Skip to content

DeleteConfigRule

AWS

DeleteConfigRule

service: AWS - Config
techniques:

Event

Deletes the named rule and its evaluation results in the account and Region. Deletion is asynchronous: the rule enters DELETING before removal completes. This does not itself stop the configuration recorder or delete every resource’s history.

Security Context

Unauthorized removal can impair a compliance check. Approved rule replacement or retirement is also legitimate. A rule name does not prove its source, scope, or remediation behavior, and other controls may still detect or block the underlying change.

The T1685 mapping applies to deliberate defensive impairment; the API name alone does not establish malicious intent.

Log Source

CloudTrail management event with eventSource: config.amazonaws.com and eventName: DeleteConfigRule. Search regional Event history or your retained management-event collection; collection scope and retention determine the available evidence.

Key Fields

FieldInvestigation use
requestParameters.configRuleNameRule to compare with its prior definition.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the request and correlate with approved work.
awsRegion, recipientAccountIdScope the affected environment.
errorCode, errorMessageCheck rejection before inferring a completed change; null responseElements alone is not proof of success.

What to Investigate

  1. Confirm approval and inspect errors, including ResourceInUseException when an associated remediation prevents deletion.
  2. Recover the previous rule source, parameters, resource scope, and remediation configuration from retained records or infrastructure code.
  3. Use DescribeConfigRules to assess DELETING versus completed removal and check replacement coverage.
  4. Correlate with DeleteConfigurationRecorder and review retained compliance evidence for the affected resources.

Sample Event

Synthetic impairment scenario. Draco requests deletion of a rule named s3-bucket-public-read-prohibited. Its name suggests a purpose but does not prove its definition or guarantee subsequent public-access changes evade all controls. No top-level error is shown. Exact CloudTrail serialization and optional fields have not been validated by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:41:18Z",
"eventSource": "config.amazonaws.com",
"eventName": "DeleteConfigRule",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"configRuleName": "s3-bucket-public-read-prohibited"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000011010010",
"eventID": "90000000-0000-4000-8000-000011010011",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "config.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.