DeleteConfigurationRecorder
DeleteConfigurationRecorder
Event
DeleteConfigurationRecorder deletes the named customer-managed AWS Config recorder in the account and Region. It does not delete service-linked recorders; those use a separate API.
Security Context
Removing a recorder can impair visibility into subsequent changes to the resource types it covered. Approved service retirement or recorder replacement can also explain this action. The T1685 mapping applies when deletion is used to impair a defensive tool; the API name alone does not establish malicious intent.
Previously recorded configuration is retained. GetResourceConfigHistory can still retrieve it, although the Config console cannot display that history until a new customer-managed recorder is created. Avoid treating this event as proof that all configuration evidence or every compliance evaluation has disappeared.
Log Source
CloudTrail management event with eventSource: config.amazonaws.com and eventName: DeleteConfigurationRecorder. Search the affected account and Region and check your collection coverage and retention. Deleting a Config recorder does not itself disable CloudTrail.
Key Fields
| Field | Investigation use |
|---|---|
userIdentity | Identify the caller and any session context. |
awsRegion, recipientAccountId | Scope the affected environment. |
requestParameters.configurationRecorderName | Identify the recorder to compare with its previous configuration. |
eventTime, sourceIPAddress, userAgent | Correlate the request with approved work and adjacent activity. |
errorCode, errorMessage | Check for a failed request; a null response alone is not an outcome check. |
What to Investigate
- Confirm authorization with the service owner and inspect any error fields before treating the deletion as successful.
- Recover the recorder’s previous resource scope from configuration records or infrastructure code. Check separately for remaining service-linked recording.
- Retrieve retained resource history and identify which investigations or compliance processes depended on fresh records from this recorder.
- Correlate with StopConfigurationRecorder and StopLogging. Verify replacement recording is actually running and establish the coverage gap.
Sample Event
Synthetic impairment scenario. Draco requests deletion of the customer-managed default recorder in us-east-1. The illustration includes no error fields, but does not establish the recorder’s previous coverage or the status of other recorders. Exact CloudTrail serialization and optional fields have not been validated by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:43:02Z", "eventSource": "config.amazonaws.com", "eventName": "DeleteConfigurationRecorder", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "configurationRecorderName": "default" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000011010100", "eventID": "90000000-0000-4000-8000-000011010101", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "config.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...