Skip to content

ArchiveFindings

AWS

ArchiveFindings

service: AWS - GuardDuty
techniques:

Event

ArchiveFindings marks the specified findings as archived. It changes finding status; it does not delete the detector or create a rule to suppress future matching findings.

Security Context

Unauthorized archiving can remove findings from an active triage queue. Legitimate incident closure and false-positive handling also use this operation. T1685 applies to deliberate impairment of defensive workflows, not every archive request.

Archived findings remain available for review. Manual archiving does not have the same delivery behavior as a suppression rule: EventBridge still receives notifications for manually archived findings and their subsequent occurrences. Do not assume that a SIEM has lost previously ingested evidence.

Log Source

CloudTrail management event with eventSource: guardduty.amazonaws.com and eventName: ArchiveFindings. Search the relevant account and Region in Event history or retained management-event logs. The API audit record is separate from the findings it references.

Key Fields

FieldInvestigation use
requestParameters.detectorId, awsRegionIdentify the regional detector.
requestParameters.findingIdsRetrieve the actual findings; IDs alone do not reveal their types or severity.
userIdentity, recipientAccountIdIdentify the caller and account; check administrator/member relationships.
eventTime, sourceIPAddress, userAgentCorrelate with triage records and other activity.
errorCode, errorMessageIdentify rejected requests before assessing impact.

What to Investigate

  1. Match the request to an approved case or automation run. In a multi-account setup, member accounts cannot archive their own findings; check the administrator context.
  2. Retrieve each referenced finding and verify its archived status, affected resources, severity, and incident history.
  3. Compare downstream notifications and retained copies with the SOC’s actual queue filters. Establish whether archiving changed analyst visibility.
  4. Correlate with CreateFilter to distinguish a one-time action from continuing suppression. Restore inappropriate archive decisions through the approved response process.

Sample Event

Synthetic impairment scenario. Draco requests archiving three fictional findings. Their types, connection to Draco’s activity, and effect on a SOC queue are not encoded in this request. No error fields are shown; exact CloudTrail serialization and optional identity fields remain unverified by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:14:52Z",
"eventSource": "guardduty.amazonaws.com",
"eventName": "ArchiveFindings",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"detectorId": "60000000000040008000001010011010",
"findingIds": [
"fa0b00f1ca5cade666ec0badad0badad0",
"fa0b00f1ca5cade666ec0badad0badad1",
"fa0b00f1ca5cade666ec0badad0badad2"
]
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000001101010",
"eventID": "90000000-0000-4000-8000-000001101011",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "guardduty.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.