Skip to content

DeleteDetector

AWS

DeleteDetector

service: AWS - GuardDuty
techniques:

Event

DeleteDetector deletes the specified GuardDuty detector in the account and Region. Disabling GuardDuty stops its monitoring there and loses the service’s existing findings and configuration. It does not establish that other Regions or independent security tools are disabled.

Security Context

An attacker may delete a detector to impair threat detection. An approved account shutdown or service retirement can produce the same event. T1685 describes the defensive-tool impairment behavior, not a verdict on the caller.

Deletion differs from suspension through UpdateDetector: suspension retains existing findings. After disabling, re-enabling GuardDuty does not restore its lost findings or configuration. Look for copies exported before deletion. In multi-account environments, inspect administrator/member relationships; AWS requires member accounts to be disassociated or deleted before suspension or disabling.

Log Source

CloudTrail management event with eventSource: guardduty.amazonaws.com and eventName: DeleteDetector. GuardDuty control-plane API calls are recorded by CloudTrail. Search Event history or your retained management-event collection; deleting the detector is not itself a request to stop CloudTrail delivery.

Key Fields

FieldInvestigation use
requestParameters.detectorIdIdentify the regional detector.
awsRegion, recipientAccountIdScope the deletion; do not assume organization-wide impact.
userIdentityTrace the principal and session behind the request.
eventTime, sourceIPAddress, userAgentCorrelate with change records and other caller activity.
errorCode, errorMessageDistinguish rejected requests from apparent success; confirm actual detector state.

What to Investigate

  1. Check authorization and request errors. Use ListDetectors in the affected account and Region to verify current state.
  2. Recover the previous detector settings and account relationships from retained records. Check other Regions independently.
  3. Preserve any previously exported findings from S3 or downstream systems. Establish the interval between deletion and verified restoration of protection.
  4. Correlate with UpdateDetector and StopLogging, then review available evidence for activity during the coverage gap.

Sample Event

Synthetic impairment scenario. Draco requests deletion of a fictional GuardDuty detector in us-east-1. No error fields are shown. The sample cannot demonstrate the previous feature configuration, retained external findings, or protection in other Regions. Exact CloudTrail serialization and optional fields remain unverified by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:18:54Z",
"eventSource": "guardduty.amazonaws.com",
"eventName": "DeleteDetector",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"detectorId": "0123456789abcdef0123456789abcdef"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000011011100",
"eventID": "90000000-0000-4000-8000-000011011101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "guardduty.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.