Skip to content

StopConfigurationRecorder

AWS

StopConfigurationRecorder

service: AWS - Config
techniques:

Event

StopConfigurationRecorder stops a named customer-managed AWS Config recorder. Its configured resource types determine the affected scope. This API does not stop service-linked configuration recorders; those remain recording. AWS API reference.

Security Context

An unexpected stop can interrupt configuration evidence used to investigate drift and assess resource changes. Do not infer that every security service, all regional recording, or every compliance evaluation stopped.

Legitimate uses: an approved maintenance window or retirement of a customer-managed recorder. Confirm the owner, expected duration, and any alternative recording path.

Mapping rationale: deliberately interrupting a configuration-monitoring tool supports Disable or Modify Tools. The mapping depends on malicious use, not simply the occurrence of an administrative API call.

Log Source

Search CloudTrail for eventSource: config.amazonaws.com and eventName: StopConfigurationRecorder. AWS publishes a CloudTrail example for this operation. Retain write management events for ongoing investigation; stopping Config recording does not itself stop CloudTrail API logging. AWS Config logging guidance.

Collection boundary: a request names a recorder, not a complete list of affected resources. Recover its recording configuration and inspect other recorders separately. Do not use this event alone to declare all configuration history or other retained evidence unavailable.

Key Fields

FieldInvestigation use
requestParameters.configurationRecorderNameResolve the customer-managed recorder and its configured resource scope.
userIdentity.arn and userIdentity.sessionContextAttribute the caller and session where available.
eventTime, awsRegion, and recipientAccountIdEstablish the account, Region, and investigation interval.
sourceIPAddress and userAgentCompare the origin and client with expected administration.
errorCode and errorMessageIdentify rejected attempts; a null response does not independently prove a stop succeeded.

What to Investigate

  1. Establish the request outcome and check DescribeConfigurationRecorderStatus, including recording and available stop/start timestamps. A current snapshot does not prove continuous state throughout the incident.
  2. Recover the recorder’s selected resource types and compare them with resources changed during the suspected gap. Check service-linked recorders and other evidence sources separately.
  3. Validate the change against maintenance records, then trace the caller’s preceding AssumeRole activity where applicable.
  4. Look for a later StartConfigurationRecorder call or DeleteConfigurationRecorder. Verify resumed recording and document what evidence was unavailable during the interval; restarting alone does not establish that every intermediate change was captured.

Sample Event

Synthetic scenario — paused configuration recording. Draco requests a stop of the customer-managed recorder default in us-east-1. The sample contains no error fields, but the affected resource types and stop duration require additional evidence. It does not imply that service-linked recorders or CloudTrail were disabled.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T21:02:14Z",
"eventSource": "config.amazonaws.com",
"eventName": "StopConfigurationRecorder",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"configurationRecorderName": "default"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000110111000",
"eventID": "90000000-0000-4000-8000-000110111001",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "config.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.