DeleteDeliveryChannel
DeleteDeliveryChannel
Event
Deletes the named Config delivery channel. The customer-managed configuration recorder must be stopped first; a running recorder causes LastDeliveryChannelDeleteFailedException. The channel controls delivery of configuration history and snapshots to S3 and notifications to SNS.
Security Context
Unauthorized deletion can disrupt downstream evidence delivery. Approved destination migration or Config retirement is also possible. Do not interpret the API as deleting the S3 bucket, SNS topic, or copies already delivered there.
The T1685 mapping applies to deliberate defensive impairment; the API name alone does not establish malicious intent.
Log Source
CloudTrail management event with eventSource: config.amazonaws.com and eventName: DeleteDeliveryChannel. Search regional Event history or your retained management-event collection; collection scope and retention determine the available evidence.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.deliveryChannelName | Channel whose prior destinations must be recovered. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the request and correlate with approved work. |
awsRegion, recipientAccountId | Scope the affected environment. |
errorCode, errorMessage | Check rejection before inferring a completed change; null responseElements alone is not proof of success. |
What to Investigate
- Confirm authorization and outcome, including the running-recorder error.
- Correlate the timeline with StopConfigurationRecorder or recorder deletion.
- Recover prior S3/SNS destinations and preserve delivered evidence; assess the specific consumers that lost updates.
- Verify the replacement channel, delivery status, and recorder state separately after approved restoration.
Sample Event
Synthetic impairment scenario. Draco requests deletion of the default channel. The scenario assumes customer-managed recording was already stopped; that prerequisite is not demonstrated by this single event. No top-level error is shown. Exact CloudTrail serialization and optional fields have not been validated by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:44:21Z", "eventSource": "config.amazonaws.com", "eventName": "DeleteDeliveryChannel", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "deliveryChannelName": "default" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000011011010", "eventID": "90000000-0000-4000-8000-000011011011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "config.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...