DisassociateMembers
DisassociateMembers
Event
Removes the specified GuardDuty member associations. Disassociation does not itself disable an enabled member detector, but the former administrator loses access to the standalone account’s findings. Invited-member details are retained until DeleteMembers.
Security Context
Unauthorized removal can disrupt centralized oversight. Approved administration changes can produce the same event. With organization auto-enable set to ALL, disassociation is blocked while the account remains in the organization. This is not removal from AWS Organizations.
The T1685 mapping applies to deliberate defensive impairment; the API name alone does not establish malicious intent.
Log Source
CloudTrail management event with eventSource: guardduty.amazonaws.com and eventName: DisassociateMembers. Search regional Event history or your retained management-event collection; collection scope and retention determine the available evidence.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.detectorId | Administrator detector for the relationship. |
requestParameters.accountIds | Requested member accounts. |
responseElements.unprocessedAccounts | Members that could not be processed and reasons. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the request and correlate with approved work. |
awsRegion, recipientAccountId | Scope the affected environment. |
errorCode, errorMessage | Check rejection before inferring a completed change; null responseElements alone is not proof of success. |
What to Investigate
- Confirm approved ownership changes and organization settings; inspect errors and per-member failures.
- Compare GetMembers or ListMembers relationship status with the previous inventory.
- Verify each member’s detector state and independent notification routes; assess actual central visibility loss.
- Correlate with StopMonitoringMembers and DeleteMembers. Re-establish approved associations using the correct invitation or Organizations workflow.
Sample Event
Synthetic impairment scenario. An assumed role in account 555424242424 requests disassociation of member 555123456789. The record does not demonstrate how the role was obtained, detector shutdown, or complete SOC blindness. No top-level error is shown. Exact CloudTrail serialization and optional fields have not been validated by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "AssumedRole", "principalId": "AROA0RGACCESS0RG007:draco-pivot", "arn": "arn:aws:sts::555424242424:assumed-role/OrgAccessRole/draco-pivot", "accountId": "555424242424", "accessKeyId": "ASIADRAC0PIV0TSESS001", "sessionContext": { "sessionIssuer": { "type": "Role", "principalId": "AROA0RGACCESS0RG007", "arn": "arn:aws:iam::555424242424:role/OrgAccessRole", "accountId": "555424242424", "userName": "OrgAccessRole" }, "attributes": { "creationDate": "2026-04-15T20:42:01Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:46:09Z", "eventSource": "guardduty.amazonaws.com", "eventName": "DisassociateMembers", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "detectorId": "0123456789abcdef0123456789abcdef", "accountIds": [ "555123456789" ] }, "responseElements": { "unprocessedAccounts": [] }, "requestID": "90000000-0000-4000-8000-000100110100", "eventID": "90000000-0000-4000-8000-000100110101", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555424242424", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "guardduty.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...