AWS Organizations

eventNameDescriptionSampleRule
anyCatch-all entry for AWS Organizations rules that match the service but not a specific eventName.NN
DescribeOrganizationRetrieves information about the organization that the calling account belongs to.YY
DescribeResourcePolicyRetrieves the resource-based policy that is attached to the organization's management account.YY
LeaveOrganizationRemoves the current member account from its parent organization, making it a standalone account.YY
ListAccountsLists all the accounts in the organization.YY
ListAccountsForParentLists the accounts in an organizational unit or the root that is specified as the parent.YY
ListAWSServiceAccessForOrganizationReturns a list of AWS services for which AWS Organizations has enabled integration (trusted access) with the organization.YY
ListDelegatedAdministratorsLists the AWS accounts that are designated as delegated administrators for the specified AWS service in the organization.YY
ListDelegatedServicesForAccountLists the AWS services for which the specified account is a delegated administrator in the organization.YY
ListOrganizationalUnitsForParentLists the organizational units (OUs) in a parent root or OU.YY
ListPoliciesRetrieves the list of all policies in an organization of a specified type.YY
ListRootsLists the roots that are defined in the organization.YY
RemoveAccountFromOrganizationRemoves a member account from its parent organization; can only be called from the management account.NY
AcceptHandshakeAccepts a handshake by sending an ACCEPTED response to the sender.YN
AttachPolicyAttaches a policy to a root, an organizational unit (OU), or an individual account.NN
CancelHandshakeCancels a Handshake.NN
CloseAccountCloses an Amazon Web Services member account within an organization.NY
CreateAccountCreates an Amazon Web Services account that is automatically a member of the organization whose credentials made the request.NN
CreateGovCloudAccountThis action is available if all of the following are true: You're authorized to create accounts in the Amazon Web Services GovCloud (US) Region.NN
CreateOrganizationCreates an Amazon Web Services organization.NN
CreateOrganizationalUnitCreates an organizational unit (OU) within a root or parent OU.NN
CreatePolicyCreates a policy of a specified type that you can attach to a root, an organizational unit (OU), or an individual Amazon Web Services account.NN
DeclineHandshakeDeclines a Handshake.NN
DeleteOrganizationDeletes the organization.YN
DeleteOrganizationalUnitDeletes an organizational unit (OU) from a root or another OU.NN
DeletePolicyDeletes the specified policy from your organization.NN
DeleteResourcePolicyDeletes the resource policy from your organization.YN
DeregisterDelegatedAdministratorRemoves the specified member Amazon Web Services account as a delegated administrator for the specified Amazon Web Services service.NN
DescribeAccountRetrieves Organizations-related information about the specified account.YN
DescribeCreateAccountStatusRetrieves the current status of an asynchronous request to create an account.NN
DescribeEffectivePolicyReturns the contents of the effective policy for specified policy type and account.YN
DescribeHandshakeReturns details for a handshake.NN
DescribeOrganizationalUnitRetrieves information about an organizational unit (OU).NN
DescribePolicyRetrieves information about a policy.YN
DescribeResponsibilityTransferReturns details for a transfer.NN
DetachPolicyDetaches a policy from a target root, organizational unit (OU), or account.NN
DisableAWSServiceAccessDisables the integration of an Amazon Web Services service (the service that is specified by ServicePrincipal) with Organizations.YN
DisablePolicyTypeDisables an organizational policy type in a root.NN
EnableAllFeaturesEnables all features in an organization.NN
EnableAWSServiceAccessProvides an Amazon Web Services service (the service that is specified by ServicePrincipal) with permissions to view the structure of an organization, create a service-linked role in all the accounts in the organization, and allow the servi.NN
EnablePolicyTypeEnables a policy type in a root.NN
InviteAccountToOrganizationSends an invitation to another account to join your organization as a member account.NN
InviteOrganizationToTransferResponsibilitySends an invitation to another organization's management account to designate your account with the specified responsibilities for their organization.NN
ListAccountsWithInvalidEffectivePolicyLists all the accounts in an organization that have invalid effective policies.YN
ListChildrenLists all of the organizational units (OUs) or accounts that are contained in the specified parent OU or root.NN
ListCreateAccountStatusLists the account creation requests that match the specified status that is currently being tracked for the organization.YN
ListEffectivePolicyValidationErrorsLists all the validation errors on an effective policy for a specified account and policy type.NN
ListHandshakesForAccountLists the recent handshakes that you have received.YN
ListHandshakesForOrganizationLists the recent handshakes that you have sent.YN
ListInboundResponsibilityTransfersLists transfers that allow you to manage the specified responsibilities for another organization.YN
ListOutboundResponsibilityTransfersLists transfers that allow an account outside your organization to manage the specified responsibilities for your organization.YN
ListParentsLists the root or organizational units (OUs) that serve as the immediate parent of the specified child OU or account.NN
ListPoliciesForTargetLists the policies that are directly attached to the specified target root, organizational unit (OU), or account.NN
ListTagsForResourceLists tags that are attached to the specified resource.NN
ListTargetsForPolicyLists all the roots, organizational units (OUs), and accounts that the specified policy is attached to.NN
MoveAccountMoves an account from its current source parent root or organizational unit (OU) to the specified destination parent root or OU.NN
PutResourcePolicyCreates or updates a resource policy.NN
RegisterDelegatedAdministratorEnables the specified member account to administer the Organizations features of the specified Amazon Web Services service.NN
TagResourceAdds one or more tags to the specified resource.NN
TerminateResponsibilityTransferEnds a transfer.NN
UntagResourceRemoves any tags with the specified keys from the specified resource.NN
UpdateOrganizationalUnitRenames the specified organizational unit (OU).NN
UpdatePolicyUpdates an existing policy with a new name, description, or content.NN
UpdateResponsibilityTransferUpdates a transfer.NN
AccountJoinedOrganizationAccountJoinedOrganization recorded by CloudTrail for AWS Organizations. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN
CreateAccountResultCreateAccountResult recorded by CloudTrail for AWS Organizations. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.NN

