CreateFilter
CreateFilter
Event
CreateFilter creates a filter for a regional GuardDuty detector. The action defaults to NOOP; ARCHIVE creates a suppression rule that automatically archives new matching findings. Creating a saved filter does not by itself establish suppression.
Security Context
An unauthorized archive rule can impair alert handling. Approved tuning for known benign activity is also common. T1685 applies when the filter is used to weaken defensive workflows; inspect its action and criteria before making that assessment.
Suppression rules still allow matching findings to be generated and retained as archived findings for 90 days. Those suppressed findings are not sent to Security Hub CSPM, S3, Detective, or EventBridge. They are also excluded as signals for Extended Threat Detection attack sequences. This differs from manually archiving findings.
Log Source
CloudTrail management event with eventSource: guardduty.amazonaws.com and eventName: CreateFilter. Review management-event collection for the affected account and Region, independently of the finding-delivery integrations the rule may affect.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.detectorId, awsRegion | Scope the filter. |
requestParameters.name, responseElements.name | Identify the created filter, when returned. |
requestParameters.action | Distinguish ARCHIVE from NOOP. |
requestParameters.findingCriteria | Determine exactly which finding fields and values match. |
userIdentity, eventTime, sourceIPAddress | Attribute and correlate creation. |
errorCode, errorMessage | Check whether the request was rejected. |
What to Investigate
- Confirm approval and inspect errors. Retrieve the stored filter with
GetFilterto verify its current action and criteria. - Compare the rule with real finding schemas. An AWS API caller-IP criterion does not match every finding that mentions the same IP in another field.
- Review matching archived findings and downstream gaps. In multi-account environments, check the administrator’s suppression rules and affected member findings.
- Correlate with ArchiveFindings and UpdateDetector. Review later filter changes or deletion and handle any suppressed incidents through the response process.
Sample Event
Synthetic impairment scenario. Draco requests an ARCHIVE filter matching the AWS API caller-IP field service.action.awsApiCallAction.remoteIpDetails.ipAddressV4. The example IP represents a fictional source. The rule does not match all possible uses of that IP across finding types. The returned name illustrates creation; exact CloudTrail serialization has not been validated by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T22:31:09Z", "eventSource": "guardduty.amazonaws.com", "eventName": "CreateFilter", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "detectorId": "60000000000040008000001010011010", "name": "incident-response-noise-filter", "description": "Auto-archive findings tied to internal network testing.", "action": "ARCHIVE", "rank": 1, "findingCriteria": { "criterion": { "service.action.awsApiCallAction.remoteIpDetails.ipAddressV4": { "equals": [ "203.0.113.66" ] } } } }, "responseElements": { "name": "incident-response-noise-filter" }, "requestID": "90000000-0000-4000-8000-000010000110", "eventID": "90000000-0000-4000-8000-000010000111", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "guardduty.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...