Skip to content

DeleteAccessKey

AWS

DeleteAccessKey

service: AWS - IAM
tactics:
techniques:

Event

Deletes the specified long-term access key; it cannot later be reactivated. This operation does not target an ASIA temporary-session key. If userName is omitted, IAM determines the user from the signing credentials as documented by the API.

Security Context

Unauthorized deletion can disrupt workloads or operators relying on the key (T1531). Planned rotation commonly removes old keys. Other keys, console access, and already-issued sessions require separate assessment. Avoid claiming instantaneous universal lockout from one key operation.

Log Source

AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: DeleteAccessKey. Check errorCode and errorMessage; a null response alone does not establish success or failure. Include IAM global-service events in collection.

Key Fields

FieldInvestigation value
requestParameters.accessKeyIdTarget long-term key; distinguish it from the caller’s key.
requestParameters.userNameKey owner when specified; may differ from the caller.
eventTime, recipientAccountId, eventID, requestIDTimeline and correlation identifiers.
sourceIPAddress, userAgentSupporting context, not a definitive attacker fingerprint.

What to Investigate

  1. Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
  2. Recover ownership, prior status, last-use evidence, and the approved rotation or incident record.
  3. Correlate CreateAccessKey and dependent workload authentication failures; do not invent a replacement key.
  4. Check other credentials and issued sessions separately. Deletion cannot be reversed by UpdateAccessKey.

Sample Event

Synthetic scenario. Hermione deletes a key for ron. A replacement key and completed workload migration are not shown.

Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDAHERM10NE000ADM1N",
"arn": "arn:aws:iam::555123456789:user/hermione",
"accountId": "555123456789",
"accessKeyId": "ASIAHERM10NEEXAMPLE1",
"userName": "hermione",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T14:02:33Z",
"mfaAuthenticated": "true"
}
}
},
"eventTime": "2026-04-15T14:21:09Z",
"eventSource": "iam.amazonaws.com",
"eventName": "DeleteAccessKey",
"awsRegion": "us-east-1",
"sourceIPAddress": "198.51.100.42",
"userAgent": "aws-cli/2.15.30 Python/3.11.6 Linux/5.15.0-1052-aws exe/x86_64.ubuntu.22 prompt/off command/iam.delete-access-key",
"requestParameters": {
"userName": "ron",
"accessKeyId": "AKIAR0NWEA5LEYEXAMP2"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000011001010",
"eventID": "90000000-0000-4000-8000-000011001011",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1531 — Account Access Removal — Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts....
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.