Detects when an EFS file system or mount is deleted. An adversary could break any file system using the mount target that is being deleted, which might disrupt instances or applications using those mounts. The mount must be deleted prior to deleting the file system, or the adversary will be unable to delete the file system.
Rule type: query
Risk score: 47
Runs every: 10m
Maximum alerts per execution: 100
- Continuous Monitoring
- Data Protection
- Austin Songer
Rule license: Elastic License v2
## Config The AWS Fleet integration, Filebeat module, or similarly structured data is required to be compatible with this rule.
event.dataset:aws.cloudtrail and event.provider:elasticfilesystem.amazonaws.com and event.action:(DeleteMountTarget or DeleteFileSystem) and event.outcome:success
Framework: MITRE ATT&CKTM