any: AWS Organizations (catch-all)

#
Service
organizations

Description

Catch-all entry for AWS Organizations rules that match the service but not a specific eventName.

DescribeOrganization

#
Service
organizations

Description

Retrieves information about the organization that the calling account belongs to.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "5b5575f9-d4ef-4651-86c1-7618d49689f5",
  "eventName": "DescribeOrganization",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2023-07-10T12:28:21Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "6d37d964-2b01-4b18-ab97-46e3c4abc522",
  "requestParameters": null,
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCS5BLNV76",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

DescribeResourcePolicy

#
Service
organizations

Description

Retrieves the resource-based policy that is attached to the organization's management account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AWSOrganizationsNotInUseException",
  "eventCategory": "Management",
  "eventID": "c23dff9f-55dc-4d22-84c9-87001731f885",
  "eventName": "DescribeResourcePolicy",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2026-06-29T18:32:27Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "de6e0d1c-6af7-4b07-8b3b-c8567021512b",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/D,Z,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

LeaveOrganization

#
Service
organizations

Description

Removes the current member account from its parent organization, making it a standalone account.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:sts::123837392027:assumed-role/stratus-red-team-leave-org-role/aws-go-sdk-1688990515440126480 is not authorized to perform: organizations:LeaveOrganization on resource: * because no identity-based policy allows the organizations:LeaveOrganization action",
  "eventCategory": "Management",
  "eventID": "be7f89b5-d456-4423-b3e6-0fb0b19bad7c",
  "eventName": "LeaveOrganization",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2023-07-10T12:02:05Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123837392027",
  "requestID": "0c762aa3-c5df-4a3b-8a14-5a3b3791ecbd",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "192.168.10.20",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "stratus-red-team_7d2a6913-ded3-49c6-a31c-0cdeebcc259c",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCVW2R4OHT",
    "accountId": "123837392027",
    "arn": "arn:aws:sts::123837392027:assumed-role/stratus-red-team-leave-org-role/aws-go-sdk-1688990515440126480",
    "principalId": "AROATFQR7NSCRI4ZA26CX:aws-go-sdk-1688990515440126480",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:02:04Z",
        "mfaAuthenticated": "false"
      },
      "sessionIssuer": {
        "accountId": "123837392027",
        "arn": "arn:aws:iam::123837392027:role/stratus-red-team-leave-org-role",
        "principalId": "AROATFQR7NSCRI4ZA26CX",
        "type": "Role",
        "userName": "stratus-red-team-leave-org-role"
      },
      "webIdFederationData": {}
    },
    "type": "AssumedRole"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS Attempt to Leave Organization source medium: Detects any attempt, successful or denied, for a member account to leave an AWS Organization via the LeaveOrganization API. Leaving an organization immediately strips the account of every Service Control Policy (SCP) guardrail the organization enforces, removes it from centralized CloudTrail aggregation, and eliminates the management account's ability to audit or control it going forward. An adversary who has gained root or organization-management-capable access in a member account may use this technique to escape organizational security controls and operate unmonitored. Denied attempts are included because a blocked call is just as strong a signal of intent as a successful one, and is often the only trace left when the account's default permissions correctly prevent the action.T1531, T1562, T1562.001

YARA-L #

Panther #

  • AWS CloudTrail Attempt To Leave Org source informational: Detects when an actor attempts to remove an AWS account from an Organization. Security configurations are often defined at the organizational level. Leaving the organization can disrupt or totally shut down these controls.T1562.008, T1666

References #

ListAccounts

#
Service
organizations

Description

Lists all the accounts in the organization.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "CallerValidation check failed",
  "eventCategory": "Management",
  "eventID": "d4b70738-0e10-4017-b2fd-7da076d1af28",
  "eventName": "ListAccounts",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2021-04-13T13:33:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "731544447609",
  "requestID": "a9535fb7-c8ad-4cae-8cf1-3bfd3e71b6e0",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "34.12.134.20",
  "userAgent": "Boto3/1.14.6 Python/3.9.4 Darwin/20.3.0 Botocore/1.17.6",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLIXX7QSZR",
    "accountId": "731544447609",
    "arn": "arn:aws:iam::731544447609:user/cloudmapper",
    "principalId": "AIDAYTOGP2RLK32EB7QZV",
    "type": "IAMUser",
    "userName": "cloudmapper"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

