DeleteNetworkAclEntry
DeleteNetworkAclEntry
Event
Removes the rule identified by ACL ID, rule number, and direction. The request does not include the removed rule’s allow/deny action, protocol, or address range. Determine the effect from the prior rule and the remaining ordered rules.
Security Context
An unauthorized deletion may weaken filtering or disrupt connectivity. Approved rule cleanup is also legitimate. Deleting a deny does not necessarily allow traffic: another matching deny or the final default deny may still apply. Deleting an allow can reduce access.
T1686.001 applies when the change deliberately impairs cloud firewall controls; the API name alone does not establish malicious intent.
Log Source
CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: DeleteNetworkAclEntry. Search regional Event history or retained management-event logs, accounting for collection scope and retention. For APIs supporting dry runs, DryRunOperation reports sufficient permissions without making the change.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.networkAclId | Affected ACL. |
requestParameters.ruleNumber, requestParameters.egress | Rule identity; the same number may occur in each direction. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the request and compare with approved work. |
awsRegion, recipientAccountId | Scope the account and regional context. |
errorCode, errorMessage | Distinguish rejection from an apparent completed request; verify actual state. |
What to Investigate
- Confirm approval and inspect errors or dry-run status.
- Recover the removed rule from retained configuration; do not infer deny from the API name or number.
- Evaluate the remaining first-match decision, reverse direction, and all associated subnets.
- Correlate with CreateNetworkAclEntry and network evidence to establish the actual effect.
Sample Event
Synthetic scenario. Draco requests deletion of inbound rule 100. The scenario assumes an unauthorized change, but neither the removed action nor the resulting traffic decision is shown. No top-level error is shown. Exact CloudTrail serialization and optional fields remain unverified by capture. The inherited request/response nesting is illustrative; API transport examples alone do not validate CloudTrail field encoding.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:25:11Z", "eventSource": "ec2.amazonaws.com", "eventName": "DeleteNetworkAclEntry", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "networkAclId": "acl-0123456789abcdef0", "ruleNumber": 100, "egress": false }, "responseElements": { "requestId": "90000000-0000-4000-8000-000011101110", "_return": true }, "requestID": "90000000-0000-4000-8000-000011101110", "eventID": "90000000-0000-4000-8000-000011101111", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.