DeleteObject
DeleteObject
Event
For general purpose buckets, a delete without versionId permanently removes an unversioned object, creates a delete marker with versioning enabled, or handles the null version when versioning is suspended. A specified versionId targets that version, including a delete marker. Object Lock and MFA Delete can impose additional constraints; removing a current view is not necessarily erasing retained versions.
Security Context
Unauthorized deletion can cause impact (T1485); ordinary retention and application updates also delete objects. A successful delete can occur for a nonexistent key. Verify prior existence, versions, and affected consumers before claiming data destruction.
Log Source
CloudTrail data event with eventSource: s3.amazonaws.com and eventName: DeleteObject. Object data events require configured collection, such as an appropriately selected trail or event data store. They are not included in Event history or default management-event collection. Check errors and resulting resource state; a null response does not by itself indicate failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.bucketName, key, versionId | Target and any selected version. |
responseElements | Inspect available delete-marker/version information; the illustrative null response lacks these details. |
eventTime, awsRegion, recipientAccountId, eventID | Timeline, service Region, account, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Recover bucket versioning state, prior object existence, retention/legal hold, and any MFA Delete requirements.
- Determine whether the action removed a version or added a marker, and whether recovery copies remain.
- Correlate application failures and DeleteObjects or lifecycle changes. Do not infer parser failure from the key name.
Sample Event
Synthetic scenario. Draco targets a manifest key without versionId. The record does not show versioning state, prior content, or whether downstream processing failed.
Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:55:11Z", "eventSource": "s3.amazonaws.com", "eventName": "DeleteObject", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "[aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6]", "requestParameters": { "bucketName": "fantasticlogs-occamy-ingest", "Host": "fantasticlogs-occamy-ingest.s3.us-east-1.amazonaws.com", "key": "raw/cloudtrail/2026-04-15/manifest.json" }, "responseElements": null, "additionalEventData": { "SignatureVersion": "SigV4", "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "bytesTransferredIn": 0, "AuthenticationMethod": "AuthHeader", "bytesTransferredOut": 0 }, "requestID": "PXEXAMPLE123ABCD", "eventID": "90000000-0000-4000-8000-000011110011", "readOnly": false, "resources": [ { "type": "AWS::S3::Object", "ARN": "arn:aws:s3:::fantasticlogs-occamy-ingest/raw/cloudtrail/2026-04-15/manifest.json" }, { "accountId": "555123456789", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::fantasticlogs-occamy-ingest" } ], "eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "555123456789", "eventCategory": "Data", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "fantasticlogs-occamy-ingest.s3.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...