AWS ArchiveFindings
Archives GuardDuty findings to suppress active security alerts from SOC visibility.
Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
View on MITRE ATT&CK →Archives GuardDuty findings to suppress active security alerts from SOC visibility.
Creates a GuardDuty finding filter that automatically suppresses or highlights findings matching specified criteria.
Creates a GuardDuty IP set — a trusted-IP allowlist whose addresses GuardDuty excludes from findings.
Deletes one or more CloudWatch alarms, removing their monitoring configurations and associated notifications.
Permanently deletes an S3 bucket; the bucket must be empty before deletion can succeed.
Deletes an AWS Config rule that was evaluating the compliance of AWS resource configurations.
Deletes the AWS Config configuration recorder, stopping resource configuration recording in the region.
Deletes the AWS Config delivery channel, stopping delivery of configuration snapshots and change notifications to S3 or SNS.
Disables and permanently deletes a GuardDuty detector in the region, stopping all threat detection.
Removes an IAM user's console password, preventing them from signing in to the AWS Management Console.
Removes member accounts from a GuardDuty administrator account, ending the delegated monitoring relationship.
Deletes an inline policy embedded directly in an IAM role.
Deletes an inline policy embedded directly in an IAM user.
Detaches a managed IAM policy from a role, removing those permissions from the role's effective policy.
Detaches a managed IAM policy from an IAM user, removing those permissions from the user.
Disassociates the current account from its GuardDuty administrator account, ending the delegated monitoring relationship.
Disassociates specified member accounts from a GuardDuty administrator account.
Mutes Security Command Center findings, suppressing security alerts from visibility.
Removes the current member account from its AWS Organization; the management account cannot leave.
Removes an extension from an Azure Arc-enabled server.
Deletes an activity log alert rule, disabling security detection and notification capabilities.
Deletes an Azure Monitor metric alert rule.
Creates or updates a suppression rule in Microsoft Defender for Cloud, hiding matching security alerts.
Modifies auto-provisioning settings, potentially disabling automatic deployment of security monitoring agents.
Changes the pricing tier (plan) for Microsoft Defender for Cloud on a subscription or specific resource type.
Removes a security solution integrated with Microsoft Defender for Cloud.
Removes an AWS account from the organization, stripping it of SCP protections and centralized security controls.
Schedules a KMS customer managed key for deletion after a waiting period (7-30 days), after which encrypted data is unrecoverable.
Updates the settings or configuration of Google Security Command Center for the organization or project.
Stops AWS Config from recording resource configuration changes in the region.
Stops GuardDuty from monitoring specified member accounts under an administrator account.
Updates the configuration of a GuardDuty detector, such as enabling or disabling specific threat detection data sources.
Modifies the IP addresses or CIDR ranges in a GuardDuty trusted-IP set (allowlist), whose entries GuardDuty excludes from findings.