AWS ArchiveFindings
Archives specified GuardDuty findings in a regional detector.
The adversary is trying to break security mechanisms, pipelines, and tooling so defenders can’t see or trust what’s happening.
Defense Impairment consists of techniques that degrade, disable, or undermine the effectiveness and trustworthiness of security controls and monitoring mechanisms. These techniques are characterized by direct interference with defensive systems. The goal is to reduce defenders’ ability to detect, interpret, or respond to adversary activity.
In cloud environments, adversaries impair defenses by disabling or deleting logging services (CloudTrail, Azure diagnostic settings, GCP logging sinks), modifying or removing security group and firewall rules, tampering with audit logs, or stopping monitoring services like GuardDuty and Microsoft Defender for Cloud.
Defense Impairment (TA0112) was introduced in ATT&CK v19 (April 2026), when the former Defense Evasion tactic was split into Stealth and Defense Impairment.
View Defense Impairment on MITRE ATT&CK →Explore this tactic in the map.
Archives specified GuardDuty findings in a regional detector.
Authorizes ingress to an RDS DB security group through a legacy networking API.
Adds outbound allow rules to an EC2 security group.
Adds inbound allow rules to an EC2 security group.
Deletes a VPC firewall rule.
Patches an existing VPC firewall rule.
Creates a GuardDuty finding filter, optionally with an automatic archive action.
Creates a GuardDuty trusted IP list and optionally requests activation.
Adds an inbound or outbound allow/deny rule to a VPC network ACL.
Registers an OIDC identity provider in IAM.
Registers SAML identity-provider metadata in IAM.
Deactivates a specified MFA device and removes its association with a user.
Deletes specified CloudWatch alarms in an account and Region.
Deletes an empty S3 bucket, after all object versions and delete markers are removed.
Deletes an AWS Config rule and its evaluation results.
Deletes a customer-managed AWS Config recorder in one Region.
Deletes an AWS Config delivery channel after customer-managed recording is stopped.
Deletes a regional GuardDuty detector, disabling GuardDuty for that account and Region.
Disables a CloudTrail Lake event data store and starts a seven-day deletion window.
Deletes selected VPC Flow Log configurations without deleting their previously delivered log data.
Deletes a CloudWatch Logs group and permanently removes its stored log events.
Deletes a CloudWatch Logs stream and permanently removes its stored events.
Deletes GuardDuty member records from an administrator’s regional detector.
Deletes a nondefault VPC network ACL that has no subnet associations.
Deletes a numbered inbound or outbound rule from a VPC network ACL.
Requests deletion of multiple S3 object keys or specific versions in one batch.
Deletes an AWS WAFv2 rule group identified by name, ID, and scope.
Deletes a CloudTrail trail and stops its future collection without deleting previously delivered logs.
Deletes an unassigned virtual MFA device resource.
Deletes an unassociated AWS WAFv2 web ACL not managed by Firewall Manager.
Legacy API for disassociating a GuardDuty member from its administrator.
Disassociates specified members from a regional GuardDuty administrator.
Changes the mute state of a Security Command Center finding.
Updates an exclusion in a resource’s _Default logging sink.
Deletes a named log’s entries from the global _Default log bucket.
Removes the calling member account from its AWS organization.
Creates an exclusion in a resource’s _Default logging sink.
Deletes a Cloud Logging sink.
Updates a Cloud Logging sink’s configuration.
Requests deletion of an Azure virtual machine.
Deletes an Event Hub entity within an Azure Event Hubs namespace.
Requests removal of an extension from an Azure Arc-enabled server.
Deletes an Azure Monitor activity log alert rule.
Deletes an Azure Monitor diagnostic setting and its configured export routes.
Deletes an Azure Monitor metric alert rule.
Deletes an Azure network security group after its resource associations are removed.
Creates or updates a rule in an Azure network security group.
Deletes an Azure Network Watcher flow-log configuration.
Creates or updates one side of an Azure virtual network peering.
Deletes an Azure Log Analytics workspace, with optional permanent deletion.
Creates or updates a Defender for Cloud alert suppression rule.
Updates the legacy Defender for Cloud agent auto-provisioning setting.
Changes a Microsoft Defender for Cloud plan configuration at a supported scope.
Deletes a Microsoft.Security security solution resource.
Modifies RDS DB instance settings, subject to parameter-specific application rules.
Changes a supported EC2 instance attribute, including user data or security groups.
Creates or replaces an S3 bucket lifecycle configuration.
Configures basic or advanced selectors that determine which events a CloudTrail trail records.
Removes a specified member account from an AWS organization.
Schedules KMS key deletion and makes the pending key unavailable for cryptographic operations.
Updates legacy Security Command Center organization settings through a deprecated API.
Stops the named customer-managed AWS Config recorder from recording its configured resource types.
Stops logging API activity for a CloudTrail trail, disabling audit log collection for that trail.
Suspends GuardDuty monitoring for specified member accounts in a Region.
Disables selected legacy Azure Storage Analytics logging categories.
Updates an existing Microsoft Entra Conditional Access policy.
Updates an Entra Conditional Access named network/location definition.
Records changes to a user’s registered Entra authentication methods.
Replaces an IAM role trust policy, changing the conditions for assuming it.
Updates a regional GuardDuty detector, including its enabled state and protection features.
Updates a GuardDuty trusted IP list configuration and activation request.
Changes a CloudTrail trail configuration, including delivery destinations, regional scope, and log-file validation.
Updates Azure Key Vault properties through a management-plane write.