Skip to content

Commit c9e7ae3

Browse files
Update aws.defense-evasion.dns-delete-logs.md with current CloudTrail event name (#515)
* Update aws.defense-evasion.dns-delete-logs.md Corrected the AWS CloudTrail Event name for detection * autogen docs --------- Co-authored-by: Christophe Tafani-Dereeper <[email protected]>
1 parent ce6c296 commit c9e7ae3

File tree

2 files changed

+4
-4
lines changed

2 files changed

+4
-4
lines changed

docs/attack-techniques/AWS/aws.defense-evasion.dns-delete-logs.md

+2-2
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ Deletes a Route53 DNS Resolver query logging configuration. Simulates an attacke
2525

2626
<span style="font-variant: small-caps;">Detonation</span>:
2727

28-
- Delete the DNS logging configuration using <code>route53:DeleteQueryLoggingConfig</code>.
28+
- Delete the DNS logging configuration using <code>route53:DeleteResolverQueryLogConfig</code>.
2929

3030
## Instructions
3131

@@ -35,6 +35,6 @@ stratus detonate aws.defense-evasion.dns-delete-logs
3535
## Detection
3636

3737

38-
Identify when a DNS logging configuration is deleted, through CloudTrail's <code>DeleteQueryLoggingConfig</code> event.
38+
Identify when a DNS logging configuration is deleted, through CloudTrail's <code>DeleteResolverQueryLogConfig</code> event.
3939

4040

v2/internal/attacktechniques/aws/defense-evasion/dns-delete-logs/main.go

+2-2
Original file line numberDiff line numberDiff line change
@@ -29,9 +29,9 @@ Warm-up:
2929
3030
Detonation:
3131
32-
- Delete the DNS logging configuration using <code>route53:DeleteQueryLoggingConfig</code>.`,
32+
- Delete the DNS logging configuration using <code>route53:DeleteResolverQueryLogConfig</code>.`,
3333
Detection: `
34-
Identify when a DNS logging configuration is deleted, through CloudTrail's <code>DeleteQueryLoggingConfig</code> event.
34+
Identify when a DNS logging configuration is deleted, through CloudTrail's <code>DeleteResolverQueryLogConfig</code> event.
3535
`,
3636
IsIdempotent: false, // can't delete a DNS logging configuration twice
3737
PrerequisitesTerraformCode: tf,

0 commit comments

Comments
 (0)