DeleteFileSystem
DeleteFileSystem
Event
Deletes an EFS file system and removes access to its contents. Mount targets must be deleted first; a file system participating in replication also requires removal of its replication configuration. The call can return while state is deleting, so verify eventual completion.
Security Context
Unauthorized deletion can destroy live file-system data (T1485); planned retirement is common. Independent backups or copies may remain. The request does not prove earlier exfiltration or that every recovery copy was erased.
Log Source
AWS CloudTrail management event with eventSource: elasticfilesystem.amazonaws.com and eventName: DeleteFileSystem. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.fileSystemId | Target file system; inspect ownership, mount targets, and replication. |
errorCode, errorMessage | Prerequisite or authorization failures; null response is not sufficient outcome evidence. |
userIdentity, sourceIPAddress, userAgent | Caller and supporting context; not proof of malicious intent. |
eventTime, awsRegion, recipientAccountId, eventID, requestID | Timeline, scope, and correlation identifiers. |
What to Investigate
- Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
- Check the approved retirement plan and correlate mount-target and replication configuration removal.
- Verify completion and affected applications rather than assuming the first accepted request is final.
- Inventory independent backups and copies. Correlate other deletion events, such as DeleteVolume, only where the same workload is affected.
Sample Event
Synthetic scenario. Draco requests deletion of a fictional EFS file system. The event alone does not contain prerequisite cleanup, prior data theft, or a backup inventory.
Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:28:09Z", "eventSource": "elasticfilesystem.amazonaws.com", "eventName": "DeleteFileSystem", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "fileSystemId": "fs-0123456789abcdef0" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000011100000", "eventID": "90000000-0000-4000-8000-000011100001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "elasticfilesystem.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...