Skip to content

DeleteDeliveryChannel

AWS

DeleteDeliveryChannel

service: AWS - Config
techniques:

Event

Deletes the named Config delivery channel. The customer-managed configuration recorder must be stopped first; a running recorder causes LastDeliveryChannelDeleteFailedException. The channel controls delivery of configuration history and snapshots to S3 and notifications to SNS.

Security Context

Unauthorized deletion can disrupt downstream evidence delivery. Approved destination migration or Config retirement is also possible. Do not interpret the API as deleting the S3 bucket, SNS topic, or copies already delivered there.

The T1685 mapping applies to deliberate defensive impairment; the API name alone does not establish malicious intent.

Log Source

CloudTrail management event with eventSource: config.amazonaws.com and eventName: DeleteDeliveryChannel. Search regional Event history or your retained management-event collection; collection scope and retention determine the available evidence.

Key Fields

FieldInvestigation use
requestParameters.deliveryChannelNameChannel whose prior destinations must be recovered.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the request and correlate with approved work.
awsRegion, recipientAccountIdScope the affected environment.
errorCode, errorMessageCheck rejection before inferring a completed change; null responseElements alone is not proof of success.

What to Investigate

  1. Confirm authorization and outcome, including the running-recorder error.
  2. Correlate the timeline with StopConfigurationRecorder or recorder deletion.
  3. Recover prior S3/SNS destinations and preserve delivered evidence; assess the specific consumers that lost updates.
  4. Verify the replacement channel, delivery status, and recorder state separately after approved restoration.

Sample Event

Synthetic impairment scenario. Draco requests deletion of the default channel. The scenario assumes customer-managed recording was already stopped; that prerequisite is not demonstrated by this single event. No top-level error is shown. Exact CloudTrail serialization and optional fields have not been validated by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:44:21Z",
"eventSource": "config.amazonaws.com",
"eventName": "DeleteDeliveryChannel",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"deliveryChannelName": "default"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000011011010",
"eventID": "90000000-0000-4000-8000-000011011011",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "config.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.