Skip to content

DeleteFlowLogs

AWS

DeleteFlowLogs

service: AWS - EC2
techniques:

Event

DeleteFlowLogs requests deletion of one or more flow-log configurations. Inspect the response’s unsuccessful items: a request can include flow logs that could not be deleted. A dry-run permission check is not a deletion. AWS API reference.

Security Context

Unexpected removal can reduce network evidence for the resources covered by those configurations. Recover the resource scope and destination for each flow-log ID before judging the impact.

Legitimate uses: retiring a resource or replacing a flow log to change its configuration or record format. Look for the approved replacement and compare its coverage. Flow-log limitations.

Mapping rationale: malicious removal of network-log collection fits Disable or Modify Cloud Log. Deletion alone does not show that subsequent network activity was malicious.

Log Source

Search CloudTrail management events for eventSource: ec2.amazonaws.com and eventName: DeleteFlowLogs. The CloudTrail API record and the traffic records produced by VPC Flow Logs are different evidence sources; retain write management events to investigate the configuration change.

Collection boundary: deletion does not remove existing destination data or the destination resource, and collection can take several minutes to stop. Deletion behavior.

VPC Flow Logs already exclude traffic to and from the instance metadata address 169.254.169.254. Do not claim that deleting a flow log newly hides metadata requests, or that it removes every possible network evidence source. Traffic exclusions.

Key Fields

FieldInvestigation use
requestParametersExtract every requested flow-log ID; verify the nesting in your collected records rather than assuming one universal serialization.
responseElementsInspect unsuccessful items and reconcile the outcome for each requested ID.
errorCode and errorMessageSeparate denied requests and dry-run results from actual deletion.
userIdentity.arn and userIdentity.sessionContextIdentify the actor and any role session.
eventTime, awsRegion, and recipientAccountIdEstablish where and when to recover configuration and traffic evidence.

What to Investigate

  1. Resolve the flow-log IDs to their VPC, subnet, or network-interface scope using prior inventory or deployment records. The deletion request alone does not identify all affected traffic.
  2. Check each result and the current inventory. Compare any replacement configuration’s resource scope, traffic selection, format, and destination.
  3. Preserve existing destination records and determine when delivery actually stopped. Check overlapping flow-log configurations and independent network telemetry before estimating a gap.
  4. Trace the caller and correlate other visibility changes, such as StopLogging or UpdateTrail. Investigate relevant resource activity during the gap without claiming absent telemetry proves no activity occurred.

Sample Event

Synthetic scenario — removed network collection. Draco requests deletion of fl-0123456789abcdef0. The resource scope and destination must be resolved separately. This example retains an illustrative EC2 Query-style request/response wrapper; exact CloudTrail nesting and the representation of an empty unsuccessful result require validation against a captured event.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:09:51Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "DeleteFlowLogs",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"DeleteFlowLogsRequest": {
"FlowLogId": {
"tag": 1,
"content": "fl-0123456789abcdef0"
}
}
},
"responseElements": {
"DeleteFlowLogsResponse": {
"xmlns": "http://ec2.amazonaws.com/doc/2016-11-15/",
"unsuccessful": ""
}
},
"requestID": "90000000-0000-4000-8000-000011100010",
"eventID": "90000000-0000-4000-8000-000011100011",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.