DisassociateFromMasterAccount
DisassociateFromMasterAccount
Event
This deprecated API disassociates the calling GuardDuty member account from its administrator. The current API is DisassociateFromAdministratorAccount. Preserve the legacy event name when searching historical logs and include the current name in detection coverage.
Security Context
Unauthorized departure can disrupt central oversight, while approved administrator migration can be legitimate. Member-initiated disassociation applies to invitation-based relationships; Organizations-managed members cannot use that workflow. Disassociation is not detector deletion.
The T1685 mapping applies to deliberate defensive impairment; the API name alone does not establish malicious intent.
Log Source
CloudTrail management event with eventSource: guardduty.amazonaws.com and eventName: DisassociateFromMasterAccount. Search regional Event history or your retained management-event collection; collection scope and retention determine the available evidence.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.detectorId | The calling member’s detector. |
eventName | Distinguish the legacy and current operation names. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the request and correlate with approved work. |
awsRegion, recipientAccountId | Scope the affected environment. |
errorCode, errorMessage | Check rejection before inferring a completed change; null responseElements alone is not proof of success. |
What to Investigate
- Identify the member account, Region, and previous administrator from retained relationship records; the request does not name the administrator.
- Check whether the relationship was invitation-based or Organizations-managed and inspect rejection errors.
- Confirm the relationship changed and separately verify detector status and local finding access.
- Correlate with DisassociateMembers and DeleteDetector; restore approved oversight and review the gap.
Sample Event
Synthetic impairment scenario. Draco invokes the legacy API from an assumed invitation-managed member account. The administrator’s identity and successful relationship change require separate evidence; the sample does not establish an Organizations departure. No top-level error is shown. Exact CloudTrail serialization and optional fields have not been validated by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T20:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:38:55Z", "eventSource": "guardduty.amazonaws.com", "eventName": "DisassociateFromMasterAccount", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "detectorId": "0123456789abcdef0123456789abcdef" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000100110010", "eventID": "90000000-0000-4000-8000-000100110011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "guardduty.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...