Skip to content

DeleteBucket

AWS

DeleteBucket

service: AWS - S3
techniques:

Event

Deletes a bucket only after it is empty, including object versions and delete markers. This operation does not empty the bucket. Establish earlier object deletion or expiration separately.

Security Context

Unauthorized removal can disrupt a logging destination (T1685.002) and accompany a data-destruction sequence (T1485). Approved retirement is also routine. The bucket name alone does not prove its contents, and deletion does not erase independent copies or itself stop a CloudTrail trail.

The mapping describes a possible adversarial sequence, not a verdict on every occurrence.

Log Source

CloudTrail management event with eventSource: s3.amazonaws.com and eventName: DeleteBucket. Check collection scope and retention before interpreting absent records.

Key Fields

FieldInvestigation use
requestParameters.bucketName, resourcesTarget bucket; recover its previous purpose and configuration.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the caller and correlate with approved work.
recipientAccountId, awsRegionAccount and recording Region; distinguish caller, target, and resource scope.
errorCode, errorMessageCheck request failures and confirm resulting state; null response alone is not proof of success.

What to Investigate

  1. Confirm approval and inspect failures such as BucketNotEmpty. Verify the actual outcome.
  2. Reconstruct earlier DeleteObjects or lifecycle changes and version history.
  3. Determine dependent producers and retained copies outside the bucket; separate destination failure from trail status.
  4. Correlate with StopLogging and verify restored delivery and evidence coverage through the approved recovery process.

Sample Event

Synthetic scenario. Draco requests deletion of a fictional log bucket assumed already empty. Prior log deletion and trail changes are not shown; this request alone is not proof of data destruction. No top-level error is shown. Exact CloudTrail serialization and optional identity/session fields remain unverified by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:48:55Z",
"eventSource": "s3.amazonaws.com",
"eventName": "DeleteBucket",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"bucketName": "fantasticlogs-cloudtrail",
"Host": "fantasticlogs-cloudtrail.s3.us-east-1.amazonaws.com"
},
"responseElements": null,
"additionalEventData": {
"SignatureVersion": "SigV4",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"bytesTransferredIn": 0,
"AuthenticationMethod": "AuthHeader",
"bytesTransferredOut": 0
},
"requestID": "90000000-0000-4000-8000-000011001110",
"eventID": "90000000-0000-4000-8000-000011001111",
"readOnly": false,
"resources": [
{
"accountId": "555123456789",
"type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::fantasticlogs-cloudtrail"
}
],
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "fantasticlogs-cloudtrail.s3.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact Defense Impairment

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
  • T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.