Skip to content

DisassociateMembers

AWS

DisassociateMembers

service: AWS - GuardDuty
techniques:

Event

Removes the specified GuardDuty member associations. Disassociation does not itself disable an enabled member detector, but the former administrator loses access to the standalone account’s findings. Invited-member details are retained until DeleteMembers.

Security Context

Unauthorized removal can disrupt centralized oversight. Approved administration changes can produce the same event. With organization auto-enable set to ALL, disassociation is blocked while the account remains in the organization. This is not removal from AWS Organizations.

The T1685 mapping applies to deliberate defensive impairment; the API name alone does not establish malicious intent.

Log Source

CloudTrail management event with eventSource: guardduty.amazonaws.com and eventName: DisassociateMembers. Search regional Event history or your retained management-event collection; collection scope and retention determine the available evidence.

Key Fields

FieldInvestigation use
requestParameters.detectorIdAdministrator detector for the relationship.
requestParameters.accountIdsRequested member accounts.
responseElements.unprocessedAccountsMembers that could not be processed and reasons.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the request and correlate with approved work.
awsRegion, recipientAccountIdScope the affected environment.
errorCode, errorMessageCheck rejection before inferring a completed change; null responseElements alone is not proof of success.

What to Investigate

  1. Confirm approved ownership changes and organization settings; inspect errors and per-member failures.
  2. Compare GetMembers or ListMembers relationship status with the previous inventory.
  3. Verify each member’s detector state and independent notification routes; assess actual central visibility loss.
  4. Correlate with StopMonitoringMembers and DeleteMembers. Re-establish approved associations using the correct invitation or Organizations workflow.

Sample Event

Synthetic impairment scenario. An assumed role in account 555424242424 requests disassociation of member 555123456789. The record does not demonstrate how the role was obtained, detector shutdown, or complete SOC blindness. No top-level error is shown. Exact CloudTrail serialization and optional fields have not been validated by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "AssumedRole",
"principalId": "AROA0RGACCESS0RG007:draco-pivot",
"arn": "arn:aws:sts::555424242424:assumed-role/OrgAccessRole/draco-pivot",
"accountId": "555424242424",
"accessKeyId": "ASIADRAC0PIV0TSESS001",
"sessionContext": {
"sessionIssuer": {
"type": "Role",
"principalId": "AROA0RGACCESS0RG007",
"arn": "arn:aws:iam::555424242424:role/OrgAccessRole",
"accountId": "555424242424",
"userName": "OrgAccessRole"
},
"attributes": {
"creationDate": "2026-04-15T20:42:01Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:46:09Z",
"eventSource": "guardduty.amazonaws.com",
"eventName": "DisassociateMembers",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"detectorId": "0123456789abcdef0123456789abcdef",
"accountIds": [
"555123456789"
]
},
"responseElements": {
"unprocessedAccounts": []
},
"requestID": "90000000-0000-4000-8000-000100110100",
"eventID": "90000000-0000-4000-8000-000100110101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555424242424",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "guardduty.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.