Skip to content

DisassociateFromMasterAccount

AWS

DisassociateFromMasterAccount

service: AWS - GuardDuty
techniques:

Event

This deprecated API disassociates the calling GuardDuty member account from its administrator. The current API is DisassociateFromAdministratorAccount. Preserve the legacy event name when searching historical logs and include the current name in detection coverage.

Security Context

Unauthorized departure can disrupt central oversight, while approved administrator migration can be legitimate. Member-initiated disassociation applies to invitation-based relationships; Organizations-managed members cannot use that workflow. Disassociation is not detector deletion.

The T1685 mapping applies to deliberate defensive impairment; the API name alone does not establish malicious intent.

Log Source

CloudTrail management event with eventSource: guardduty.amazonaws.com and eventName: DisassociateFromMasterAccount. Search regional Event history or your retained management-event collection; collection scope and retention determine the available evidence.

Key Fields

FieldInvestigation use
requestParameters.detectorIdThe calling member’s detector.
eventNameDistinguish the legacy and current operation names.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the request and correlate with approved work.
awsRegion, recipientAccountIdScope the affected environment.
errorCode, errorMessageCheck rejection before inferring a completed change; null responseElements alone is not proof of success.

What to Investigate

  1. Identify the member account, Region, and previous administrator from retained relationship records; the request does not name the administrator.
  2. Check whether the relationship was invitation-based or Organizations-managed and inspect rejection errors.
  3. Confirm the relationship changed and separately verify detector status and local finding access.
  4. Correlate with DisassociateMembers and DeleteDetector; restore approved oversight and review the gap.

Sample Event

Synthetic impairment scenario. Draco invokes the legacy API from an assumed invitation-managed member account. The administrator’s identity and successful relationship change require separate evidence; the sample does not establish an Organizations departure. No top-level error is shown. Exact CloudTrail serialization and optional fields have not been validated by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T20:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:38:55Z",
"eventSource": "guardduty.amazonaws.com",
"eventName": "DisassociateFromMasterAccount",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"detectorId": "0123456789abcdef0123456789abcdef"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000100110010",
"eventID": "90000000-0000-4000-8000-000100110011",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "guardduty.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.