Skip to content

DeleteFileSystem

AWS

DeleteFileSystem

service: AWS - elasticfilesystem
tactics:
techniques:

Event

Deletes an EFS file system and removes access to its contents. Mount targets must be deleted first; a file system participating in replication also requires removal of its replication configuration. The call can return while state is deleting, so verify eventual completion.

Security Context

Unauthorized deletion can destroy live file-system data (T1485); planned retirement is common. Independent backups or copies may remain. The request does not prove earlier exfiltration or that every recovery copy was erased.

Log Source

AWS CloudTrail management event with eventSource: elasticfilesystem.amazonaws.com and eventName: DeleteFileSystem. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.

Key Fields

FieldInvestigation value
requestParameters.fileSystemIdTarget file system; inspect ownership, mount targets, and replication.
errorCode, errorMessagePrerequisite or authorization failures; null response is not sufficient outcome evidence.
userIdentity, sourceIPAddress, userAgentCaller and supporting context; not proof of malicious intent.
eventTime, awsRegion, recipientAccountId, eventID, requestIDTimeline, scope, and correlation identifiers.

What to Investigate

  1. Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
  2. Check the approved retirement plan and correlate mount-target and replication configuration removal.
  3. Verify completion and affected applications rather than assuming the first accepted request is final.
  4. Inventory independent backups and copies. Correlate other deletion events, such as DeleteVolume, only where the same workload is affected.

Sample Event

Synthetic scenario. Draco requests deletion of a fictional EFS file system. The event alone does not contain prerequisite cleanup, prior data theft, or a backup inventory.

Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T21:28:09Z",
"eventSource": "elasticfilesystem.amazonaws.com",
"eventName": "DeleteFileSystem",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"fileSystemId": "fs-0123456789abcdef0"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000011100000",
"eventID": "90000000-0000-4000-8000-000011100001",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "elasticfilesystem.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.