventID": "d4b70738-0e10-4017-b2fd-7da076d1af28",
"eventName": "ListAccounts",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2021-04-13T13:33:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "731544447609",
"requestID": "a9535fb7-c8ad-4cae-8cf1-3bfd3e71b6e0",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "34.12.134.20",
"userAgent": "Boto3/1.14.6 Python/3.9.4 Darwin/20.3.0 Botocore/1.17.6",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLIXX7QSZR",
"accountId": "731544447609",
"arn": "arn:aws:iam::731544447609:user/cloudmapper",
"principalId": "AIDAYTOGP2RLK32EB7QZV",
"type": "IAMUser",
"userName": "cloudmapper"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
cloud.account.id and user.name pair for these actions.T1087, T1087.004, T1580↳ also matches DescribeOrganization, DescribeResourcePolicy, ListAccountsForParent, ListAWSServiceAccessForOrganization, ListDelegatedAdministrators, ListDelegatedServicesForAccount, and 3 more
References #
ListAccountsForParent
#Description
Lists the accounts in an organizational unit or the root that is specified as the parent.
Example CloudTrail Event #
{
"eventVersion": "1.11",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE"
},
"eventTime": "2026-07-28T20:59:04Z",
"eventSource": "organizations.amazonaws.com",
"eventName": "ListAccountsForParent",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/n,Z,E,C,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#organizations.list-accounts-for-parent",
"errorCode": "AWSOrganizationsNotInUseException",
"requestParameters": null,
"responseElements": null,
"requestID": "1604929e-af00-420a-8db2-7196c9740bbb",
"eventID": "b0de8cf1-011f-4eb6-84e7-deb9e09b508f",
"readOnly": true,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
cloud.account.id and user.name pair for these actions.T1087, T1087.004, T1580↳ also matches DescribeOrganization, DescribeResourcePolicy, ListAccounts, ListAWSServiceAccessForOrganization, ListDelegatedAdministrators, ListDelegatedServicesForAccount, and 3 more
ListAWSServiceAccessForOrganization
#Description
Returns a list of AWS services for which AWS Organizations has enabled integration (trusted access) with the organization.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: organizations:ListAWSServiceAccessForOrganization on resource: *",
"eventID": "db1b9709-d847-4d75-8571-364423f0b97d",
"eventName": "ListAWSServiceAccessForOrganization",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2019-10-19T23:49:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.05",
"recipientAccountId": "811596193553",
"requestID": "865251-856a-4e70-b4ac-d6cb03f26f14",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "213.253.166.5",
"userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
cloud.account.id and user.name pair for these actions.T1087, T1087.004, T1580↳ also matches DescribeOrganization, DescribeResourcePolicy, ListAccounts, ListAccountsForParent, ListDelegatedAdministrators, ListDelegatedServicesForAccount, and 3 more
References #
ListDelegatedAdministrators
#Description
Lists the AWS accounts that are designated as delegated administrators for the specified AWS service in the organization.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventCategory": "Management",
"eventID": "3697daff-dcbd-4824-acf9-710362af8afc",
"eventName": "ListDelegatedAdministrators",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2023-07-10T12:29:18Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123837392027",
"requestID": "e41016c8-44c3-44ed-8a77-90c2f6b370e7",
"requestParameters": {
"servicePrincipal": "cloudtrail.amazonaws.com"
},
"responseElements": null,
"sessionCredentialFromConsole": "true",
"sourceIPAddress": "10.8.8.10",
"userAgent": "AWS Internal",
"userIdentity": {
"accessKeyId": "ASIATFQR7NSCXRLH2ACF",
"accountId": "123837392027",
"arn": "arn:aws:iam::123837392027:user/bert-jan",
"principalId": "AIDATFQR7NSC5AU2ZV3IE",
"sessionContext": {
"attributes": {
"creationDate": "2023-07-10T12:27:45Z",
"mfaAuthenticated": "true"
},
"sessionIssuer": {},
"webIdFederationData": {}
},
"type": "IAMUser",
"userName": "bert-jan"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
cloud.account.id and user.name pair for these actions.T1087, T1087.004, T1580↳ also matches DescribeOrganization, DescribeResourcePolicy, ListAccounts, ListAccountsForParent, ListAWSServiceAccessForOrganization, ListDelegatedServicesForAccount, and 3 more
References #
ListDelegatedServicesForAccount
#Description
Lists the AWS services for which the specified account is a delegated administrator in the organization.
