Skip to content

EnableRegion

AWS

EnableRegion

service: AWS - Account Management
tactics:
techniques:

Event

EnableRegion starts account preparation in an opt-in Region. The Region cannot be used until preparation completes, which can take minutes to hours. The API’s recorded awsRegion is distinct from requestParameters.regionName, the Region being enabled.

Security Context

Unexpected use of previously unused Regions can support T1535, but enabling a Region does not guarantee a monitoring blind spot. Multi-Region CloudTrail trails extend to newly enabled Regions, subject to propagation and delivery delays; other regional controls require individual verification.

Log Source

AWS CloudTrail management event with eventSource: account.amazonaws.com and eventName: EnableRegion. Verify collection across the relevant accounts and Regions. Inspect response and error fields; the event does not by itself prove downstream use.

Key Fields

FieldInvestigation value
userIdentity, sourceIPAddressRecorded identity/client context, not proof of malicious intent.
eventName, eventSource, awsRegionOperation and collection context; distinguish requested target Region when applicable.
requestParameters, responseElementsRequest scope and outcome, where present.
eventID, eventTime, errorCode, errorMessageTiming, correlation, and errors; inspect related completion/sign-in records.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Confirm the target account and requested Region against approved geographic requirements and account policies.
  3. Check the resulting Region status and subsequent resource creation, rather than assuming immediate usability.
  4. Verify actual CloudTrail delivery and regional security-service coverage; use regional Event History when investigating propagation delays.

Sample Event

Synthetic scenario. Draco requests activation of ap-east-1. The sample does not show completed activation, security-control configuration, or resources deployed there.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "AKIADRAC0MALF0YEXAMP5",
"userName": "draco"
},
"eventTime": "2026-04-15T20:54:33Z",
"eventSource": "account.amazonaws.com",
"eventName": "EnableRegion",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/2.15.30 Python/3.11.6 Linux/5.15.0-1052-aws exe/x86_64.ubuntu.22 prompt/off command/account.enable-region",
"requestParameters": {
"regionName": "ap-east-1"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000100110110",
"eventID": "90000000-0000-4000-8000-000100110111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "account.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Stealth

Techniques:
  • T1535 — Unused/Unsupported Cloud Regions — Adversaries may create cloud instances in unused geographic service regions in order to evade detection. Access is usually obtained through compromising accounts used to manage cloud infrastructure.
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.