Threat Actors Leverage Cloud Logs to Bypass Defender Visibility
ID: 324be8c4-dd58-5066-b3d9-af80ae3b3518
STIX ID: report--324be8c4-dd58-5066-b3d9-af80ae3b3518
Feed Name: Cyber Press
Unit 42 research warns that sophisticated attackers are actively exploiting cloud logging services (AWS CloudTrail and Google Cloud Logging) to blind defenders or to gain persistent, covert visibility. The report details methods including stopping logging, deleting log storage or routers, creating/using external KMS keys to make logs unreadable, poisoning stored log files, and redirecting or duplicating logs to attacker-controlled buckets. These techniques can disable SIEM/SOAR ingestion, wipe forensic evidence, or provide real-time intelligence to adversaries; recommended mitigations include restricting logging modification permissions, enabling CloudTrail integrity validation, locking Google log buckets, and alerting on trail/sink creation or updates.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
