EnableRegion
EnableRegion
Event
EnableRegion starts account preparation in an opt-in Region. The Region cannot be used until preparation completes, which can take minutes to hours. The API’s recorded awsRegion is distinct from requestParameters.regionName, the Region being enabled.
Security Context
Unexpected use of previously unused Regions can support T1535, but enabling a Region does not guarantee a monitoring blind spot. Multi-Region CloudTrail trails extend to newly enabled Regions, subject to propagation and delivery delays; other regional controls require individual verification.
Log Source
AWS CloudTrail management event with eventSource: account.amazonaws.com and eventName: EnableRegion. Verify collection across the relevant accounts and Regions. Inspect response and error fields; the event does not by itself prove downstream use.
Key Fields
| Field | Investigation value |
|---|---|
userIdentity, sourceIPAddress | Recorded identity/client context, not proof of malicious intent. |
eventName, eventSource, awsRegion | Operation and collection context; distinguish requested target Region when applicable. |
requestParameters, responseElements | Request scope and outcome, where present. |
eventID, eventTime, errorCode, errorMessage | Timing, correlation, and errors; inspect related completion/sign-in records. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Confirm the target account and requested Region against approved geographic requirements and account policies.
- Check the resulting Region status and subsequent resource creation, rather than assuming immediate usability.
- Verify actual CloudTrail delivery and regional security-service coverage; use regional Event History when investigating propagation delays.
Sample Event
Synthetic scenario. Draco requests activation of ap-east-1. The sample does not show completed activation, security-control configuration, or resources deployed there.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "AKIADRAC0MALF0YEXAMP5", "userName": "draco" }, "eventTime": "2026-04-15T20:54:33Z", "eventSource": "account.amazonaws.com", "eventName": "EnableRegion", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/2.15.30 Python/3.11.6 Linux/5.15.0-1052-aws exe/x86_64.ubuntu.22 prompt/off command/account.enable-region", "requestParameters": { "regionName": "ap-east-1" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000100110110", "eventID": "90000000-0000-4000-8000-000100110111", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "account.us-east-1.amazonaws.com" }}