Example CloudTrail Event #
{
"eventVersion": "1.11",
"userIdentity": {
"type": "Root",
"principalId": "123456789012",
"arn": "arn:aws:iam::123456789012:root",
"accountId": "123456789012",
"accessKeyId": "AKIAIOSFODNN7EXAMPLE"
},
"eventTime": "2026-07-28T20:59:07Z",
"eventSource": "organizations.amazonaws.com",
"eventName": "ListDelegatedServicesForAccount",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.5",
"userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/n,Z,E,C,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#organizations.list-delegated-services-for-account",
"errorCode": "AWSOrganizationsNotInUseException",
"requestParameters": null,
"responseElements": null,
"requestID": "020905fb-b784-4636-b82c-0342b006d8ee",
"eventID": "e31a54c1-40ea-4d24-b033-7f4b43da9887",
"readOnly": true,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "123456789012",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
cloud.account.id and user.name pair for these actions.T1087, T1087.004, T1580↳ also matches DescribeOrganization, DescribeResourcePolicy, ListAccounts, ListAccountsForParent, ListAWSServiceAccessForOrganization, ListDelegatedAdministrators, and 3 more
ListOrganizationalUnitsForParent
#Description
Lists the organizational units (OUs) in a parent root or OU.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::123456789012:user/TrailDiscover is not authorized to perform: organizations:ListOrganizationalUnitsForParent on resource: arn:aws:organizations::123456789012:root/o-t7q5oihfb0/r-traildiscover because no resource-based policy allows the organizations:ListOrganizationalUnitsForParent action",
"eventCategory": "Management",
"eventID": "68f65a74-1ca7-4654-8e96-17a9c4cba479",
"eventName": "ListOrganizationalUnitsForParent",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2024-08-18T08:56:45Z",
"eventType": "AwsApiCall",
"eventVersion": "1.09",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "26b87752-be34-491f-b77a-9388d036665a",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "0.0.0.0",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "aws-cli/2.17.32 md/awscrt#0.21.2 ua/2.0 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.11.9 md/pyimpl#CPython exec-env/grimoire_d5090842-6dc5-41cc-841d-519ed768ab5b cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#organizations.list-organizational-units-for-parent",
"userIdentity": {
"accessKeyId": "AKIA****************",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/TrailDiscover",
"principalId": "AROA****************:User",
"type": "IAMUser",
"userName": "TrailDiscover"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
cloud.account.id and user.name pair for these actions.T1087, T1087.004, T1580↳ also matches DescribeOrganization, DescribeResourcePolicy, ListAccounts, ListAccountsForParent, ListAWSServiceAccessForOrganization, ListDelegatedAdministrators, and 3 more
References #
ListPolicies
#Description
Retrieves the list of all policies in an organization of a specified type.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: organizations:ListPolicies on resource: *",
"eventID": "5548f194-95dc-48db-8c19-285ecfa33877",
"eventName": "ListPolicies",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2018-11-05T13:01:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "e006ae25-e0fa-11e8-a2b0-70810de9c71f",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "245.70.252.112",
"userAgent": "aws-cli/1.16.47 Python/2.7.13 Linux/4.17.0-3rodete2-amd64 botocore/1.12.37",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
cloud.account.id and user.name pair for these actions.T1087, T1087.004, T1580↳ also matches DescribeOrganization, DescribeResourcePolicy, ListAccounts, ListAccountsForParent, ListAWSServiceAccessForOrganization, ListDelegatedAdministrators, and 3 more
References #
ListRoots
#Description
Lists the roots that are defined in the organization.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: organizations:ListRoots on resource: *",
"eventID": "4a51237d-9a32-4f71-9916-09b4f9adb6fc",
