Skip to content

DeleteObjects

AWS

DeleteObjects

service: AWS - S3
techniques:

Event

Requests multiple object deletions. The API can return both successful items and per-object errors in an HTTP 200 response. In a versioning-enabled bucket, deleting a key without a version ID normally creates a delete marker; deleting a specified version can permanently remove that version.

Security Context

Unauthorized deletion may destroy data (T1485) or impair log evidence (T1685.002). Approved retention cleanup is also common. Assess versioning, Object Lock, permissions, and retained copies before concluding the bucket was emptied or evidence became unrecoverable.

The mapping describes a possible adversarial sequence, not a verdict on every occurrence.

Log Source

CloudTrail data event with eventSource: s3.amazonaws.com and eventName: DeleteObjects. S3 object data-event logging must be configured for the relevant resources and operations on a trail or event data store. These events are not recorded in Event history; default management-event collection is insufficient.

Key Fields

FieldInvestigation use
requestParameters.bucketName, resourcesBucket and any recorded object references.
requestParameters.deleteIllustrated keys, version IDs, and quiet setting; field availability requires capture validation.
responseElementsMay not expose per-object API results; null does not prove every deletion succeeded.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the caller and correlate with approved work.
recipientAccountId, awsRegionAccount and recording Region; distinguish caller, target, and resource scope.
errorCode, errorMessageCheck request failures and confirm resulting state; null response alone is not proof of success.

What to Investigate

  1. Confirm approval and distinguish the batch request from actual item outcomes; retrieve client results or other evidence where available.
  2. Inspect version IDs, delete markers, retention protections, and remaining versions.
  3. Compare requested keys with inventory and independent copies rather than treating a batch as all-or-nothing.
  4. Correlate with DeleteBucket and protect surviving evidence through the incident process.

Sample Event

Synthetic scenario. Draco requests deletion of three fictional log keys without version IDs. Versioning state and per-object outcomes are not shown, so permanent deletion or an empty bucket cannot be inferred. No top-level error is shown. Exact CloudTrail serialization and optional identity/session fields remain unverified by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:46:33Z",
"eventSource": "s3.amazonaws.com",
"eventName": "DeleteObjects",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "[aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6]",
"requestParameters": {
"bucketName": "fantasticlogs-cloudtrail",
"Host": "fantasticlogs-cloudtrail.s3.us-east-1.amazonaws.com",
"delete": {
"objects": [
{
"key": "AWSLogs/555123456789/CloudTrail/us-east-1/2026/04/14/555123456789_CloudTrail_us-east-1_20260414T1810Z_aBcDeFgHiJ.json.gz"
},
{
"key": "AWSLogs/555123456789/CloudTrail/us-east-1/2026/04/14/555123456789_CloudTrail_us-east-1_20260414T1815Z_kLmNoPqRsT.json.gz"
},
{
"key": "AWSLogs/555123456789/CloudTrail/us-east-1/2026/04/14/555123456789_CloudTrail_us-east-1_20260414T1820Z_uVwXyZ012345.json.gz"
}
],
"quiet": false
}
},
"responseElements": null,
"additionalEventData": {
"SignatureVersion": "SigV4",
"CipherSuite": "ECDHE-RSA-AES128-GCM-SHA256",
"bytesTransferredIn": 612,
"AuthenticationMethod": "AuthHeader",
"bytesTransferredOut": 422
},
"requestID": "PXEXAMPLE456EFGH",
"eventID": "90000000-0000-4000-8000-000011110101",
"readOnly": false,
"resources": [
{
"accountId": "555123456789",
"type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::fantasticlogs-cloudtrail"
},
{
"accountId": "555123456789",
"type": "AWS::S3::Object",
"ARN": "arn:aws:s3:::fantasticlogs-cloudtrail/AWSLogs/555123456789/CloudTrail/us-east-1/2026/04/14/555123456789_CloudTrail_us-east-1_20260414T1810Z_aBcDeFgHiJ.json.gz"
},
{
"accountId": "555123456789",
"type": "AWS::S3::Object",
"ARN": "arn:aws:s3:::fantasticlogs-cloudtrail/AWSLogs/555123456789/CloudTrail/us-east-1/2026/04/14/555123456789_CloudTrail_us-east-1_20260414T1815Z_kLmNoPqRsT.json.gz"
},
{
"accountId": "555123456789",
"type": "AWS::S3::Object",
"ARN": "arn:aws:s3:::fantasticlogs-cloudtrail/AWSLogs/555123456789/CloudTrail/us-east-1/2026/04/14/555123456789_CloudTrail_us-east-1_20260414T1820Z_uVwXyZ012345.json.gz"
}
],
"eventType": "AwsApiCall",
"managementEvent": false,
"recipientAccountId": "555123456789",
"eventCategory": "Data",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "fantasticlogs-cloudtrail.s3.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact Defense Impairment

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
  • T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.