Skip to content

DeleteRuleGroup

AWS

DeleteRuleGroup

service: AWS - WAFV2
techniques:

Event

Deletes a WAFv2 rule group. Check web ACL references first: an in-use resource can produce WAFAssociatedItemException. A stale lock token can produce WAFOptimisticLockException. The request does not contain the deleted rules.

Security Context

Unauthorized removal may be part of weakening web filtering; approved replacement or cleanup is also possible. Recover the actual rules and prior references. A group name does not prove rate limits or bot controls existed, and deletion may follow an earlier web ACL update that already removed protection.

T1686.001 applies when the change deliberately impairs cloud firewall controls; the API name alone does not establish malicious intent.

Log Source

CloudTrail management event with eventSource: wafv2.amazonaws.com and eventName: DeleteRuleGroup. Search regional Event history or retained management-event logs, accounting for collection scope and retention.

Key Fields

FieldInvestigation use
requestParameters.name, requestParameters.idRule-group identity.
requestParameters.scopeREGIONAL or CLOUDFRONT; CloudFront scope uses us-east-1.
requestParameters.lockTokenConcurrency token, not proof that deletion succeeded.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the request and compare with approved work.
awsRegion, recipientAccountIdScope the account and regional context.
errorCode, errorMessageDistinguish rejection from an apparent completed request; verify actual state.

What to Investigate

  1. Confirm approval and inspect association, lock-token, and other errors.
  2. Recover prior rules and web ACL references; inspect preceding UpdateWebACL changes.
  3. Check scope and protected resource associations, including replacement controls.
  4. Correlate with DeleteWebACL and request logs to assess actual impact; do not assume a specific attack would have been blocked.

Sample Event

Synthetic scenario. Draco requests deletion of a regional fictional rule group assumed no longer referenced. The event does not establish its contents or the time web filtering changed. No top-level error is shown. Exact CloudTrail serialization and optional fields remain unverified by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:08:42Z",
"eventSource": "wafv2.amazonaws.com",
"eventName": "DeleteRuleGroup",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"name": "billywig-public-ingress-rg",
"scope": "REGIONAL",
"id": "60000000-0000-4000-8000-000011111100",
"lockToken": "a1b2c3d4-5678-90ab-cdef-1234567890ab"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000011111010",
"eventID": "90000000-0000-4000-8000-000011111011",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "wafv2.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.