"eventName": "ListRoots",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2018-11-05T13:01:46Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "f392a56a-e0fa-11e8-b3c3-af159c59891c",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "245.70.252.112",
"userAgent": "aws-cli/1.16.47 Python/2.7.13 Linux/4.17.0-3rodete2-amd64 botocore/1.12.37",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Elastic #
cloud.account.id and user.name pair for these actions.T1087, T1087.004, T1580↳ also matches DescribeOrganization, DescribeResourcePolicy, ListAccounts, ListAccountsForParent, ListAWSServiceAccessForOrganization, ListDelegatedAdministrators, and 3 more
References #
RemoveAccountFromOrganization
#Description
Removes a member account from its parent organization; can only be called from the management account.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
YARA-L #
T1562↳ also matches LeaveOrganization
AcceptHandshake
#Description
Accepts a handshake by sending an ACCEPTED response to the sender.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"eventID": "b009869-2939-4bab-a57f-306692d4b969",
"eventName": "AcceptHandshake",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2017-07-17T16:20:57Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "e7e2c503-6b0b-11e7-b691-0f41c764907e",
"requestParameters": {
"handshakeId": "h-8d51878f67b07021e14ef1e02fa19a4a"
},
"responseElements": {
"handshake": {
"action": "INVITE",
"arn": "arn:aws:organizations::745598359964:handshake/o-57vb65iy55/invite/h-8d51878f67b07021e14ef1e02fa19a4a",
"expirationTimestamp": "Aug 1, 2017 4:20:26 PM",
"id": "h-8d51878f67b07021e14ef1e02fa19a4a",
"parties": [
{
"id": "811596193553",
"type": "ACCOUNT"
},
{
"id": "57vb65iy55",
"type": "ORGANIZATION"
}
],
"requestedTimestamp": "Jul 17, 2017 4:20:26 PM",
"resources": [
{
"resources": [
{
"type": "MASTER_EMAIL",
"value": "****"
},
{
"type": "MASTER_NAME",
"value": "****"
},
{
"type": "ORGANIZATION_FEATURE_SET",
"value": "ALL"
}
],
"type": "ORGANIZATION",
"value": "o-57vb65iy55"
},
{
"type": "EMAIL",
"value": "****"
}
],
"state": "ACCEPTED"
}
},
"sharedEventID": "0b89a44a-1969-486e-b58d-a76f1def2d18",
"sourceIPAddress": "255.253.125.115",
"userAgent": "AWS Organizations Console, aws-internal/3",
"userIdentity": {
"accessKeyId": "ASIAJGRK5PZ30YTNRAT0",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:root",
"principalId": "811596193553",
"sessionContext": {
"attributes": {
"creationDate": "2017-07-17T16:18:27Z",
"mfaAuthenticated": "true"
}
},
"type": "Root"
}
}
References #
AttachPolicy
#Description
Attaches a policy to a root, an organizational unit (OU), or an individual account.
CloudTrail management event, logged by default.
CancelHandshake
#Description
Cancels a Handshake.
CloseAccount
#Description
Closes an Amazon Web Services member account within an organization.
CloudTrail management event, logged by default. Full rule details for this event, including ATT&CK technique mappings and native queries →Detection Rules #
Elastic #
T1485, T1531
CreateAccount
#Description
Creates an Amazon Web Services account that is automatically a member of the organization whose credentials made the request.
CloudTrail management event, logged by default. This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.Example CloudTrail Event #
{
"eventVersion": "1.11",
"eventID": "89ff413a-e00e-4b1f-b216-67127a3bc3ae",
"eventSource": "organizations.amazonaws.com",
"eventName": "CreateAccount",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "3d7e0bf8-aec0-4bd8-9167-0b1bb0bf23ba",
"userAgent": "AWSStepFunctions aws-sdk-java/2.48.1 md/io#async md/http#NettyNio md/internal ua/2.1 api/Organizations#2.46.x os/Linux#4.14.355-284.740.amzn2.x86_64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+12-LTS md/vendor#Amazon.com_Inc. md/en_US md/kotlin/2.3.21-release-298 m/D,AL,e",
"tlsDetails": {
"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
}
}
CreateGovCloudAccount
#Description
This action is available if all of the following are true: You're authorized to create accounts in the Amazon Web Services GovCloud (US) Region.