ListAccountsForParent

#
Service
organizations

Description

Lists the accounts in an organizational unit or the root that is specified as the parent.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:59:04Z",
  "eventSource": "organizations.amazonaws.com",
  "eventName": "ListAccountsForParent",
  "awsRegion": "us-east-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/n,Z,E,C,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#organizations.list-accounts-for-parent",
  "errorCode": "AWSOrganizationsNotInUseException",
  "requestParameters": null,
  "responseElements": null,
  "requestID": "1604929e-af00-420a-8db2-7196c9740bbb",
  "eventID": "b0de8cf1-011f-4eb6-84e7-deb9e09b508f",
  "readOnly": true,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

ListAWSServiceAccessForOrganization

#
Service
organizations

Description

Returns a list of AWS services for which AWS Organizations has enabled integration (trusted access) with the organization.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: organizations:ListAWSServiceAccessForOrganization on resource: *",
  "eventID": "db1b9709-d847-4d75-8571-364423f0b97d",
  "eventName": "ListAWSServiceAccessForOrganization",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2019-10-19T23:49:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.05",
  "recipientAccountId": "811596193553",
  "requestID": "865251-856a-4e70-b4ac-d6cb03f26f14",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "213.253.166.5",
  "userAgent": "Boto3/1.9.210 Python/2.7.10 Darwin/18.7.0 Botocore/1.12.210",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

ListDelegatedAdministrators

#
Service
organizations

Description

Lists the AWS accounts that are designated as delegated administrators for the specified AWS service in the organization.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventCategory": "Management",
  "eventID": "3697daff-dcbd-4824-acf9-710362af8afc",
  "eventName": "ListDelegatedAdministrators",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2023-07-10T12:29:18Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123837392027",
  "requestID": "e41016c8-44c3-44ed-8a77-90c2f6b370e7",
  "requestParameters": {
    "servicePrincipal": "cloudtrail.amazonaws.com"
  },
  "responseElements": null,
  "sessionCredentialFromConsole": "true",
  "sourceIPAddress": "10.8.8.10",
  "userAgent": "AWS Internal",
  "userIdentity": {
    "accessKeyId": "ASIATFQR7NSCXRLH2ACF",
    "accountId": "123837392027",
    "arn": "arn:aws:iam::123837392027:user/bert-jan",
    "principalId": "AIDATFQR7NSC5AU2ZV3IE",
    "sessionContext": {
      "attributes": {
        "creationDate": "2023-07-10T12:27:45Z",
        "mfaAuthenticated": "true"
      },
      "sessionIssuer": {},
      "webIdFederationData": {}
    },
    "type": "IAMUser",
    "userName": "bert-jan"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

ListDelegatedServicesForAccount

#
Service
organizations

Description

Lists the AWS services for which the specified account is a delegated administrator in the organization.

Example CloudTrail Event #

{
  "eventVersion": "1.11",
  "userIdentity": {
    "type": "Root",
    "principalId": "123456789012",
    "arn": "arn:aws:iam::123456789012:root",
    "accountId": "123456789012",
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE"
  },
  "eventTime": "2026-07-28T20:59:07Z",
  "eventSource": "organizations.amazonaws.com",
  "eventName": "ListDelegatedServicesForAccount",
  "awsRegion": "us-east-1",
  "sourceIPAddress": "203.0.113.5",
  "userAgent": "aws-cli/2.34.28 md/awscrt#0.31.2 ua/2.1 os/linux#6.1.0-51-amd64 md/arch#x86_64 lang/python#3.14.3 md/pyimpl#CPython m/n,Z,E,C,b cfg/retry-mode#standard md/installer#exe md/distrib#debian.12 md/prompt#off md/command#organizations.list-delegated-services-for-account",
  "errorCode": "AWSOrganizationsNotInUseException",
  "requestParameters": null,
  "responseElements": null,
  "requestID": "020905fb-b784-4636-b82c-0342b006d8ee",
  "eventID": "e31a54c1-40ea-4d24-b033-7f4b43da9887",
  "readOnly": true,
  "eventType": "AwsApiCall",
  "managementEvent": true,
  "recipientAccountId": "123456789012",
  "eventCategory": "Management",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

ListOrganizationalUnitsForParent

#
Service
organizations

Description

Lists the organizational units (OUs) in a parent root or OU.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::123456789012:user/TrailDiscover is not authorized to perform: organizations:ListOrganizationalUnitsForParent on resource: arn:aws:organizations::123456789012:root/o-t7q5oihfb0/r-traildiscover because no resource-based policy allows the organizations:ListOrganizationalUnitsForParent action",
  "eventCategory": "Management",
  "eventID": "68f65a74-1ca7-4654-8e96-17a9c4cba479",
  "eventName": "ListOrganizationalUnitsForParent",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2024-08-18T08:56:45Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.09",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "26b87752-be34-491f-b77a-9388d036665a",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "0.0.0.0",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "aws-cli/2.17.32 md/awscrt#0.21.2 ua/2.0 os/linux#0.0.0.0-microsoft-standard-WSL2 md/arch#x86_64 lang/python#3.11.9 md/pyimpl#CPython exec-env/grimoire_d5090842-6dc5-41cc-841d-519ed768ab5b cfg/retry-mode#standard md/installer#exe md/distrib#ubuntu.24 md/prompt#off md/command#organizations.list-organizational-units-for-parent",
  "userIdentity": {
    "accessKeyId": "AKIA****************",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/TrailDiscover",
    "principalId": "AROA****************:User",
    "type": "IAMUser",
    "userName": "TrailDiscover"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

