StopConfigurationRecorder
StopConfigurationRecorder
Event
StopConfigurationRecorder stops a named customer-managed AWS Config recorder. Its configured resource types determine the affected scope. This API does not stop service-linked configuration recorders; those remain recording. AWS API reference.
Security Context
An unexpected stop can interrupt configuration evidence used to investigate drift and assess resource changes. Do not infer that every security service, all regional recording, or every compliance evaluation stopped.
Legitimate uses: an approved maintenance window or retirement of a customer-managed recorder. Confirm the owner, expected duration, and any alternative recording path.
Mapping rationale: deliberately interrupting a configuration-monitoring tool supports Disable or Modify Tools. The mapping depends on malicious use, not simply the occurrence of an administrative API call.
Log Source
Search CloudTrail for eventSource: config.amazonaws.com and eventName: StopConfigurationRecorder. AWS publishes a CloudTrail example for this operation. Retain write management events for ongoing investigation; stopping Config recording does not itself stop CloudTrail API logging. AWS Config logging guidance.
Collection boundary: a request names a recorder, not a complete list of affected resources. Recover its recording configuration and inspect other recorders separately. Do not use this event alone to declare all configuration history or other retained evidence unavailable.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.configurationRecorderName | Resolve the customer-managed recorder and its configured resource scope. |
userIdentity.arn and userIdentity.sessionContext | Attribute the caller and session where available. |
eventTime, awsRegion, and recipientAccountId | Establish the account, Region, and investigation interval. |
sourceIPAddress and userAgent | Compare the origin and client with expected administration. |
errorCode and errorMessage | Identify rejected attempts; a null response does not independently prove a stop succeeded. |
What to Investigate
- Establish the request outcome and check DescribeConfigurationRecorderStatus, including
recordingand available stop/start timestamps. A current snapshot does not prove continuous state throughout the incident. - Recover the recorder’s selected resource types and compare them with resources changed during the suspected gap. Check service-linked recorders and other evidence sources separately.
- Validate the change against maintenance records, then trace the caller’s preceding AssumeRole activity where applicable.
- Look for a later
StartConfigurationRecordercall or DeleteConfigurationRecorder. Verify resumed recording and document what evidence was unavailable during the interval; restarting alone does not establish that every intermediate change was captured.
Sample Event
Synthetic scenario — paused configuration recording. Draco requests a stop of the customer-managed recorder default in us-east-1. The sample contains no error fields, but the affected resource types and stop duration require additional evidence. It does not imply that service-linked recorders or CloudTrail were disabled.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:02:14Z", "eventSource": "config.amazonaws.com", "eventName": "StopConfigurationRecorder", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "configurationRecorderName": "default" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000110111000", "eventID": "90000000-0000-4000-8000-000110111001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "config.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...