DeleteRuleGroup
DeleteRuleGroup
Event
Deletes a WAFv2 rule group. Check web ACL references first: an in-use resource can produce WAFAssociatedItemException. A stale lock token can produce WAFOptimisticLockException. The request does not contain the deleted rules.
Security Context
Unauthorized removal may be part of weakening web filtering; approved replacement or cleanup is also possible. Recover the actual rules and prior references. A group name does not prove rate limits or bot controls existed, and deletion may follow an earlier web ACL update that already removed protection.
T1686.001 applies when the change deliberately impairs cloud firewall controls; the API name alone does not establish malicious intent.
Log Source
CloudTrail management event with eventSource: wafv2.amazonaws.com and eventName: DeleteRuleGroup. Search regional Event history or retained management-event logs, accounting for collection scope and retention.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.name, requestParameters.id | Rule-group identity. |
requestParameters.scope | REGIONAL or CLOUDFRONT; CloudFront scope uses us-east-1. |
requestParameters.lockToken | Concurrency token, not proof that deletion succeeded. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the request and compare with approved work. |
awsRegion, recipientAccountId | Scope the account and regional context. |
errorCode, errorMessage | Distinguish rejection from an apparent completed request; verify actual state. |
What to Investigate
- Confirm approval and inspect association, lock-token, and other errors.
- Recover prior rules and web ACL references; inspect preceding UpdateWebACL changes.
- Check scope and protected resource associations, including replacement controls.
- Correlate with DeleteWebACL and request logs to assess actual impact; do not assume a specific attack would have been blocked.
Sample Event
Synthetic scenario. Draco requests deletion of a regional fictional rule group assumed no longer referenced. The event does not establish its contents or the time web filtering changed. No top-level error is shown. Exact CloudTrail serialization and optional fields remain unverified by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:08:42Z", "eventSource": "wafv2.amazonaws.com", "eventName": "DeleteRuleGroup", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "name": "billywig-public-ingress-rg", "scope": "REGIONAL", "id": "60000000-0000-4000-8000-000011111100", "lockToken": "a1b2c3d4-5678-90ab-cdef-1234567890ab" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000011111010", "eventID": "90000000-0000-4000-8000-000011111011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "wafv2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.