DeleteDBInstance
DeleteDBInstance
Event
Deletes a DB instance. Deleting an Aurora member instance is not equivalent to deleting its cluster storage; identify the deployment type first. Deletion protection and state prerequisites can block the request. skipFinalSnapshot true omits a new final snapshot; otherwise a final snapshot identifier is required. deleteAutomatedBackups governs automated-backup handling, with service/deployment and AWS Backup policy considerations. Existing manual snapshots are separate.
Security Context
Unauthorized deletion can destroy availability or data (T1485). Routine decommissioning also uses these flags. Skipping a final snapshot does not prove all earlier backups are gone, and a deleting response is not confirmation that deletion has completed.
Log Source
AWS CloudTrail management event with eventSource: rds.amazonaws.com and eventName: DeleteDBInstance. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.dBInstanceIdentifier | Target and deployment type. |
requestParameters.skipFinalSnapshot, finalDBSnapshotIdentifier, deleteAutomatedBackups | Requested recovery handling; examine actual retained backups. |
responseElements | Initial deletion state and protection settings where logged. |
userIdentity, sourceIPAddress, userAgent | Caller and supporting context; not proof of malicious intent. |
eventTime, awsRegion, recipientAccountId, eventID, requestID | Timeline, scope, and correlation identifiers. |
What to Investigate
- Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
- Confirm approval, target dependencies, deployment type, and deletion-protection history.
- Follow the operation to its final state and inspect manual snapshots, automated backups, AWS Backup recovery points, and copies in other Regions/accounts.
- Assess workload disruption and recoverability. Correlate DeleteDBCluster without treating the APIs as interchangeable.
Sample Event
Synthetic scenario. Draco requests deletion with skipFinalSnapshot and deleteAutomatedBackups true. The response is deleting; prior manual snapshots and independent backups are not shown.
Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:14:05Z", "eventSource": "rds.amazonaws.com", "eventName": "DeleteDBInstance", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "dBInstanceIdentifier": "occamy-metadata-prod", "skipFinalSnapshot": true, "deleteAutomatedBackups": true }, "responseElements": { "dBInstanceIdentifier": "occamy-metadata-prod", "dBInstanceClass": "db.r6g.large", "engine": "postgres", "dBInstanceStatus": "deleting", "masterUsername": "occamy_admin", "engineVersion": "15.5", "dBInstanceArn": "arn:aws:rds:us-east-1:555123456789:db:occamy-metadata-prod", "dbiResourceId": "db-OCCAMYMETADATA0PROD01", "deletionProtection": false, "storageEncrypted": true, "kmsKeyId": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000001" }, "requestID": "90000000-0000-4000-8000-000011011000", "eventID": "90000000-0000-4000-8000-000011011001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "rds.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...