UpdateIPSet
UpdateIPSet
Event
Updates the specified trusted IP list, including its S3 location, name, or activation setting. The request does not contain the list entries. A name-only change is not evidence that trusted addresses changed.
Security Context
Unauthorized list changes can weaken detection; approved infrastructure changes can also explain them. IP lists affect CloudTrail and VPC Flow Logs findings, not Route 53 Resolver DNS findings. They apply to publicly routable IPv4 addresses. Updating the S3 file requires reactivation; do not assume a periodic sync has loaded it.
The T1685 mapping applies to deliberate defensive impairment; the API name alone does not establish malicious intent.
Log Source
CloudTrail management event with eventSource: guardduty.amazonaws.com and eventName: UpdateIPSet. Search regional Event history or your retained management-event collection; collection scope and retention determine the available evidence.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.detectorId, requestParameters.ipSetId | Identify the regional list. |
requestParameters.location, requestParameters.activate | Compare requested configuration with prior state and actual activation status. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the request and correlate with approved work. |
awsRegion, recipientAccountId | Scope the affected environment. |
errorCode, errorMessage | Check rejection before inferring a completed change; null responseElements alone is not proof of success. |
What to Investigate
- Confirm the change owner and inspect request errors. Use GetIPSet to check the stored location and status.
- Preserve the relevant S3 object version and compare its entries with the approved list. The caller address does not prove list contents.
- Check administrator/member scope and establish when the list reached ACTIVE, rather than using the request time as guaranteed activation time.
- Correlate with CreateIPSet and verify the final approved list after remediation.
Sample Event
Synthetic impairment scenario. Draco requests a new list location and activation. This assumes unauthorized tuning, but the list contents and completed activation are not shown. The caller address is documentation-only. No top-level error is shown. Exact CloudTrail serialization and optional fields have not been validated by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:50:09Z", "eventSource": "guardduty.amazonaws.com", "eventName": "UpdateIPSet", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "detectorId": "0123456789abcdef0123456789abcdef", "ipSetId": "abcdef0123456789abcdef0123456789", "name": "corp-egress", "location": "https://s3.amazonaws.com/example-guardduty-lists/corp-egress.txt", "activate": true }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000111001110", "eventID": "90000000-0000-4000-8000-000111001111", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "guardduty.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...