Skip to content

DeleteObject

AWS

DeleteObject

service: AWS - S3
tactics:
techniques:

Event

For general purpose buckets, a delete without versionId permanently removes an unversioned object, creates a delete marker with versioning enabled, or handles the null version when versioning is suspended. A specified versionId targets that version, including a delete marker. Object Lock and MFA Delete can impose additional constraints; removing a current view is not necessarily erasing retained versions.

Security Context

Unauthorized deletion can cause impact (T1485); ordinary retention and application updates also delete objects. A successful delete can occur for a nonexistent key. Verify prior existence, versions, and affected consumers before claiming data destruction.

Log Source

CloudTrail data event with eventSource: s3.amazonaws.com and eventName: DeleteObject. Object data events require configured collection, such as an appropriately selected trail or event data store. They are not included in Event history or default management-event collection. Check errors and resulting resource state; a null response does not by itself indicate failure.

Key Fields

FieldInvestigation value
requestParameters.bucketName, key, versionIdTarget and any selected version.
responseElementsInspect available delete-marker/version information; the illustrative null response lacks these details.
eventTime, awsRegion, recipientAccountId, eventIDTimeline, service Region, account, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Recover bucket versioning state, prior object existence, retention/legal hold, and any MFA Delete requirements.
  3. Determine whether the action removed a version or added a marker, and whether recovery copies remain.
  4. Correlate application failures and DeleteObjects or lifecycle changes. Do not infer parser failure from the key name.

Sample Event

Synthetic scenario. Draco targets a manifest key without versionId. The record does not show versioning state, prior content, or whether downstream processing failed.

Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:55:11Z",
"eventSource": "s3.amazonaws.com",
"eventName": "DeleteObject",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "[aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6]",
"requestParameters": {
"bucketName": "fantasticlogs-occamy-ingest",
"Host": "fantasticlogs-occamy-ingest.s3.us-east-1.amazonaws.com",
"key": "raw/cloudtrail/2026-04-15/manifest.json"
},
"responseElements": null,
"additionalEventData": {
"SignatureVersion": "SigV4",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"bytesTransferredIn": 0,
"AuthenticationMethod": "AuthHeader",
"bytesTransferredOut": 0
},
"requestID": "PXEXAMPLE123ABCD",
"eventID": "90000000-0000-4000-8000-000011110011",
"readOnly": false,
"resources": [
{
"type": "AWS::S3::Object",
"ARN": "arn:aws:s3:::fantasticlogs-occamy-ingest/raw/cloudtrail/2026-04-15/manifest.json"
},
{
"accountId": "555123456789",
"type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::fantasticlogs-occamy-ingest"
}
],
"eventType": "AwsApiCall",
"managementEvent": false,
"recipientAccountId": "555123456789",
"eventCategory": "Data",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "fantasticlogs-occamy-ingest.s3.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.