This data component refers to monitoring actions that deactivate or stop a cloud service in a cloud control plane. Examples include disabling essential logging services like AWS CloudTrail (StopLogging API call), Microsoft Azure Monitor Logs, or Google Cloud's Operations Suite (formerly Stackdriver). Disabling such services can hinder visibility into adversary activities within the cloud environment. Examples:
| Name | Channel |
|---|---|
| AWS:CloudTrail | Stop logging for an existing CloudTrail |
| AWS:CloudTrail | Removal of CloudTrail trail |
| AWS:CloudTrail | StopLogging, DeleteTrail, or DisableSecurityService |
| azure:activity | az monitor diagnostic-settings delete |
| saas:audit | Log export integration removed or disabled |