CreateOrganization
#Description
Creates an Amazon Web Services organization.
CreateOrganizationalUnit
#Description
Creates an organizational unit (OU) within a root or parent OU.
CreatePolicy
#Description
Creates a policy of a specified type that you can attach to a root, an organizational unit (OU), or an individual Amazon Web Services account.
CloudTrail management event, logged by default.
DeclineHandshake
#Description
Declines a Handshake.
DeleteOrganization
#Description
Deletes the organization.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AWSOrganizationsNotInUseException",
"eventCategory": "Management",
"eventID": "312bd1c1-2869-4e61-88dc-8297d1e51f89",
"eventName": "DeleteOrganization",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2026-06-29T19:45:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "c51385d2-f3f5-42f7-9044-e6ea713a854a",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeleteOrganizationalUnit
#Description
Deletes an organizational unit (OU) from a root or another OU.
DeletePolicy
#Description
Deletes the specified policy from your organization.
CloudTrail management event, logged by default.
DeleteResourcePolicy
#Description
Deletes the resource policy from your organization.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AWSOrganizationsNotInUseException",
"eventCategory": "Management",
"eventID": "a24dbc61-4bd3-4070-a147-cbc7ad91c5c6",
"eventName": "DeleteResourcePolicy",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2026-06-29T19:45:31Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "ee6c21cc-0116-4778-906f-7e9209b70bf1",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DeregisterDelegatedAdministrator
#Description
Removes the specified member Amazon Web Services account as a delegated administrator for the specified Amazon Web Services service.
CloudTrail management event, logged by default.
DescribeAccount
#Description
Retrieves Organizations-related information about the specified account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: organizations:DescribeAccount on resource: arn:aws:organizations::745598359964:account/o-57vb65iy55/811596193553",
"eventID": "e06ee5d5-ab5d-4ae2-a580-64cdc341e3cd",
"eventName": "DescribeAccount",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2017-11-05T00:15:01Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "5dbbdf94-c1be-11e7-9b01-67c4270b379a",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "1.198.254.60",
"userAgent": "Boto3/1.4.7 Python/2.7.13 Darwin/16.7.0 Botocore/1.7.38",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
DescribeCreateAccountStatus
#Description
Retrieves the current status of an asynchronous request to create an account.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "0f2a1a05-62b7-45ee-8dbf-929166b83057",
"eventSource": "organizations.amazonaws.com",
"eventName": "DescribeCreateAccountStatus",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "efd70aa1-e74b-4b37-938c-160afffd9fb2",
"userAgent": "AWSStepFunctions aws-sdk-java/2.48.1 md/io#async md/http#NettyNio md/internal ua/2.1 api/Organizations#2.46.x os/Linux#4.14.355-284.740.amzn2.x86_64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+12-LTS md/vendor#Amazon.com_Inc. md/en_US md/kotlin/2.3.21-release-298 m/D,AL,e",
"tlsDetails": {
"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
}
}
DescribeEffectivePolicy
#Description
Returns the contents of the effective policy for specified policy type and account.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AWSOrganizationsNotInUseException",
"eventCategory": "Management",
"eventID": "b5e95761-64c5-44d8-bb68-bbd8e9fce322",
"eventName": "DescribeEffectivePolicy",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2026-06-29T18:45:14Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "1cf7c24f-4e0e-4632-b48b-f137a543ccda",
"requestParameters": {
"policyType": "TAG_POLICY"
},
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DescribeHandshake
#Description
Returns details for a handshake.
DescribeOrganizationalUnit
#Description
Retrieves information about an organizational unit (OU).
