Skip to content

DeleteAlarms

AWS

DeleteAlarms

service: AWS - CloudWatch
techniques:

Event

Deletes the named alarms. Incorrect names do not prevent correctly named alarms in the same request from being deleted. Other syntax errors can prevent all deletion; verify each requested alarm with DescribeAlarms.

Security Context

Unauthorized alarm deletion can remove notifications or automated responses. Approved resource retirement and alarm replacement also use this API. Alarm names alone do not establish their metrics, actions, or security purpose; deletion does not itself erase the underlying logs or metrics.

The T1685 mapping applies to deliberate defensive impairment; the API name alone does not establish malicious intent.

Log Source

CloudTrail management event with eventSource: monitoring.amazonaws.com and eventName: DeleteAlarms. Search regional Event history or your retained management-event collection; collection scope and retention determine the available evidence.

Key Fields

FieldInvestigation use
requestParameters.alarmNamesRequested alarms; recover their definitions to assess impact.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the request and correlate with approved work.
awsRegion, recipientAccountIdScope the affected environment.
errorCode, errorMessageCheck rejection before inferring a completed change; null responseElements alone is not proof of success.

What to Investigate

  1. Confirm approval and inspect errors, then verify deletion per alarm rather than treating the batch as all-or-nothing.
  2. Recover metric or composite definitions, action targets, and dependencies from retained configuration.
  3. Check overlapping alarms and downstream workflows to identify the actual response gap.
  4. Correlate with DeleteLogGroup and verify replacement alarms and their actions after restoration.

Sample Event

Synthetic impairment scenario. Draco requests deletion of three alarms in account 555123456789. Their names are fictional labels, not proof that they monitor another account or detect the behaviors claimed by those labels. No top-level error is shown. Exact CloudTrail serialization and optional fields have not been validated by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:33:21Z",
"eventSource": "monitoring.amazonaws.com",
"eventName": "DeleteAlarms",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"alarmNames": [
"phoenix-root-login-detected",
"phoenix-iam-policy-change",
"phoenix-console-mfa-failure-spike"
]
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000011001100",
"eventID": "90000000-0000-4000-8000-000011001101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "monitoring.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.