Skip to content

DeleteBucketPolicy

AWS

DeleteBucketPolicy

service: AWS - S3
tactics:
techniques:

Event

Removes the bucket’s resource-based policy. Other applicable authorization controls remain. Deleting explicit denies can broaden access where another valid grant exists, while deleting allow statements can remove access. It does not automatically make a bucket public or grant cross-account reads.

Security Context

Unauthorized policy removal can precede access to stored data; approved policy replacement is also common. The T1530 collection mapping is contextual to a sequence with actual object access, not a claim that this operation collected data. Recover the prior policy and evaluate the full authorization path.

Log Source

CloudTrail management event with eventSource: s3.amazonaws.com and eventName: DeleteBucketPolicy. Search regional Event history or retained management-event logs, accounting for collection scope and retention.

Key Fields

FieldInvestigation use
requestParameters.bucketName, resourcesAffected bucket.
userIdentity.accountId, recipientAccountIdCaller and resource-account context; do not infer a later cross-account grant.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the request and compare with approved work.
awsRegion, recipientAccountIdScope the account and regional context.
errorCode, errorMessageDistinguish rejection from an apparent completed request; verify actual state.

What to Investigate

  1. Confirm approval and inspect errors. Recover the previous policy from retained configuration or change records.
  2. Separate removed allows from denies and evaluate applicable IAM, Organizations, endpoint, access-point, public-access, ACL, and encryption controls.
  3. Verify current policy state and any immediate replacement; do not interpret policy absence as public access.
  4. Correlate with PutBucketPolicy and object-access evidence. CloudTrail GetObject data events require appropriate data-event collection and are not established by this management event.

Sample Event

Synthetic scenario. Draco requests deletion of a fictional bucket policy. The policy statements are absent, so this record cannot establish whether access broadened or narrowed, or whether subsequent cross-account GetObject calls succeeded. No top-level error is shown. Exact CloudTrail serialization and optional fields remain unverified by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:14:02Z",
"eventSource": "s3.amazonaws.com",
"eventName": "DeleteBucketPolicy",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"bucketName": "fantasticlogs-niffler-archive",
"Host": "fantasticlogs-niffler-archive.s3.us-east-1.amazonaws.com"
},
"responseElements": null,
"additionalEventData": {
"SignatureVersion": "SigV4",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"bytesTransferredIn": 0,
"AuthenticationMethod": "AuthHeader",
"bytesTransferredOut": 0
},
"requestID": "90000000-0000-4000-8000-000011010000",
"eventID": "90000000-0000-4000-8000-000011010001",
"readOnly": false,
"resources": [
{
"accountId": "555123456789",
"type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::fantasticlogs-niffler-archive"
}
],
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "fantasticlogs-niffler-archive.s3.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Collection

Techniques:
  • T1530 — Data from Cloud Storage — Adversaries may access data from cloud storage.
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.