ListPolicies

#
Service
organizations

Description

Retrieves the list of all policies in an organization of a specified type.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: organizations:ListPolicies on resource: *",
  "eventID": "5548f194-95dc-48db-8c19-285ecfa33877",
  "eventName": "ListPolicies",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2018-11-05T13:01:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "e006ae25-e0fa-11e8-a2b0-70810de9c71f",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "245.70.252.112",
  "userAgent": "aws-cli/1.16.47 Python/2.7.13 Linux/4.17.0-3rodete2-amd64 botocore/1.12.37",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

ListRoots

#
Service
organizations

Description

Lists the roots that are defined in the organization.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: organizations:ListRoots on resource: *",
  "eventID": "4a51237d-9a32-4f71-9916-09b4f9adb6fc",
  "eventName": "ListRoots",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2018-11-05T13:01:46Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "f392a56a-e0fa-11e8-b3c3-af159c59891c",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "245.70.252.112",
  "userAgent": "aws-cli/1.16.47 Python/2.7.13 Linux/4.17.0-3rodete2-amd64 botocore/1.12.37",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

References #

RemoveAccountFromOrganization

#
Service
organizations

Description

Removes a member account from its parent organization; can only be called from the management account.

CloudTrail management event, logged by default.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

YARA-L #

AcceptHandshake

#
Service
organizations

Description

Accepts a handshake by sending an ACCEPTED response to the sender.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "eventID": "b009869-2939-4bab-a57f-306692d4b969",
  "eventName": "AcceptHandshake",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2017-07-17T16:20:57Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "e7e2c503-6b0b-11e7-b691-0f41c764907e",
  "requestParameters": {
    "handshakeId": "h-8d51878f67b07021e14ef1e02fa19a4a"
  },
  "responseElements": {
    "handshake": {
      "action": "INVITE",
      "arn": "arn:aws:organizations::745598359964:handshake/o-57vb65iy55/invite/h-8d51878f67b07021e14ef1e02fa19a4a",
      "expirationTimestamp": "Aug 1, 2017 4:20:26 PM",
      "id": "h-8d51878f67b07021e14ef1e02fa19a4a",
      "parties": [
        {
          "id": "811596193553",
          "type": "ACCOUNT"
        },
        {
          "id": "57vb65iy55",
          "type": "ORGANIZATION"
        }
      ],
      "requestedTimestamp": "Jul 17, 2017 4:20:26 PM",
      "resources": [
        {
          "resources": [
            {
              "type": "MASTER_EMAIL",
              "value": "****"
            },
            {
              "type": "MASTER_NAME",
              "value": "****"
            },
            {
              "type": "ORGANIZATION_FEATURE_SET",
              "value": "ALL"
            }
          ],
          "type": "ORGANIZATION",
          "value": "o-57vb65iy55"
        },
        {
          "type": "EMAIL",
          "value": "****"
        }
      ],
      "state": "ACCEPTED"
    }
  },
  "sharedEventID": "0b89a44a-1969-486e-b58d-a76f1def2d18",
  "sourceIPAddress": "255.253.125.115",
  "userAgent": "AWS Organizations Console, aws-internal/3",
  "userIdentity": {
    "accessKeyId": "ASIAJGRK5PZ30YTNRAT0",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:root",
    "principalId": "811596193553",
    "sessionContext": {
      "attributes": {
        "creationDate": "2017-07-17T16:18:27Z",
        "mfaAuthenticated": "true"
      }
    },
    "type": "Root"
  }
}

References #

AttachPolicy

#
Service
organizations

Description

Attaches a policy to a root, an organizational unit (OU), or an individual account.

CloudTrail management event, logged by default.

CancelHandshake

#
Service
organizations

Description

Cancels a Handshake.

CloseAccount

#
Service
organizations

Description

Closes an Amazon Web Services member account within an organization.

CloudTrail management event, logged by default.

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Elastic #

  • AWS Account Closed source medium: Detects the closure of an AWS account via the CloseAccount API. This can be called either by the account itself (account.amazonaws.com, self-service closure) or by an AWS Organizations management account against one of its member accounts (organizations.amazonaws.com). Account closure triggers a 90-day grace period during which the account is suspended before permanent termination, and is one of the most destructive and disruptive actions available in AWS. It removes access to all resources and data in the account for the duration of the suspension. An adversary with root-level access in a member account, or management-level access to an organization, may close accounts to destroy evidence, disrupt business operations, or eliminate compute and data resources. A malicious insider could use the same action for sabotage.T1485, T1531

CreateAccount

#
Service
organizations

Description

Creates an Amazon Web Services account that is automatically a member of the organization whose credentials made the request.

