AWS DeleteEventDataStore
Deletes a CloudTrail Lake event data store, destroying stored forensic evidence and audit logs.
An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...
View on MITRE ATT&CK →Deletes a CloudTrail Lake event data store, destroying stored forensic evidence and audit logs.
Permanently deletes a CloudWatch Logs log group and all its log streams and stored data.
Permanently deletes a log stream and all its events from within a CloudWatch Logs log group.
Permanently deletes a CloudTrail trail, stopping API activity logging for that trail configuration.
Modifies a logging exclusion filter to silently drop specific log entries, hiding ongoing attacker activity.
Deletes a Cloud Logging sink that was routing log entries to a destination such as Cloud Storage or BigQuery.
Modifies a Cloud Logging sink's configuration, such as its destination or log filter criteria.
Permanently deletes a Log Analytics workspace and its stored data.
Stops logging for an Azure Storage account, disabling the collection of storage analytics logs.
Configures which API events (management or data, read/write) a CloudTrail trail records.
Stops logging API activity for a CloudTrail trail, disabling audit log collection for that trail.
Modifies the configuration of an existing CloudTrail trail, such as its S3 bucket, log validation, or multi-region settings.