PutRule
PutRule
Event
Defines an event pattern, schedule, or both and sets rule state. Updating a rule replaces supplied properties and can reset omitted properties to null. Targets are configured separately. An enabled rule needs matching delivered events and usable targets/permissions to cause downstream activity.
Security Context
Unauthorized event-triggered automation can support persistence (T1546). Normal automation uses identical APIs. CloudTrail-based event patterns require the relevant event collection/delivery; a rule ARN does not prove any match or target execution.
Log Source
CloudTrail management event with eventSource: events.amazonaws.com and eventName: PutRule. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.
Key Fields
Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.
| Field | Investigation value |
|---|---|
name, eventBusName, state | Rule identity, bus, and enabled state. |
eventPattern, scheduleExpression | Matching logic or schedule; parse embedded pattern JSON. |
userIdentity, eventTime, awsRegion, eventID (top level) | Caller/session, timeline, Region, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Compare the complete prior and new rule, including omitted properties and approved purpose.
- Inspect PutTargets history, current targets, authorization, and input transformations.
- Check source-event availability and rule/target metrics plus downstream logs before asserting execution.
Sample Event
Synthetic scenario. An enabled rule matches CloudTrail CreateUser events. No targets, matched event, or invocation are shown.
Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:28:11Z", "eventSource": "events.amazonaws.com", "eventName": "PutRule", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "name": "phoenix-restore-watch", "eventPattern": "{\"source\":[\"aws.iam\"],\"detail-type\":[\"AWS API Call via CloudTrail\"],\"detail\":{\"eventSource\":[\"iam.amazonaws.com\"],\"eventName\":[\"CreateUser\"]}}", "state": "ENABLED", "description": "Internal restore-watcher (do not modify)", "eventBusName": "default" }, "responseElements": { "ruleArn": "arn:aws:events:us-east-1:555123456789:rule/phoenix-restore-watch" }, "requestID": "90000000-0000-4000-8000-000110010100", "eventID": "90000000-0000-4000-8000-000110010101", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "events.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence
- T1546 — Event Triggered Execution — Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. Various operating systems have means to monitor and subscribe to events such as logons or other user activity such as running specific applications/binaries. Cl...