Skip to content

UpdateIPSet

AWS

UpdateIPSet

service: AWS - GuardDuty
techniques:

Event

Updates the specified trusted IP list, including its S3 location, name, or activation setting. The request does not contain the list entries. A name-only change is not evidence that trusted addresses changed.

Security Context

Unauthorized list changes can weaken detection; approved infrastructure changes can also explain them. IP lists affect CloudTrail and VPC Flow Logs findings, not Route 53 Resolver DNS findings. They apply to publicly routable IPv4 addresses. Updating the S3 file requires reactivation; do not assume a periodic sync has loaded it.

The T1685 mapping applies to deliberate defensive impairment; the API name alone does not establish malicious intent.

Log Source

CloudTrail management event with eventSource: guardduty.amazonaws.com and eventName: UpdateIPSet. Search regional Event history or your retained management-event collection; collection scope and retention determine the available evidence.

Key Fields

FieldInvestigation use
requestParameters.detectorId, requestParameters.ipSetIdIdentify the regional list.
requestParameters.location, requestParameters.activateCompare requested configuration with prior state and actual activation status.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the request and correlate with approved work.
awsRegion, recipientAccountIdScope the affected environment.
errorCode, errorMessageCheck rejection before inferring a completed change; null responseElements alone is not proof of success.

What to Investigate

  1. Confirm the change owner and inspect request errors. Use GetIPSet to check the stored location and status.
  2. Preserve the relevant S3 object version and compare its entries with the approved list. The caller address does not prove list contents.
  3. Check administrator/member scope and establish when the list reached ACTIVE, rather than using the request time as guaranteed activation time.
  4. Correlate with CreateIPSet and verify the final approved list after remediation.

Sample Event

Synthetic impairment scenario. Draco requests a new list location and activation. This assumes unauthorized tuning, but the list contents and completed activation are not shown. The caller address is documentation-only. No top-level error is shown. Exact CloudTrail serialization and optional fields have not been validated by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T21:50:09Z",
"eventSource": "guardduty.amazonaws.com",
"eventName": "UpdateIPSet",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"detectorId": "0123456789abcdef0123456789abcdef",
"ipSetId": "abcdef0123456789abcdef0123456789",
"name": "corp-egress",
"location": "https://s3.amazonaws.com/example-guardduty-lists/corp-egress.txt",
"activate": true
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000111001110",
"eventID": "90000000-0000-4000-8000-000111001111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "guardduty.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.