CloudTrail management event, logged by default.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "89ff413a-e00e-4b1f-b216-67127a3bc3ae",
  "eventSource": "organizations.amazonaws.com",
  "eventName": "CreateAccount",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "3d7e0bf8-aec0-4bd8-9167-0b1bb0bf23ba",
  "userAgent": "AWSStepFunctions aws-sdk-java/2.48.1 md/io#async md/http#NettyNio md/internal ua/2.1 api/Organizations#2.46.x os/Linux#4.14.355-284.740.amzn2.x86_64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+12-LTS md/vendor#Amazon.com_Inc. md/en_US md/kotlin/2.3.21-release-298 m/D,AL,e",
  "tlsDetails": {
    "tlsVersion": "TLSv1.2",
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
  }
}

CreateGovCloudAccount

#
Service
organizations

Description

This action is available if all of the following are true: You're authorized to create accounts in the Amazon Web Services GovCloud (US) Region.

CreateOrganization

#
Service
organizations

Description

Creates an Amazon Web Services organization.

CreateOrganizationalUnit

#
Service
organizations

Description

Creates an organizational unit (OU) within a root or parent OU.

CreatePolicy

#
Service
organizations

Description

Creates a policy of a specified type that you can attach to a root, an organizational unit (OU), or an individual Amazon Web Services account.

CloudTrail management event, logged by default.

DeclineHandshake

#
Service
organizations

Description

Declines a Handshake.

DeleteOrganization

#
Service
organizations

Description

Deletes the organization.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AWSOrganizationsNotInUseException",
  "eventCategory": "Management",
  "eventID": "312bd1c1-2869-4e61-88dc-8297d1e51f89",
  "eventName": "DeleteOrganization",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2026-06-29T19:45:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "c51385d2-f3f5-42f7-9044-e6ea713a854a",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeleteOrganizationalUnit

#
Service
organizations

Description

Deletes an organizational unit (OU) from a root or another OU.

DeletePolicy

#
Service
organizations

Description

Deletes the specified policy from your organization.

CloudTrail management event, logged by default.

DeleteResourcePolicy

#
Service
organizations

Description

Deletes the resource policy from your organization.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AWSOrganizationsNotInUseException",
  "eventCategory": "Management",
  "eventID": "a24dbc61-4bd3-4070-a147-cbc7ad91c5c6",
  "eventName": "DeleteResourcePolicy",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2026-06-29T19:45:31Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "ee6c21cc-0116-4778-906f-7e9209b70bf1",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/b,Z,D cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DeregisterDelegatedAdministrator

#
Service
organizations

Description

Removes the specified member Amazon Web Services account as a delegated administrator for the specified Amazon Web Services service.

CloudTrail management event, logged by default.

DescribeAccount

#
Service
organizations

Description

Retrieves Organizations-related information about the specified account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: organizations:DescribeAccount on resource: arn:aws:organizations::745598359964:account/o-57vb65iy55/811596193553",
  "eventID": "e06ee5d5-ab5d-4ae2-a580-64cdc341e3cd",
  "eventName": "DescribeAccount",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2017-11-05T00:15:01Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "5dbbdf94-c1be-11e7-9b01-67c4270b379a",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "1.198.254.60",
  "userAgent": "Boto3/1.4.7 Python/2.7.13 Darwin/16.7.0 Botocore/1.7.38",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

DescribeCreateAccountStatus

#
Service
organizations

Description

Retrieves the current status of an asynchronous request to create an account.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "0f2a1a05-62b7-45ee-8dbf-929166b83057",
  "eventSource": "organizations.amazonaws.com",
  "eventName": "DescribeCreateAccountStatus",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "efd70aa1-e74b-4b37-938c-160afffd9fb2",
  "userAgent": "AWSStepFunctions aws-sdk-java/2.48.1 md/io#async md/http#NettyNio md/internal ua/2.1 api/Organizations#2.46.x os/Linux#4.14.355-284.740.amzn2.x86_64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+12-LTS md/vendor#Amazon.com_Inc. md/en_US md/kotlin/2.3.21-release-298 m/D,AL,e",
  "tlsDetails": {
    "tlsVersion": "TLSv1.2",
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
  }
}

DescribeEffectivePolicy

#
Service
organizations

Description

Returns the contents of the effective policy for specified policy type and account.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AWSOrganizationsNotInUseException",
  "eventCategory": "Management",
  "eventID": "b5e95761-64c5-44d8-bb68-bbd8e9fce322",
  "eventName": "DescribeEffectivePolicy",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2026-06-29T18:45:14Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "1cf7c24f-4e0e-4632-b48b-f137a543ccda",
  "requestParameters": {
    "policyType": "TAG_POLICY"
  },
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DescribeHandshake

#
Service
organizations

Description

Returns details for a handshake.

DescribeOrganizationalUnit

#
Service
organizations

Description

Retrieves information about an organizational unit (OU).