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "3d528730-d493-3202-a890-19a558fe1356",
"eventSource": "organizations.amazonaws.com",
"eventName": "DescribeOrganizationalUnit",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "dbba6cf9-9d71-48d0-ae90-24876717c6b6",
"userAgent": "aws-sdk-dotnet-coreclr/4.0.11.13 ua/2.1 os/linux#6.1.176.221 md/ARCH#Arm64 lang/.NET_Core#10.0.10 exec-env/AWS_ECS_EC2 md/aws-sdk-dotnet-core#4.0.100.3 api/Organizations#4.0.11.13 md/ClientAsync cfg/init-coll#0 m/b,P,i,E",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
}
}
DescribePolicy
#Description
Retrieves information about a policy.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: organizations:DescribePolicy on resource: arn:aws:organizations::745598359964:policy/o-57vb65iy55/UNKNOWN/p-ANPA1WYEAOB5NS7A9TAEB",
"eventID": "22a959ed-752d-4ffa-bdb9-141d3f394058",
"eventName": "DescribePolicy",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2018-04-23T10:04:52Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "c39b1f1d-46dd-11e8-a21d-e4bb5f858199",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "150.5.17.8",
"userAgent": "aws-cli/1.11.139 Python/3.6.3 Linux/4.13.0-38-generic botocore/1.6.6",
"userIdentity": {
"accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/Level6",
"principalId": "AIDADO2GQD0K8TEF7KW1V",
"type": "IAMUser",
"userName": "Level6"
}
}
References #
DescribeResponsibilityTransfer
#Description
Returns details for a transfer.
DetachPolicy
#Description
Detaches a policy from a target root, organizational unit (OU), or account.
CloudTrail management event, logged by default.
DisableAWSServiceAccess
#Description
Disables the integration of an Amazon Web Services service (the service that is specified by ServicePrincipal) with Organizations.
CloudTrail management event, logged by default.Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AWSOrganizationsNotInUseException",
"eventCategory": "Management",
"eventID": "35671b01-5a15-4fd2-bcd7-a4756a239504",
"eventName": "DisableAWSServiceAccess",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2026-06-29T19:24:54Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": false,
"recipientAccountId": "123456789012",
"requestID": "54c21fe6-e168-4503-bfb1-10229647ee31",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
DisablePolicyType
#Description
Disables an organizational policy type in a root.
CloudTrail management event, logged by default.
EnableAllFeatures
#Description
Enables all features in an organization.
EnableAWSServiceAccess
#Description
Provides an Amazon Web Services service (the service that is specified by ServicePrincipal) with permissions to view the structure of an organization, create a service-linked role in all the accounts in the organization, and allow the servi.
CloudTrail management event, logged by default.
EnablePolicyType
#Description
Enables a policy type in a root.
InviteAccountToOrganization
#Description
Sends an invitation to another account to join your organization as a member account.
CloudTrail management event, logged by default.
InviteOrganizationToTransferResponsibility
#Description
Sends an invitation to another organization's management account to designate your account with the specified responsibilities for their organization.
ListAccountsWithInvalidEffectivePolicy
#Description
Lists all the accounts in an organization that have invalid effective policies.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AWSOrganizationsNotInUseException",
"eventCategory": "Management",
"eventID": "a31a8340-b788-4e5b-948e-eeb72067043b",
"eventName": "ListAccountsWithInvalidEffectivePolicy",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2026-06-29T18:45:15Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "27f91d6c-f771-471f-b665-4e9a28a5ccd6",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListChildren
#Description
Lists all of the organizational units (OUs) or accounts that are contained in the specified parent OU or root.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "1555a106-eaf6-3602-83ba-2d5917a64949",
"eventSource": "organizations.amazonaws.com",
"eventName": "ListChildren",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "bd1c2267-8d36-4116-b29c-f5fcdf51502c",
"userAgent": "aws-sdk-dotnet-coreclr/4.0.11.13 ua/2.1 os/linux#6.1.176.221 md/ARCH#Arm64 lang/.NET_Core#10.0.10 exec-env/AWS_ECS_EC2 md/aws-sdk-dotnet-core#4.0.100.3 api/Organizations#4.0.11.13 md/ClientAsync cfg/init-coll#0 m/b,P,i,E,C",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
}
}
ListCreateAccountStatus
#Description
Lists the account creation requests that match the specified status that is currently being tracked for the organization.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: organizations:ListCreateAccountStatus on resource: *",
"eventID": "cf99cec0-8664-4883-b003-6b902e4008c6",
"eventName": "ListCreateAccountStatus",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2018-11-24T19:59:33Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "219642d-f023-11e8-9496-c9c363f4b14a",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "16.12.99.2",
"userAgent": "Boto3/1.7.4 Python/3.6.5 Linux/4.15.0-39-generic Botocore/1.10.4",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
ListEffectivePolicyValidationErrors
#Description
Lists all the validation errors on an effective policy for a specified account and policy type.
