Skip to content

CreateFilter

AWS

CreateFilter

service: AWS - GuardDuty
techniques:

Event

CreateFilter creates a filter for a regional GuardDuty detector. The action defaults to NOOP; ARCHIVE creates a suppression rule that automatically archives new matching findings. Creating a saved filter does not by itself establish suppression.

Security Context

An unauthorized archive rule can impair alert handling. Approved tuning for known benign activity is also common. T1685 applies when the filter is used to weaken defensive workflows; inspect its action and criteria before making that assessment.

Suppression rules still allow matching findings to be generated and retained as archived findings for 90 days. Those suppressed findings are not sent to Security Hub CSPM, S3, Detective, or EventBridge. They are also excluded as signals for Extended Threat Detection attack sequences. This differs from manually archiving findings.

Log Source

CloudTrail management event with eventSource: guardduty.amazonaws.com and eventName: CreateFilter. Review management-event collection for the affected account and Region, independently of the finding-delivery integrations the rule may affect.

Key Fields

FieldInvestigation use
requestParameters.detectorId, awsRegionScope the filter.
requestParameters.name, responseElements.nameIdentify the created filter, when returned.
requestParameters.actionDistinguish ARCHIVE from NOOP.
requestParameters.findingCriteriaDetermine exactly which finding fields and values match.
userIdentity, eventTime, sourceIPAddressAttribute and correlate creation.
errorCode, errorMessageCheck whether the request was rejected.

What to Investigate

  1. Confirm approval and inspect errors. Retrieve the stored filter with GetFilter to verify its current action and criteria.
  2. Compare the rule with real finding schemas. An AWS API caller-IP criterion does not match every finding that mentions the same IP in another field.
  3. Review matching archived findings and downstream gaps. In multi-account environments, check the administrator’s suppression rules and affected member findings.
  4. Correlate with ArchiveFindings and UpdateDetector. Review later filter changes or deletion and handle any suppressed incidents through the response process.

Sample Event

Synthetic impairment scenario. Draco requests an ARCHIVE filter matching the AWS API caller-IP field service.action.awsApiCallAction.remoteIpDetails.ipAddressV4. The example IP represents a fictional source. The rule does not match all possible uses of that IP across finding types. The returned name illustrates creation; exact CloudTrail serialization has not been validated by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T22:31:09Z",
"eventSource": "guardduty.amazonaws.com",
"eventName": "CreateFilter",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"detectorId": "60000000000040008000001010011010",
"name": "incident-response-noise-filter",
"description": "Auto-archive findings tied to internal network testing.",
"action": "ARCHIVE",
"rank": 1,
"findingCriteria": {
"criterion": {
"service.action.awsApiCallAction.remoteIpDetails.ipAddressV4": {
"equals": [
"203.0.113.66"
]
}
}
}
},
"responseElements": {
"name": "incident-response-noise-filter"
},
"requestID": "90000000-0000-4000-8000-000010000110",
"eventID": "90000000-0000-4000-8000-000010000111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "guardduty.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.