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "3d528730-d493-3202-a890-19a558fe1356",
  "eventSource": "organizations.amazonaws.com",
  "eventName": "DescribeOrganizationalUnit",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "dbba6cf9-9d71-48d0-ae90-24876717c6b6",
  "userAgent": "aws-sdk-dotnet-coreclr/4.0.11.13 ua/2.1 os/linux#6.1.176.221 md/ARCH#Arm64 lang/.NET_Core#10.0.10 exec-env/AWS_ECS_EC2 md/aws-sdk-dotnet-core#4.0.100.3 api/Organizations#4.0.11.13 md/ClientAsync cfg/init-coll#0 m/b,P,i,E",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
  }
}

DescribePolicy

#
Service
organizations

Description

Retrieves information about a policy.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/Level6 is not authorized to perform: organizations:DescribePolicy on resource: arn:aws:organizations::745598359964:policy/o-57vb65iy55/UNKNOWN/p-ANPA1WYEAOB5NS7A9TAEB",
  "eventID": "22a959ed-752d-4ffa-bdb9-141d3f394058",
  "eventName": "DescribePolicy",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2018-04-23T10:04:52Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "c39b1f1d-46dd-11e8-a21d-e4bb5f858199",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "150.5.17.8",
  "userAgent": "aws-cli/1.11.139 Python/3.6.3 Linux/4.13.0-38-generic botocore/1.6.6",
  "userIdentity": {
    "accessKeyId": "AKIA3Z2XBVUDFQ9TU4MD",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/Level6",
    "principalId": "AIDADO2GQD0K8TEF7KW1V",
    "type": "IAMUser",
    "userName": "Level6"
  }
}

References #

DescribeResponsibilityTransfer

#
Service
organizations

Description

Returns details for a transfer.

DetachPolicy

#
Service
organizations

Description

Detaches a policy from a target root, organizational unit (OU), or account.

CloudTrail management event, logged by default.

DisableAWSServiceAccess

#
Service
organizations

Description

Disables the integration of an Amazon Web Services service (the service that is specified by ServicePrincipal) with Organizations.

CloudTrail management event, logged by default.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AWSOrganizationsNotInUseException",
  "eventCategory": "Management",
  "eventID": "35671b01-5a15-4fd2-bcd7-a4756a239504",
  "eventName": "DisableAWSServiceAccess",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2026-06-29T19:24:54Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": false,
  "recipientAccountId": "123456789012",
  "requestID": "54c21fe6-e168-4503-bfb1-10229647ee31",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

DisablePolicyType

#
Service
organizations

Description

Disables an organizational policy type in a root.

CloudTrail management event, logged by default.

EnableAllFeatures

#
Service
organizations

Description

Enables all features in an organization.

EnableAWSServiceAccess

#
Service
organizations

Description

Provides an Amazon Web Services service (the service that is specified by ServicePrincipal) with permissions to view the structure of an organization, create a service-linked role in all the accounts in the organization, and allow the servi.

CloudTrail management event, logged by default.

EnablePolicyType

#
Service
organizations

Description

Enables a policy type in a root.

InviteAccountToOrganization

#
Service
organizations

Description

Sends an invitation to another account to join your organization as a member account.

CloudTrail management event, logged by default.

InviteOrganizationToTransferResponsibility

#
Service
organizations

Description

Sends an invitation to another organization's management account to designate your account with the specified responsibilities for their organization.

ListAccountsWithInvalidEffectivePolicy

#
Service
organizations

Description

Lists all the accounts in an organization that have invalid effective policies.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AWSOrganizationsNotInUseException",
  "eventCategory": "Management",
  "eventID": "a31a8340-b788-4e5b-948e-eeb72067043b",
  "eventName": "ListAccountsWithInvalidEffectivePolicy",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2026-06-29T18:45:15Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "27f91d6c-f771-471f-b665-4e9a28a5ccd6",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListChildren

#
Service
organizations

Description

Lists all of the organizational units (OUs) or accounts that are contained in the specified parent OU or root.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "1555a106-eaf6-3602-83ba-2d5917a64949",
  "eventSource": "organizations.amazonaws.com",
  "eventName": "ListChildren",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "bd1c2267-8d36-4116-b29c-f5fcdf51502c",
  "userAgent": "aws-sdk-dotnet-coreclr/4.0.11.13 ua/2.1 os/linux#6.1.176.221 md/ARCH#Arm64 lang/.NET_Core#10.0.10 exec-env/AWS_ECS_EC2 md/aws-sdk-dotnet-core#4.0.100.3 api/Organizations#4.0.11.13 md/ClientAsync cfg/init-coll#0 m/b,P,i,E,C",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
  }
}

ListCreateAccountStatus

#
Service
organizations

Description

Lists the account creation requests that match the specified status that is currently being tracked for the organization.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: organizations:ListCreateAccountStatus on resource: *",
  "eventID": "cf99cec0-8664-4883-b003-6b902e4008c6",
  "eventName": "ListCreateAccountStatus",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2018-11-24T19:59:33Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "219642d-f023-11e8-9496-c9c363f4b14a",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "16.12.99.2",
  "userAgent": "Boto3/1.7.4 Python/3.6.5 Linux/4.15.0-39-generic Botocore/1.10.4",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ListEffectivePolicyValidationErrors

#
Service
organizations

Description

Lists all the validation errors on an effective policy for a specified account and policy type.

