DeleteBucketPolicy
DeleteBucketPolicy
Event
Removes the bucket’s resource-based policy. Other applicable authorization controls remain. Deleting explicit denies can broaden access where another valid grant exists, while deleting allow statements can remove access. It does not automatically make a bucket public or grant cross-account reads.
Security Context
Unauthorized policy removal can precede access to stored data; approved policy replacement is also common. The T1530 collection mapping is contextual to a sequence with actual object access, not a claim that this operation collected data. Recover the prior policy and evaluate the full authorization path.
Log Source
CloudTrail management event with eventSource: s3.amazonaws.com and eventName: DeleteBucketPolicy. Search regional Event history or retained management-event logs, accounting for collection scope and retention.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.bucketName, resources | Affected bucket. |
userIdentity.accountId, recipientAccountId | Caller and resource-account context; do not infer a later cross-account grant. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the request and compare with approved work. |
awsRegion, recipientAccountId | Scope the account and regional context. |
errorCode, errorMessage | Distinguish rejection from an apparent completed request; verify actual state. |
What to Investigate
- Confirm approval and inspect errors. Recover the previous policy from retained configuration or change records.
- Separate removed allows from denies and evaluate applicable IAM, Organizations, endpoint, access-point, public-access, ACL, and encryption controls.
- Verify current policy state and any immediate replacement; do not interpret policy absence as public access.
- Correlate with PutBucketPolicy and object-access evidence. CloudTrail GetObject data events require appropriate data-event collection and are not established by this management event.
Sample Event
Synthetic scenario. Draco requests deletion of a fictional bucket policy. The policy statements are absent, so this record cannot establish whether access broadened or narrowed, or whether subsequent cross-account GetObject calls succeeded. No top-level error is shown. Exact CloudTrail serialization and optional fields remain unverified by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:14:02Z", "eventSource": "s3.amazonaws.com", "eventName": "DeleteBucketPolicy", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "bucketName": "fantasticlogs-niffler-archive", "Host": "fantasticlogs-niffler-archive.s3.us-east-1.amazonaws.com" }, "responseElements": null, "additionalEventData": { "SignatureVersion": "SigV4", "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "bytesTransferredIn": 0, "AuthenticationMethod": "AuthHeader", "bytesTransferredOut": 0 }, "requestID": "90000000-0000-4000-8000-000011010000", "eventID": "90000000-0000-4000-8000-000011010001", "readOnly": false, "resources": [ { "accountId": "555123456789", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::fantasticlogs-niffler-archive" } ], "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "fantasticlogs-niffler-archive.s3.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Collection
- T1530 — Data from Cloud Storage — Adversaries may access data from cloud storage.