Skip to content

CreateIPSet

AWS

CreateIPSet

service: AWS - GuardDuty
techniques:

Event

CreateIPSet creates a trusted IP list for a GuardDuty detector using a file in S3. It is distinct from a threat IP list. activate: true requests use of the list; the creation response alone does not prove it has reached ACTIVE status.

Security Context

An unauthorized trusted list can reduce detection coverage for attacker-controlled addresses. Approved lists for trusted infrastructure can produce the same operation. T1685 applies when this configuration is used to impair defensive coverage.

Trusted IP lists apply to CloudTrail and VPC Flow Logs findings, not Route 53 Resolver DNS findings, and are limited to publicly routable IPv4 addresses. They are not a universal bypass of every GuardDuty protection feature. In multi-account environments, administrator-managed lists apply to member accounts as well.

Log Source

CloudTrail management event with eventSource: guardduty.amazonaws.com and eventName: CreateIPSet. This record identifies the list’s location, not its contents. Investigating the referenced S3 object requires separate evidence; object-level access logs depend on the collection configured for that bucket.

Key Fields

FieldInvestigation use
requestParameters.detectorId, awsRegionIdentify the regional detector.
requestParameters.location, requestParameters.formatLocate and interpret the referenced list file.
requestParameters.activateRequested activation, not completed activation.
responseElements.ipSetIdPivot to GetIPSet for status and configuration.
userIdentity, recipientAccountId, eventTimeAttribute creation and determine account scope.
errorCode, errorMessageIdentify a rejected request before investigating activation.

What to Investigate

  1. Confirm approval, caller permissions, and administrator/member relationships. Inspect request errors and the returned list ID.
  2. Use GetIPSet to verify status. ACTIVATING or ERROR is not ACTIVE; account for propagation before assigning a coverage interval.
  3. Preserve the S3 object version relevant to activation, where available. Review actual entries, ownership, and change history rather than inferring contents from its name or the caller’s IP.
  4. Correlate with UpdateIPSet and CreateFilter. Identify affected accounts and confirm the final approved list and status after remediation.

Sample Event

Synthetic impairment scenario. Draco requests creation and activation of a fictional trusted list. Its contents and successful activation are not shown. 203.0.113.66 is a documentation-only caller address, not a demonstrated effective trusted-list entry. The S3 location is illustrative, and exact CloudTrail serialization remains unverified by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T23:09:51Z",
"eventSource": "guardduty.amazonaws.com",
"eventName": "CreateIPSet",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"detectorId": "60000000000040008000001010011010",
"name": "trusted-internal-scanners",
"format": "TXT",
"location": "https://s3.amazonaws.com/example-guardduty-lists/trusted-ips.txt",
"activate": true
},
"responseElements": {
"ipSetId": "60000000000040008000001010011011"
},
"requestID": "90000000-0000-4000-8000-000010001100",
"eventID": "90000000-0000-4000-8000-000010001101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "guardduty.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.