Skip to content

PutRule

AWS

PutRule

service: AWS - EventBridge
tactics:
techniques:

Event

Defines an event pattern, schedule, or both and sets rule state. Updating a rule replaces supplied properties and can reset omitted properties to null. Targets are configured separately. An enabled rule needs matching delivered events and usable targets/permissions to cause downstream activity.

Security Context

Unauthorized event-triggered automation can support persistence (T1546). Normal automation uses identical APIs. CloudTrail-based event patterns require the relevant event collection/delivery; a rule ARN does not prove any match or target execution.

Log Source

CloudTrail management event with eventSource: events.amazonaws.com and eventName: PutRule. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.

Key Fields

Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.

FieldInvestigation value
name, eventBusName, stateRule identity, bus, and enabled state.
eventPattern, scheduleExpressionMatching logic or schedule; parse embedded pattern JSON.
userIdentity, eventTime, awsRegion, eventID (top level)Caller/session, timeline, Region, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Compare the complete prior and new rule, including omitted properties and approved purpose.
  3. Inspect PutTargets history, current targets, authorization, and input transformations.
  4. Check source-event availability and rule/target metrics plus downstream logs before asserting execution.

Sample Event

Synthetic scenario. An enabled rule matches CloudTrail CreateUser events. No targets, matched event, or invocation are shown.

Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:28:11Z",
"eventSource": "events.amazonaws.com",
"eventName": "PutRule",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"name": "phoenix-restore-watch",
"eventPattern": "{\"source\":[\"aws.iam\"],\"detail-type\":[\"AWS API Call via CloudTrail\"],\"detail\":{\"eventSource\":[\"iam.amazonaws.com\"],\"eventName\":[\"CreateUser\"]}}",
"state": "ENABLED",
"description": "Internal restore-watcher (do not modify)",
"eventBusName": "default"
},
"responseElements": {
"ruleArn": "arn:aws:events:us-east-1:555123456789:rule/phoenix-restore-watch"
},
"requestID": "90000000-0000-4000-8000-000110010100",
"eventID": "90000000-0000-4000-8000-000110010101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "events.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence

Techniques:
  • T1546 — Event Triggered Execution — Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. Various operating systems have means to monitor and subscribe to events such as logons or other user activity such as running specific applications/binaries. Cl...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.