Skip to content

UpdateDetector

AWS

UpdateDetector

service: AWS - GuardDuty
techniques:

Event

UpdateDetector changes a GuardDuty detector’s settings in one account and Region. A request can change the detector’s enabled state, individual protection features, or finding publishing frequency. Inspect the supplied fields and prior configuration to determine the effect.

Security Context

Unauthorized suspension or feature disabling can impair detection and fits T1685. Routine protection rollout or configuration maintenance can also use this API. A detector with enable: true does not necessarily have every protection feature enabled.

Setting enable: false suspends GuardDuty rather than deleting the detector; existing findings are retained. Feature-level changes need separate review. Do not infer that a disabled feature would certainly have detected a particular attack, or that all remaining protection is ineffective.

Log Source

CloudTrail management event with eventSource: guardduty.amazonaws.com and eventName: UpdateDetector. Inspect retained GuardDuty control-plane events, independently of the findings generated by the detector. Collection coverage and retention determine the available investigation window.

Key Fields

FieldInvestigation use
requestParameters.detectorId, awsRegion, recipientAccountIdIdentify the affected regional detector.
requestParameters.enableRequested overall enabled state, when supplied.
requestParameters.featuresFeature names, statuses, and any additional configuration; compare with prior state.
requestParameters.dataSourcesOlder, deprecated configuration parameter that may occur in historical requests.
requestParameters.findingPublishingFrequencyPublishing setting; not the detector’s scanning interval.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute and correlate the change.
errorCode, errorMessageIdentify rejected requests before assessing coverage impact.

What to Investigate

  1. Confirm the caller’s authorization and inspect errors. Compare GetDetector status and features with the last known approved configuration.
  2. Determine which features changed and which workloads depended on them. Check regional availability and organization policy rather than assuming identical settings across accounts.
  3. If publishing frequency changed, assess notification timing separately from detection coverage. For EventBridge, this controls notifications for subsequent finding occurrences; newly generated findings are sent in near real time.
  4. Correlate with DeleteDetector and other security changes. Verify restored feature settings and workload coverage, and investigate the interval of reduced protection.

Sample Event

Synthetic impairment scenario. Draco requests disabling S3_DATA_EVENTS and RUNTIME_MONITORING while keeping the detector enabled. The scenario assumes these features were previously enabled; the request alone cannot prove that change. SIX_HOURS is a publishing setting, not evidence of a six-hour detection delay. No error fields are shown, and exact CloudTrail serialization has not been validated by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T21:27:43Z",
"eventSource": "guardduty.amazonaws.com",
"eventName": "UpdateDetector",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"detectorId": "0123456789abcdef0123456789abcdef",
"enable": true,
"findingPublishingFrequency": "SIX_HOURS",
"features": [
{
"name": "S3_DATA_EVENTS",
"status": "DISABLED"
},
{
"name": "RUNTIME_MONITORING",
"status": "DISABLED"
}
]
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000111000100",
"eventID": "90000000-0000-4000-8000-000111000101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "guardduty.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.