elastic
high
kql
AWS GuardDuty Member Account Manipulation
Detects attempts to disassociate or manipulate Amazon GuardDuty member accounts within an AWS organization. In
multi-account GuardDuty deployments, a delegated administrator account aggregates findings from member accounts.
Adversaries may attempt to disassociate member accounts, delete member relationships, stop monitoring members, or delete
pending invitations to break this centralized visibility. These actions can be precursors to or alternatives for
deleting GuardDuty detectors entirely, all