ListHandshakesForAccount

#
Service
organizations

Description

Lists the recent handshakes that you have received.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::731544447609:user/cloudsploit is not authorized to perform: organizations:ListHandshakesForAccount on resource: *",
  "eventCategory": "Management",
  "eventID": "874d11ce-f4a7-4589-96c1-1beb8a701c10",
  "eventName": "ListHandshakesForAccount",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2021-04-13T11:35:25Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.08",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "731544447609",
  "requestID": "a71481fe-248d-48b0-b233-a51dc40ffeb2",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "34.12.134.20",
  "userAgent": "aws-sdk-nodejs/2.885.0 linux/v14.16.1 callback",
  "userIdentity": {
    "accessKeyId": "AKIAYTOGP2RLGBSBSMH2",
    "accountId": "731544447609",
    "arn": "arn:aws:iam::731544447609:user/cloudsploit",
    "principalId": "AIDAYTOGP2RLMDEPWZWMJ",
    "type": "IAMUser",
    "userName": "cloudsploit"
  }
}

References #

ListHandshakesForOrganization

#
Service
organizations

Description

Lists the recent handshakes that you have sent.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AccessDenied",
  "errorMessage": "User: arn:aws:iam::811596193553:user/backup is not authorized to perform: organizations:ListHandshakesForOrganization on resource: *",
  "eventID": "7dea0e61-25ed-4b44-a057-71b22b8ddf21",
  "eventName": "ListHandshakesForOrganization",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2018-11-24T19:59:35Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.04",
  "recipientAccountId": "811596193553",
  "requestID": "777be53e-f023-11e8-ad23-455b670e6960",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "16.12.99.2",
  "userAgent": "Boto3/1.7.4 Python/3.6.5 Linux/4.15.0-39-generic Botocore/1.10.4",
  "userIdentity": {
    "accessKeyId": "AKIA01U43UX3RBRDXF4Q",
    "accountId": "811596193553",
    "arn": "arn:aws:iam::811596193553:user/backup",
    "principalId": "AIDA9BO36HFBHKGJAO9C1",
    "type": "IAMUser",
    "userName": "backup"
  }
}

References #

ListInboundResponsibilityTransfers

#
Service
organizations

Description

Lists transfers that allow you to manage the specified responsibilities for another organization.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AWSOrganizationsNotInUseException",
  "eventCategory": "Management",
  "eventID": "9a252037-ab81-4b5f-ab80-e1787cb2179f",
  "eventName": "ListInboundResponsibilityTransfers",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2026-06-29T18:45:17Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "dd81b648-4b4d-4002-bb99-365e8c779e5f",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListOutboundResponsibilityTransfers

#
Service
organizations

Description

Lists transfers that allow an account outside your organization to manage the specified responsibilities for your organization.

Example CloudTrail Event #

{
  "awsRegion": "us-east-1",
  "errorCode": "AWSOrganizationsNotInUseException",
  "eventCategory": "Management",
  "eventID": "1e163614-773e-4b8b-b4ff-1a9a1a990d6b",
  "eventName": "ListOutboundResponsibilityTransfers",
  "eventSource": "organizations.amazonaws.com",
  "eventTime": "2026-06-29T18:45:17Z",
  "eventType": "AwsApiCall",
  "eventVersion": "1.11",
  "managementEvent": true,
  "readOnly": true,
  "recipientAccountId": "123456789012",
  "requestID": "50e47b0e-0ed6-4879-bb75-db462b6d74d7",
  "requestParameters": null,
  "responseElements": null,
  "sourceIPAddress": "203.0.113.5",
  "tlsDetails": {
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com",
    "tlsVersion": "TLSv1.3"
  },
  "userAgent": "Boto3/1.43.36 md/Botocore#1.43.36 ua/2.1 os/linux#6.1.0-41-amd64 md/arch#x86_64 lang/python#3.11.2 md/pyimpl#CPython m/Z,D,b cfg/retry-mode#legacy Botocore/1.43.36",
  "userIdentity": {
    "accessKeyId": "AKIAIOSFODNN7EXAMPLE",
    "accountId": "123456789012",
    "arn": "arn:aws:iam::123456789012:user/sample-user",
    "principalId": "AIDAEXAMPLE00000000",
    "type": "IAMUser",
    "userName": "sample-user"
  }
}

ListParents

#
Service
organizations

Description

Lists the root or organizational units (OUs) that serve as the immediate parent of the specified child OU or account.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "a8c9e384-f10e-43bd-91fd-d9ca4a3e4bd4",
  "eventSource": "organizations.amazonaws.com",
  "eventName": "ListParents",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "10e375a2-d520-489f-99b2-78765f8e0e09",
  "userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
  }
}

ListPoliciesForTarget

#
Service
organizations

Description

Lists the policies that are directly attached to the specified target root, organizational unit (OU), or account.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "2f5e38fe-0041-4d47-84e0-8b46bf94bfd1",
  "eventSource": "organizations.amazonaws.com",
  "eventName": "ListPoliciesForTarget",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "8ddda50c-e0b7-4010-8e5e-14c77e4cd3d7",
  "userAgent": "aws-sdk-java/2.20.138 Linux/5.10.245-245.983.amzn2.x86_64 OpenJDK_64-Bit_Server_VM/17.0.13+11-LTS Java/17.0.13 scala/2.13.8 kotlin/1.8.22-release-407(1.8.22) vendor/Amazon.com_Inc. io/sync http/Apache cfg/retry-mode/legacy",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
  }
}

ListTagsForResource

#
Service
organizations

Description

Lists tags that are attached to the specified resource.

