DeleteBucket
DeleteBucket
Event
Deletes a bucket only after it is empty, including object versions and delete markers. This operation does not empty the bucket. Establish earlier object deletion or expiration separately.
Security Context
Unauthorized removal can disrupt a logging destination (T1685.002) and accompany a data-destruction sequence (T1485). Approved retirement is also routine. The bucket name alone does not prove its contents, and deletion does not erase independent copies or itself stop a CloudTrail trail.
The mapping describes a possible adversarial sequence, not a verdict on every occurrence.
Log Source
CloudTrail management event with eventSource: s3.amazonaws.com and eventName: DeleteBucket. Check collection scope and retention before interpreting absent records.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.bucketName, resources | Target bucket; recover its previous purpose and configuration. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the caller and correlate with approved work. |
recipientAccountId, awsRegion | Account and recording Region; distinguish caller, target, and resource scope. |
errorCode, errorMessage | Check request failures and confirm resulting state; null response alone is not proof of success. |
What to Investigate
- Confirm approval and inspect failures such as BucketNotEmpty. Verify the actual outcome.
- Reconstruct earlier DeleteObjects or lifecycle changes and version history.
- Determine dependent producers and retained copies outside the bucket; separate destination failure from trail status.
- Correlate with StopLogging and verify restored delivery and evidence coverage through the approved recovery process.
Sample Event
Synthetic scenario. Draco requests deletion of a fictional log bucket assumed already empty. Prior log deletion and trail changes are not shown; this request alone is not proof of data destruction. No top-level error is shown. Exact CloudTrail serialization and optional identity/session fields remain unverified by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:48:55Z", "eventSource": "s3.amazonaws.com", "eventName": "DeleteBucket", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "bucketName": "fantasticlogs-cloudtrail", "Host": "fantasticlogs-cloudtrail.s3.us-east-1.amazonaws.com" }, "responseElements": null, "additionalEventData": { "SignatureVersion": "SigV4", "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "bytesTransferredIn": 0, "AuthenticationMethod": "AuthHeader", "bytesTransferredOut": 0 }, "requestID": "90000000-0000-4000-8000-000011001110", "eventID": "90000000-0000-4000-8000-000011001111", "readOnly": false, "resources": [ { "accountId": "555123456789", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::fantasticlogs-cloudtrail" } ], "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "fantasticlogs-cloudtrail.s3.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Impact Defense Impairment
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
- T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...