DeleteObjects
DeleteObjects
Event
Requests multiple object deletions. The API can return both successful items and per-object errors in an HTTP 200 response. In a versioning-enabled bucket, deleting a key without a version ID normally creates a delete marker; deleting a specified version can permanently remove that version.
Security Context
Unauthorized deletion may destroy data (T1485) or impair log evidence (T1685.002). Approved retention cleanup is also common. Assess versioning, Object Lock, permissions, and retained copies before concluding the bucket was emptied or evidence became unrecoverable.
The mapping describes a possible adversarial sequence, not a verdict on every occurrence.
Log Source
CloudTrail data event with eventSource: s3.amazonaws.com and eventName: DeleteObjects. S3 object data-event logging must be configured for the relevant resources and operations on a trail or event data store. These events are not recorded in Event history; default management-event collection is insufficient.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.bucketName, resources | Bucket and any recorded object references. |
requestParameters.delete | Illustrated keys, version IDs, and quiet setting; field availability requires capture validation. |
responseElements | May not expose per-object API results; null does not prove every deletion succeeded. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the caller and correlate with approved work. |
recipientAccountId, awsRegion | Account and recording Region; distinguish caller, target, and resource scope. |
errorCode, errorMessage | Check request failures and confirm resulting state; null response alone is not proof of success. |
What to Investigate
- Confirm approval and distinguish the batch request from actual item outcomes; retrieve client results or other evidence where available.
- Inspect version IDs, delete markers, retention protections, and remaining versions.
- Compare requested keys with inventory and independent copies rather than treating a batch as all-or-nothing.
- Correlate with DeleteBucket and protect surviving evidence through the incident process.
Sample Event
Synthetic scenario. Draco requests deletion of three fictional log keys without version IDs. Versioning state and per-object outcomes are not shown, so permanent deletion or an empty bucket cannot be inferred. No top-level error is shown. Exact CloudTrail serialization and optional identity/session fields remain unverified by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:46:33Z", "eventSource": "s3.amazonaws.com", "eventName": "DeleteObjects", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "[aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6]", "requestParameters": { "bucketName": "fantasticlogs-cloudtrail", "Host": "fantasticlogs-cloudtrail.s3.us-east-1.amazonaws.com", "delete": { "objects": [ { "key": "AWSLogs/555123456789/CloudTrail/us-east-1/2026/04/14/555123456789_CloudTrail_us-east-1_20260414T1810Z_aBcDeFgHiJ.json.gz" }, { "key": "AWSLogs/555123456789/CloudTrail/us-east-1/2026/04/14/555123456789_CloudTrail_us-east-1_20260414T1815Z_kLmNoPqRsT.json.gz" }, { "key": "AWSLogs/555123456789/CloudTrail/us-east-1/2026/04/14/555123456789_CloudTrail_us-east-1_20260414T1820Z_uVwXyZ012345.json.gz" } ], "quiet": false } }, "responseElements": null, "additionalEventData": { "SignatureVersion": "SigV4", "CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256", "bytesTransferredIn": 612, "AuthenticationMethod": "AuthHeader", "bytesTransferredOut": 422 }, "requestID": "PXEXAMPLE456EFGH", "eventID": "90000000-0000-4000-8000-000011110101", "readOnly": false, "resources": [ { "accountId": "555123456789", "type": "AWS::S3::Bucket", "ARN": "arn:aws:s3:::fantasticlogs-cloudtrail" }, { "accountId": "555123456789", "type": "AWS::S3::Object", "ARN": "arn:aws:s3:::fantasticlogs-cloudtrail/AWSLogs/555123456789/CloudTrail/us-east-1/2026/04/14/555123456789_CloudTrail_us-east-1_20260414T1810Z_aBcDeFgHiJ.json.gz" }, { "accountId": "555123456789", "type": "AWS::S3::Object", "ARN": "arn:aws:s3:::fantasticlogs-cloudtrail/AWSLogs/555123456789/CloudTrail/us-east-1/2026/04/14/555123456789_CloudTrail_us-east-1_20260414T1815Z_kLmNoPqRsT.json.gz" }, { "accountId": "555123456789", "type": "AWS::S3::Object", "ARN": "arn:aws:s3:::fantasticlogs-cloudtrail/AWSLogs/555123456789/CloudTrail/us-east-1/2026/04/14/555123456789_CloudTrail_us-east-1_20260414T1820Z_uVwXyZ012345.json.gz" } ], "eventType": "AwsApiCall", "managementEvent": false, "recipientAccountId": "555123456789", "eventCategory": "Data", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "fantasticlogs-cloudtrail.s3.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Impact Defense Impairment
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
- T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...