ListHandshakesForAccount
#Description
Lists the recent handshakes that you have received.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::731544447609:user/cloudsploit is not authorized to perform: organizations:ListHandshakesForAccount on resource: *",
"eventCategory": "Management",
"eventID": "874d11ce-f4a7-4589-96c1-1beb8a701c10",
"eventName": "ListHandshakesForAccount",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2021-04-13T11:35:25Z",
"eventType": "AwsApiCall",
"eventVersion": "1.08",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "731544447609",
"requestID": "a71481fe-248d-48b0-b233-a51dc40ffeb2",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "34.12.134.20",
"userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
"userIdentity": {
"accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
"accountId": "731544447609",
"arn": "arn:aws:iam::731544447609:user/cloudsploit",
"principalId": "AIDAYTOGP2RLMDEPWZWMJ",
"type": "IAMUser",
"userName": "cloudsploit"
}
}
References #
ListHandshakesForOrganization
#Description
Lists the recent handshakes that you have sent.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AccessDenied",
"errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: organizations:ListHandshakesForOrganization on resource: *",
"eventID": "7dea0e61-25ed-4b44-a057-71b22b8ddf21",
"eventName": "ListHandshakesForOrganization",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2018-11-24T19:59:35Z",
"eventType": "AwsApiCall",
"eventVersion": "1.04",
"recipientAccountId": "811596193553",
"requestID": "777be53e-f023-11e8-ad23-455b670e6960",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "16.12.99.2",
"userAgent": "Boto3/1.7.4 Python/3.6.5 Linux/4.15.0-39-generic Botocore/1.10.4",
"userIdentity": {
"accessKeyId": "AKIA01U43UX3RBRDXF4Q",
"accountId": "811596193553",
"arn": "arn:aws:iam::811596193553:user/backup",
"principalId": "AIDA9BO36HFBHKGJAO9C1",
"type": "IAMUser",
"userName": "backup"
}
}
References #
ListInboundResponsibilityTransfers
#Description
Lists transfers that allow you to manage the specified responsibilities for another organization.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AWSOrganizationsNotInUseException",
"eventCategory": "Management",
"eventID": "9a252037-ab81-4b5f-ab80-e1787cb2179f",
"eventName": "ListInboundResponsibilityTransfers",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2026-06-29T18:45:17Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "dd81b648-4b4d-4002-bb99-365e8c779e5f",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListOutboundResponsibilityTransfers
#Description
Lists transfers that allow an account outside your organization to manage the specified responsibilities for your organization.
Example CloudTrail Event #
{
"awsRegion": "us-east-1",
"errorCode": "AWSOrganizationsNotInUseException",
"eventCategory": "Management",
"eventID": "1e163614-773e-4b8b-b4ff-1a9a1a990d6b",
"eventName": "ListOutboundResponsibilityTransfers",
"eventSource": "organizations.amazonaws.com",
"eventTime": "2026-06-29T18:45:17Z",
"eventType": "AwsApiCall",
"eventVersion": "1.11",
"managementEvent": true,
"readOnly": true,
"recipientAccountId": "123456789012",
"requestID": "50e47b0e-0ed6-4879-bb75-db462b6d74d7",
"requestParameters": null,
"responseElements": null,
"sourceIPAddress": "203.0.113.5",
"tlsDetails": {
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
"tlsVersion": "TLSv1.3"
},
"userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
"userIdentity": {
"accessKeyId": "AKIAIOSFODNN7EXAMPLE",
"accountId": "123456789012",
"arn": "arn:aws:iam::123456789012:user/sample-user",
"principalId": "AIDAEXAMPLE00000000",
"type": "IAMUser",
"userName": "sample-user"
}
}
ListParents
#Description
Lists the root or organizational units (OUs) that serve as the immediate parent of the specified child OU or account.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "a8c9e384-f10e-43bd-91fd-d9ca4a3e4bd4",
"eventSource": "organizations.amazonaws.com",
