Skip to content

StopLogging

AWS

StopLogging

service: AWS - CloudTrail
techniques:

Event

StopLogging pauses recording and log delivery for one CloudTrail trail. It does not delete that trail’s previously delivered logs. For a multi-Region trail, the request must target its home Region. AWS API reference.

Security Context

An unexpected successful stop can interrupt the evidence pipeline used by investigations and alerts. Treat the trail’s purpose and scope as the starting point: a production audit trail warrants different scrutiny from a disposable test trail.

Legitimate uses: retiring a duplicate trail or ending a controlled test. Confirm the change owner and replacement collection path. Routine trail configuration changes do not require stopping logging first.

Mapping rationale: disabling a cloud audit trail supports the catalog’s Disable or Modify Cloud Log mapping. The API name alone does not establish malicious intent.

Log Source

Look for eventSource: cloudtrail.amazonaws.com and eventName: StopLogging in CloudTrail management events. For a retained trail feed, include write management events in its collection settings. Management event collection.

Collection boundary: stopping a trail does not stop CloudTrail Event history, which independently retains 90 days of regional management events. Other trails may also retain evidence. Event history does not recover missing data events. Avoid assuming the stop request is the final record delivered, or that all later activity is invisible. Event history behavior.

Key Fields

FieldInvestigation use
requestParameters.nameIdentify the trail by name or ARN; resolve its scope and home Region.
userIdentity.arn and userIdentity.sessionContextAttribute the caller and, when present, its role session.
eventTime and awsRegionEstablish the investigation window and where to search.
sourceIPAddress and userAgentCompare the origin and client with the actor’s baseline.
errorCode and errorMessageSeparate rejected attempts from apparent success; responseElements: null alone is not proof.

What to Investigate

  1. Confirm the outcome and check the trail’s current IsLogging state with GetTrailStatus. Current state does not establish what happened throughout the earlier interval. Status fields.
  2. Identify who controlled the caller’s credentials. If it was a role session, trace the preceding AssumeRole activity and compare it with approved administration.
  3. Look for nearby DeleteTrail and PutEventSelectors calls. Determine whether collection was stopped, narrowed, or removed.
  4. Find any subsequent StartLogging call and verify delivery resumed. Investigate the intervening activity using independent retained sources; record which event types are unavailable.

Sample Event

Synthetic scenario — suspicious change. Draco stops the account trail fantasticlogs-prod-trail in us-east-1. This illustrative record contains no error fields. Confirm the result and the trail state rather than treating the record as proof of a complete logging outage.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T21:04:08Z",
"eventSource": "cloudtrail.amazonaws.com",
"eventName": "StopLogging",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"name": "arn:aws:cloudtrail:us-east-1:555123456789:trail/fantasticlogs-prod-trail"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000110111010",
"eventID": "90000000-0000-4000-8000-000110111011",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "cloudtrail.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...
Documentation reviewed: September 28, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.