ListTargetsForPolicy

#
Service
organizations

Description

Lists all the roots, organizational units (OUs), and accounts that the specified policy is attached to.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "874fadb5-fc60-498d-abce-10da62a0313b",
  "eventSource": "organizations.amazonaws.com",
  "eventName": "ListTargetsForPolicy",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": true,
  "managementEvent": true,
  "requestID": "6e15201e-924a-4c0f-8522-ac1dbe014278",
  "userAgent": "Botocore/1.35.95 ua/2.0 os/linux#5.10.245-245.983.amzn2.x86_64 md/arch#x86_64 lang/python#3.9.23 md/pyimpl#CPython cfg/retry-mode#standard",
  "tlsDetails": {
    "tlsVersion": "TLSv1.3",
    "cipherSuite": "TLS_AES_128_GCM_SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
  }
}

MoveAccount

#
Service
organizations

Description

Moves an account from its current source parent root or organizational unit (OU) to the specified destination parent root or OU.

CloudTrail management event, logged by default.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "21346595-f53b-4575-866a-2f367e3e2369",
  "eventSource": "organizations.amazonaws.com",
  "eventName": "MoveAccount",
  "awsRegion": "us-east-1",
  "eventType": "AwsApiCall",
  "readOnly": false,
  "managementEvent": true,
  "requestID": "c89a7814-6d6f-49d7-9838-82bf8e7c1a08",
  "userAgent": "AWSStepFunctions aws-sdk-java/2.48.1 md/io#async md/http#NettyNio md/internal ua/2.1 api/Organizations#2.46.x os/Linux#4.14.355-284.740.amzn2.x86_64 lang/java#21.0.11 md/OpenJDK_64-Bit_Server_VM#21.0.11+12-LTS md/vendor#Amazon.com_Inc. md/en_US md/kotlin/2.3.21-release-298 m/D,AL,e",
  "tlsDetails": {
    "tlsVersion": "TLSv1.2",
    "cipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
    "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
  }
}

PutResourcePolicy

#
Service
organizations

Description

Creates or updates a resource policy.

RegisterDelegatedAdministrator

#
Service
organizations

Description

Enables the specified member account to administer the Organizations features of the specified Amazon Web Services service.

CloudTrail management event, logged by default.

TagResource

#
Service
organizations

Description

Adds one or more tags to the specified resource.

TerminateResponsibilityTransfer

#
Service
organizations

Description

Ends a transfer.

UntagResource

#
Service
organizations

Description

Removes any tags with the specified keys from the specified resource.

UpdateOrganizationalUnit

#
Service
organizations

Description

Renames the specified organizational unit (OU).

UpdatePolicy

#
Service
organizations

Description

Updates an existing policy with a new name, description, or content.

CloudTrail management event, logged by default.

UpdateResponsibilityTransfer

#
Service
organizations

Description

Updates a transfer.

AccountJoinedOrganization

#
Service
organizations

Description

AccountJoinedOrganization recorded by CloudTrail for AWS Organizations. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.11",
  "eventID": "f053eeac-4340-4ff3-b7f5-52988c8a0bf8",
  "eventSource": "organizations.amazonaws.com",
  "eventName": "AccountJoinedOrganization",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "userAgent": "organizations.amazonaws.com"
}

CreateAccountResult

#
Service
organizations

Description

CreateAccountResult recorded by CloudTrail for AWS Organizations. Observed in real CloudTrail; no AWS SDK operation model documents it, so no description is available from the SDK.

Example CloudTrail Event #

This is a projected export row, not a complete CloudTrail record: it shows only the envelope columns a SIEM export retained. The export never carried userIdentity, requestParameters, responseElements, sourceIPAddress, recipientAccountId, eventCategory, so their absence here says nothing about the real event. Account identifiers, ARNs and endpoint hostnames in eventID, requestID, resources, tlsDetails, userAgent are replaced with the placeholders AWS uses in its own documentation, so those values are structurally real but not the originals. errorMessage is withheld: it is free-form prose that names customer resources, which no substitution rule can find reliably. eventTime is withheld because the export renders it in the exporting system's local timezone rather than the UTC a CloudTrail record carries.

{
  "eventVersion": "1.08",
  "eventID": "bf781092-aba6-4912-9576-76410d177152",
  "eventSource": "organizations.amazonaws.com",
  "eventName": "CreateAccountResult",
  "awsRegion": "us-east-1",
  "eventType": "AwsServiceEvent",
  "readOnly": false,
  "managementEvent": true,
  "userAgent": "AWS Internal"
}