Skip to content

DeleteLogStream

AWS

DeleteLogStream

service: AWS - CloudWatchLogs
techniques:

Event

Deletes the named log stream and its stored events within a log group. It does not delete the parent group or other streams. Any independent copies and subsequent producer activity must be checked separately.

Security Context

Unauthorized stream deletion can remove evidence from a specific source or interval. Approved cleanup is also possible. The narrower scope does not establish that the operation evades alerts, and an existing parent group does not establish that historical evidence is intact.

The T1685.002 mapping applies to deliberate defensive impairment; the API name alone does not establish malicious intent.

Log Source

CloudTrail management event with eventSource: logs.amazonaws.com and eventName: DeleteLogStream. Search regional Event history or your retained management-event collection; collection scope and retention determine the available evidence.

Key Fields

FieldInvestigation use
requestParameters.logGroupName, requestParameters.logStreamNameTogether identify the deleted stream.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the request and correlate with approved work.
awsRegion, recipientAccountIdScope the affected environment.
errorCode, errorMessageCheck rejection before inferring a completed change; null responseElements alone is not proof of success.

What to Investigate

  1. Confirm authorization and inspect errors; verify the stream’s current state and any recreation.
  2. Identify its producer and actual event interval from retained metadata, not just the stream name.
  3. Compare sibling streams, exports, and independent destinations to assess the evidence gap.
  4. Correlate with DeleteLogGroup and check resumed ingestion. A newly created stream with the same name does not restore deleted events.

Sample Event

Synthetic impairment scenario. Draco requests deletion of one fictional stream in a CloudTrail destination group. The name is illustrative, not a verified CloudTrail naming convention or proof of its contents. No claim is made about whether a defender alerts on the request. No top-level error is shown. Exact CloudTrail serialization and optional fields have not been validated by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:18:12Z",
"eventSource": "logs.amazonaws.com",
"eventName": "DeleteLogStream",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"logGroupName": "fantasticlogs-cloudtrail-management",
"logStreamName": "555123456789_CloudTrail_us-east-1_20260415"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000011101010",
"eventID": "90000000-0000-4000-8000-000011101011",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "logs.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.