Skip to content

DeleteConfigurationRecorder

AWS

DeleteConfigurationRecorder

service: AWS - Config
techniques:

Event

DeleteConfigurationRecorder deletes the named customer-managed AWS Config recorder in the account and Region. It does not delete service-linked recorders; those use a separate API.

Security Context

Removing a recorder can impair visibility into subsequent changes to the resource types it covered. Approved service retirement or recorder replacement can also explain this action. The T1685 mapping applies when deletion is used to impair a defensive tool; the API name alone does not establish malicious intent.

Previously recorded configuration is retained. GetResourceConfigHistory can still retrieve it, although the Config console cannot display that history until a new customer-managed recorder is created. Avoid treating this event as proof that all configuration evidence or every compliance evaluation has disappeared.

Log Source

CloudTrail management event with eventSource: config.amazonaws.com and eventName: DeleteConfigurationRecorder. Search the affected account and Region and check your collection coverage and retention. Deleting a Config recorder does not itself disable CloudTrail.

Key Fields

FieldInvestigation use
userIdentityIdentify the caller and any session context.
awsRegion, recipientAccountIdScope the affected environment.
requestParameters.configurationRecorderNameIdentify the recorder to compare with its previous configuration.
eventTime, sourceIPAddress, userAgentCorrelate the request with approved work and adjacent activity.
errorCode, errorMessageCheck for a failed request; a null response alone is not an outcome check.

What to Investigate

  1. Confirm authorization with the service owner and inspect any error fields before treating the deletion as successful.
  2. Recover the recorder’s previous resource scope from configuration records or infrastructure code. Check separately for remaining service-linked recording.
  3. Retrieve retained resource history and identify which investigations or compliance processes depended on fresh records from this recorder.
  4. Correlate with StopConfigurationRecorder and StopLogging. Verify replacement recording is actually running and establish the coverage gap.

Sample Event

Synthetic impairment scenario. Draco requests deletion of the customer-managed default recorder in us-east-1. The illustration includes no error fields, but does not establish the recorder’s previous coverage or the status of other recorders. Exact CloudTrail serialization and optional fields have not been validated by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:43:02Z",
"eventSource": "config.amazonaws.com",
"eventName": "DeleteConfigurationRecorder",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"configurationRecorderName": "default"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000011010100",
"eventID": "90000000-0000-4000-8000-000011010101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "config.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.