Skip to content

DeleteMembers

AWS

DeleteMembers

service: AWS - GuardDuty
techniques:

Event

Deletes the specified GuardDuty member records. Associated members must first be disassociated. This is not deletion of the AWS accounts or their detectors, and should not be treated as the moment active monitoring necessarily stopped.

Security Context

Unauthorized removal can obscure the administrator’s membership inventory; approved cleanup after disassociation is also routine. Reconstruct the preceding relationship changes to identify when central access or monitoring was affected.

The T1685 mapping applies to deliberate defensive impairment; the API name alone does not establish malicious intent.

Log Source

CloudTrail management event with eventSource: guardduty.amazonaws.com and eventName: DeleteMembers. Search regional Event history or your retained management-event collection; collection scope and retention determine the available evidence.

Key Fields

FieldInvestigation use
requestParameters.detectorIdAdministrator detector.
requestParameters.accountIdsRequested member records.
responseElements.unprocessedAccountsPer-member processing failures, when recorded.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the request and correlate with approved work.
awsRegion, recipientAccountIdScope the affected environment.
errorCode, errorMessageCheck rejection before inferring a completed change; null responseElements alone is not proof of success.

What to Investigate

  1. Check authorization, top-level errors, and unprocessedAccounts for partial failure.
  2. Find earlier DisassociateMembers or member-initiated departure events.
  3. Compare the administrator inventory with member detector status; do not infer that the AWS accounts or detectors were deleted.
  4. Review existing central evidence and independently retained findings. Restore the approved membership through the appropriate onboarding process.

Sample Event

Synthetic impairment scenario. An administrator-account role requests removal of two fictional member records, assumed already disassociated. The request alone cannot identify when central visibility was lost. No top-level error is shown. Exact CloudTrail serialization and optional fields have not been validated by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "AssumedRole",
"principalId": "AROAGRAPH0RNADM1NR01:draco-session",
"arn": "arn:aws:sts::555424242424:assumed-role/GraphornAdminRole/draco-session",
"accountId": "555424242424",
"accessKeyId": "ASIAGRAPH0RNSESS1ON1",
"sessionContext": {
"sessionIssuer": {
"type": "Role",
"principalId": "AROAGRAPH0RNADM1NR01",
"arn": "arn:aws:iam::555424242424:role/GraphornAdminRole",
"accountId": "555424242424",
"userName": "GraphornAdminRole"
},
"attributes": {
"creationDate": "2026-04-15T19:30:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:48:22Z",
"eventSource": "guardduty.amazonaws.com",
"eventName": "DeleteMembers",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"detectorId": "0123456789abcdef0123456789abcdef",
"accountIds": [
"555123456789",
"555098765432"
]
},
"responseElements": {
"unprocessedAccounts": []
},
"requestID": "90000000-0000-4000-8000-000011101100",
"eventID": "90000000-0000-4000-8000-000011101101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555424242424",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "guardduty.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.