Skip to content

DeleteDBInstance

AWS

DeleteDBInstance

service: AWS - RDS
tactics:
techniques:

Event

Deletes a DB instance. Deleting an Aurora member instance is not equivalent to deleting its cluster storage; identify the deployment type first. Deletion protection and state prerequisites can block the request. skipFinalSnapshot true omits a new final snapshot; otherwise a final snapshot identifier is required. deleteAutomatedBackups governs automated-backup handling, with service/deployment and AWS Backup policy considerations. Existing manual snapshots are separate.

Security Context

Unauthorized deletion can destroy availability or data (T1485). Routine decommissioning also uses these flags. Skipping a final snapshot does not prove all earlier backups are gone, and a deleting response is not confirmation that deletion has completed.

Log Source

AWS CloudTrail management event with eventSource: rds.amazonaws.com and eventName: DeleteDBInstance. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.

Key Fields

FieldInvestigation value
requestParameters.dBInstanceIdentifierTarget and deployment type.
requestParameters.skipFinalSnapshot, finalDBSnapshotIdentifier, deleteAutomatedBackupsRequested recovery handling; examine actual retained backups.
responseElementsInitial deletion state and protection settings where logged.
userIdentity, sourceIPAddress, userAgentCaller and supporting context; not proof of malicious intent.
eventTime, awsRegion, recipientAccountId, eventID, requestIDTimeline, scope, and correlation identifiers.

What to Investigate

  1. Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
  2. Confirm approval, target dependencies, deployment type, and deletion-protection history.
  3. Follow the operation to its final state and inspect manual snapshots, automated backups, AWS Backup recovery points, and copies in other Regions/accounts.
  4. Assess workload disruption and recoverability. Correlate DeleteDBCluster without treating the APIs as interchangeable.

Sample Event

Synthetic scenario. Draco requests deletion with skipFinalSnapshot and deleteAutomatedBackups true. The response is deleting; prior manual snapshots and independent backups are not shown.

Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T21:14:05Z",
"eventSource": "rds.amazonaws.com",
"eventName": "DeleteDBInstance",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"dBInstanceIdentifier": "occamy-metadata-prod",
"skipFinalSnapshot": true,
"deleteAutomatedBackups": true
},
"responseElements": {
"dBInstanceIdentifier": "occamy-metadata-prod",
"dBInstanceClass": "db.r6g.large",
"engine": "postgres",
"dBInstanceStatus": "deleting",
"masterUsername": "occamy_admin",
"engineVersion": "15.5",
"dBInstanceArn": "arn:aws:rds:us-east-1:555123456789:db:occamy-metadata-prod",
"dbiResourceId": "db-OCCAMYMETADATA0PROD01",
"deletionProtection": false,
"storageEncrypted": true,
"kmsKeyId": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000001"
},
"requestID": "90000000-0000-4000-8000-000011011000",
"eventID": "90000000-0000-4000-8000-000011011001",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "rds.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.