UpdateDetector
UpdateDetector
Event
UpdateDetector changes a GuardDuty detector’s settings in one account and Region. A request can change the detector’s enabled state, individual protection features, or finding publishing frequency. Inspect the supplied fields and prior configuration to determine the effect.
Security Context
Unauthorized suspension or feature disabling can impair detection and fits T1685. Routine protection rollout or configuration maintenance can also use this API. A detector with enable: true does not necessarily have every protection feature enabled.
Setting enable: false suspends GuardDuty rather than deleting the detector; existing findings are retained. Feature-level changes need separate review. Do not infer that a disabled feature would certainly have detected a particular attack, or that all remaining protection is ineffective.
Log Source
CloudTrail management event with eventSource: guardduty.amazonaws.com and eventName: UpdateDetector. Inspect retained GuardDuty control-plane events, independently of the findings generated by the detector. Collection coverage and retention determine the available investigation window.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.detectorId, awsRegion, recipientAccountId | Identify the affected regional detector. |
requestParameters.enable | Requested overall enabled state, when supplied. |
requestParameters.features | Feature names, statuses, and any additional configuration; compare with prior state. |
requestParameters.dataSources | Older, deprecated configuration parameter that may occur in historical requests. |
requestParameters.findingPublishingFrequency | Publishing setting; not the detector’s scanning interval. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute and correlate the change. |
errorCode, errorMessage | Identify rejected requests before assessing coverage impact. |
What to Investigate
- Confirm the caller’s authorization and inspect errors. Compare
GetDetectorstatus and features with the last known approved configuration. - Determine which features changed and which workloads depended on them. Check regional availability and organization policy rather than assuming identical settings across accounts.
- If publishing frequency changed, assess notification timing separately from detection coverage. For EventBridge, this controls notifications for subsequent finding occurrences; newly generated findings are sent in near real time.
- Correlate with DeleteDetector and other security changes. Verify restored feature settings and workload coverage, and investigate the interval of reduced protection.
Sample Event
Synthetic impairment scenario. Draco requests disabling S3_DATA_EVENTS and RUNTIME_MONITORING while keeping the detector enabled. The scenario assumes these features were previously enabled; the request alone cannot prove that change. SIX_HOURS is a publishing setting, not evidence of a six-hour detection delay. No error fields are shown, and exact CloudTrail serialization has not been validated by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:27:43Z", "eventSource": "guardduty.amazonaws.com", "eventName": "UpdateDetector", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "detectorId": "0123456789abcdef0123456789abcdef", "enable": true, "findingPublishingFrequency": "SIX_HOURS", "features": [ { "name": "S3_DATA_EVENTS", "status": "DISABLED" }, { "name": "RUNTIME_MONITORING", "status": "DISABLED" } ] }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000111000100", "eventID": "90000000-0000-4000-8000-000111000101", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "guardduty.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...