Skip to content

DeleteEventDataStore

AWS

DeleteEventDataStore

service: AWS - CloudTrail
techniques:

Event

Places a CloudTrail Lake event data store into PENDING_DELETION, with automatic deletion after seven days. Termination protection must be off and federation disabled; other dependencies can also block the request. RestoreEventDataStore can restore it within the waiting period.

Security Context

Unauthorized deletion can impair audit access and ultimately destroy stored evidence (T1685.002). Approved retirement or migration is also possible. Pending deletion restricts query operations, but is not immediate irreversible erasure. The ARN’s Region does not establish the store’s full collection scope or retention.

The mapping describes a possible adversarial sequence, not a verdict on every occurrence.

Log Source

CloudTrail management event with eventSource: cloudtrail.amazonaws.com and eventName: DeleteEventDataStore. Check collection scope and retention before interpreting absent records.

Key Fields

FieldInvestigation use
requestParameters.eventDataStoreStore ARN or ID; recover collection and retention settings.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the caller and correlate with approved work.
recipientAccountId, awsRegionAccount and recording Region; distinguish caller, target, and resource scope.
errorCode, errorMessageCheck request failures and confirm resulting state; null response alone is not proof of success.

What to Investigate

  1. Confirm approval and inspect errors for termination protection, federation, channels, or ongoing imports.
  2. Verify current store status and establish the deletion deadline; use approved restoration within seven days if required.
  3. Recover organization/multi-Region scope, selectors, retention, and previous changes that enabled deletion.
  4. Correlate with DeleteTrail and verify restored ingestion/query access plus independent evidence copies.

Sample Event

Synthetic scenario. Draco requests deletion of a fictional store. Its seven-day retention, prior contents, and successful final deletion are not demonstrated. The recovery window is distinct from configured data retention. No top-level error is shown. Exact CloudTrail serialization and optional identity/session fields remain unverified by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:36:18Z",
"eventSource": "cloudtrail.amazonaws.com",
"eventName": "DeleteEventDataStore",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"eventDataStore": "arn:aws:cloudtrail:us-east-1:555123456789:eventdatastore/60000000-0000-4000-8000-000100000000"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000011011110",
"eventID": "90000000-0000-4000-8000-000011011111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "cloudtrail.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.