Skip to content

PutEventSelectors

AWS

PutEventSelectors

service: AWS - CloudTrail
techniques:

Event

PutEventSelectors changes the selection rules for a CloudTrail trail. A request uses either basic or advanced selectors, not both; switching selector types replaces the other type. Advanced selectors also support network activity events. The operation must target the trail’s home Region. AWS API reference.

Security Context

A trail can remain enabled while its selectors exclude activity that investigators need. Compare the previous and resulting configuration; the operation name alone does not tell you whether coverage increased or decreased.

Legitimate uses: adding application data events, reducing an approved collection scope, or migrating to advanced selectors. Verify that required evidence still reaches its intended destination.

Mapping rationale: deliberately narrowing audit collection to conceal activity fits Disable or Modify Cloud Log. Changing selectors does not itself delete previously delivered records.

Log Source

Search CloudTrail management events for eventSource: cloudtrail.amazonaws.com and eventName: PutEventSelectors. Include write management events when configuring retained collection for this operation.

Collection boundary: a change affects the named trail’s selection rules, not every source of evidence. Event history is independent of trail configuration and retains regional management events for 90 days. Other trails may continue collecting the excluded activity. Do not describe the selector-change request as a guaranteed final delivered record. Event history behavior.

Key Fields

FieldInvestigation use
requestParameters.trailNameIdentify the affected trail by name or ARN.
requestParameters.eventSelectorsInspect management-event inclusion, read/write selection, data-resource scope, and excluded sources.
requestParameters.advancedEventSelectorsInspect field conditions when the request uses advanced selectors instead.
responseElementsCompare returned selectors with the request when present; inspect error fields before assuming success.
userIdentity.arn, eventTime, and awsRegionAttribute the change and establish its account/Region context and timing.

What to Investigate

  1. Check the outcome, then retrieve the current configuration with GetEventSelectors. Current settings may reflect later changes; preserve the original event and a timestamped configuration snapshot.
  2. Compare the complete selector set with the previous approved configuration. Check both selector types and all entries, rather than assuming one restrictive entry describes the whole trail.
  3. Identify the specific event classes and resources excluded by the change. Verify whether independent collection paths cover them before concluding there is an organization-wide visibility gap.
  4. Correlate the caller with AssumeRole activity where relevant, and look for nearby UpdateTrail, StopLogging, or DeleteTrail calls. Compare the timeline with approved changes and later restoration.

Sample Event

Synthetic scenario — narrowed collection. Draco sets an account trail to collect read-only management events, with no data resources selected. If this replaces a broader configuration successfully, the resulting selector set excludes write management events from this trail. The record alone does not establish the previous configuration or whether another trail collects those events.

The basic selector uses readWriteType: ReadOnly and includeManagementEvents: true. Interpret these settings together: management events are included, but only reads match this selector. Basic selector fields.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T21:42:08Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T22:00:11Z",
"eventSource": "cloudtrail.amazonaws.com",
"eventName": "PutEventSelectors",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"trailName": "fantasticlogs-prod-trail",
"eventSelectors": [
{
"readWriteType": "ReadOnly",
"includeManagementEvents": true,
"dataResources": [],
"excludeManagementEventSources": []
}
]
},
"responseElements": {
"trailARN": "arn:aws:cloudtrail:us-east-1:555123456789:trail/fantasticlogs-prod-trail",
"eventSelectors": [
{
"readWriteType": "ReadOnly",
"includeManagementEvents": true,
"dataResources": [],
"excludeManagementEventSources": []
}
]
},
"requestID": "90000000-0000-4000-8000-000101101010",
"eventID": "90000000-0000-4000-8000-000101101011",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "cloudtrail.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.