"eventName": "ListParents",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "10e375a2-d520-489f-99b2-78765f8e0e09",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
}
}
ListPoliciesForTarget
#Description
Lists the policies that are directly attached to the specified target root, organizational unit (OU), or account.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "2f5e38fe-0041-4d47-84e0-8b46bf94bfd1",
"eventSource": "organizations.amazonaws.com",
"eventName": "ListPoliciesForTarget",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "8ddda50c-e0b7-4010-8e5e-14c77e4cd3d7",
"userAgent": "aws-sdk-java/2.20.138 Linux/5.10.245-245.983.amzn2.x86_64 OpenJDK_64-Bit_Server_VM/17.0.13+11-LTS Java/17.0.13 scala/2.13.8 kotlin/1.8.22-release-407(1.8.22) vendor/Amazon.com_Inc. io/sync http/Apache cfg/retry-mode/legacy",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
}
}
ListTargetsForPolicy
#Description
Lists all the roots, organizational units (OUs), and accounts that the specified policy is attached to.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "874fadb5-fc60-498d-abce-10da62a0313b",
"eventSource": "organizations.amazonaws.com",
"eventName": "ListTargetsForPolicy",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": true,
"managementEvent": true,
"requestID": "6e15201e-924a-4c0f-8522-ac1dbe014278",
"userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
}
}
MoveAccount
#Description
Moves an account from its current source parent root or organizational unit (OU) to the specified destination parent root or OU.
CloudTrail management event, logged by default. This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.Example CloudTrail Event #
{
"eventVersion": "1.11",
"eventID": "21346595-f53b-4575-866a-2f367e3e2369",
"eventSource": "organizations.amazonaws.com",
"eventName": "MoveAccount",
"awsRegion": "us-east-1",
"eventType": "AwsApiCall",
"readOnly": false,
"managementEvent": true,
"requestID": "c89a7814-6d6f-49d7-9838-82bf8e7c1a08",
"userAgent": "AWSStepFunctions aws-sdk-java/2.48.1 md/io#async md/http#NettyNio md/internal ua/2.1 api/Organizations#2.46.x os/Linux#4.14.355-284.740.amzn2.x86_64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+12-LTS md/vendor#Amazon.com_Inc. md/en_US md/kotlin/2.3.21-release-298 m/D,AL,e",
"tlsDetails": {
"tlsVersion": "TLSv1.2",
"cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
}
}
PutResourcePolicy
#Description
Creates or updates a resource policy.
RegisterDelegatedAdministrator
#Description
Enables the specified member account to administer the Organizations features of the specified Amazon Web Services service.
CloudTrail management event, logged by default.
TagResource
#Description
Adds one or more tags to the specified resource.
TerminateResponsibilityTransfer
#Description
Ends a transfer.
UntagResource
#Description
Removes any tags with the specified keys from the specified resource.
UpdateOrganizationalUnit
#Description
Renames the specified organizational unit (OU).
UpdatePolicy
#Description
Updates an existing policy with a new name, description, or content.
CloudTrail management event, logged by default.
UpdateResponsibilityTransfer
#Description
Updates a transfer.
AccountJoinedOrganization
#Description
AccountJoinedOrganization recorded by CloudTrail for AWS Organizations. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.11",
"eventID": "f053eeac-4340-4ff3-b7f5-52988c8a0bf8",
"eventSource": "organizations.amazonaws.com",
"eventName": "AccountJoinedOrganization",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"userAgent": "organizations.amazonaws.com"
}
CreateAccountResult
#Description
CreateAccountResult recorded by CloudTrail for AWS Organizations. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.
Example CloudTrail Event #
This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.
{
"eventVersion": "1.08",
"eventID": "bf781092-aba6-4912-9576-76410d177152",
"eventSource": "organizations.amazonaws.com",
"eventName": "CreateAccountResult",
"awsRegion": "us-east-1",
"eventType": "AwsServiceEvent",
"readOnly": false,
"managementEvent": true,
"userAgent": "AWS Internal"
}