Skip to content

DeleteNetworkAclEntry

AWS

DeleteNetworkAclEntry

service: AWS - EC2
techniques:

Event

Removes the rule identified by ACL ID, rule number, and direction. The request does not include the removed rule’s allow/deny action, protocol, or address range. Determine the effect from the prior rule and the remaining ordered rules.

Security Context

An unauthorized deletion may weaken filtering or disrupt connectivity. Approved rule cleanup is also legitimate. Deleting a deny does not necessarily allow traffic: another matching deny or the final default deny may still apply. Deleting an allow can reduce access.

T1686.001 applies when the change deliberately impairs cloud firewall controls; the API name alone does not establish malicious intent.

Log Source

CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: DeleteNetworkAclEntry. Search regional Event history or retained management-event logs, accounting for collection scope and retention. For APIs supporting dry runs, DryRunOperation reports sufficient permissions without making the change.

Key Fields

FieldInvestigation use
requestParameters.networkAclIdAffected ACL.
requestParameters.ruleNumber, requestParameters.egressRule identity; the same number may occur in each direction.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the request and compare with approved work.
awsRegion, recipientAccountIdScope the account and regional context.
errorCode, errorMessageDistinguish rejection from an apparent completed request; verify actual state.

What to Investigate

  1. Confirm approval and inspect errors or dry-run status.
  2. Recover the removed rule from retained configuration; do not infer deny from the API name or number.
  3. Evaluate the remaining first-match decision, reverse direction, and all associated subnets.
  4. Correlate with CreateNetworkAclEntry and network evidence to establish the actual effect.

Sample Event

Synthetic scenario. Draco requests deletion of inbound rule 100. The scenario assumes an unauthorized change, but neither the removed action nor the resulting traffic decision is shown. No top-level error is shown. Exact CloudTrail serialization and optional fields remain unverified by capture. The inherited request/response nesting is illustrative; API transport examples alone do not validate CloudTrail field encoding.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:25:11Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "DeleteNetworkAclEntry",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"networkAclId": "acl-0123456789abcdef0",
"ruleNumber": 100,
"egress": false
},
"responseElements": {
"requestId": "90000000-0000-4000-8000-000011101110",
"_return": true
},
"requestID": "90000000-0000-4000-8000-000011101110",
"eventID": "90000000-0000-4000-8000-000011101111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.