StopMonitoringMembers
StopMonitoringMembers
Event
Suspends GuardDuty monitoring for the specified members. This stops monitoring and new findings for those members, rather than merely stopping central aggregation. Existing findings remain, and the accounts stay associated. Malware Protection for S3 configurations are not affected by this suspension.
Security Context
Unauthorized suspension can create a detection gap; approved account maintenance can also explain it. Organization auto-enable set to ALL prevents this operation. Assess each requested member separately and check other Regions independently.
The T1685 mapping applies to deliberate defensive impairment; the API name alone does not establish malicious intent.
Log Source
CloudTrail management event with eventSource: guardduty.amazonaws.com and eventName: StopMonitoringMembers. Search regional Event history or your retained management-event collection; collection scope and retention determine the available evidence.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.detectorId | Administrator detector, not a member detector. |
requestParameters.accountIds | Members requested for suspension. |
responseElements.unprocessedAccounts | Per-account failures and reasons, when recorded. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the request and correlate with approved work. |
awsRegion, recipientAccountId | Scope the affected environment. |
errorCode, errorMessage | Check rejection before inferring a completed change; null responseElements alone is not proof of success. |
What to Investigate
- Confirm authorization and organization settings. Inspect both top-level errors and unprocessedAccounts.
- Check member relationship and monitoring status through GetMembers or ListMembers; do not equate an existing detector with active monitoring.
- Establish the affected interval and inspect retained findings and independent evidence for each member.
- Correlate with DisassociateMembers. Verify monitoring resumes after an approved StartMonitoringMembers operation.
Sample Event
Synthetic impairment scenario. A role session in administrator account 555424242424 requests suspension for member 555123456789. The empty failure list illustrates a processed request, not proof of the prior monitoring state or later restoration. No top-level error is shown. Exact CloudTrail serialization and optional fields have not been validated by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "AssumedRole", "principalId": "AROAERUMPENT1RR0006:draco-ir-session", "arn": "arn:aws:sts::555424242424:assumed-role/IncidentResponseRole/draco-ir-session", "accountId": "555424242424", "accessKeyId": "ASIAERUMPENT1RSESS01", "sessionContext": { "sessionIssuer": { "type": "Role", "principalId": "AROAERUMPENT1RR0006", "arn": "arn:aws:iam::555424242424:role/IncidentResponseRole", "accountId": "555424242424", "userName": "IncidentResponseRole" }, "attributes": { "creationDate": "2026-04-15T20:55:00Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:08:36Z", "eventSource": "guardduty.amazonaws.com", "eventName": "StopMonitoringMembers", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "detectorId": "0123456789abcdef0123456789abcdef", "accountIds": [ "555123456789" ] }, "responseElements": { "unprocessedAccounts": [] }, "requestID": "90000000-0000-4000-8000-000110111100", "eventID": "90000000-0000-4000-8000-000110111101", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555424242424", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "guardduty.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...