Skip to content

DeleteSnapshot

AWS

DeleteSnapshot

service: AWS - EC2
tactics:
techniques:

Event

Deletes an owned EBS snapshot. A snapshot covered by a Recycle Bin retention rule is retained for recovery rather than immediately erased. Registered AMI root-snapshot dependencies and snapshot protection can block deletion; AWS Backup-managed recovery points require the AWS Backup deletion path. Deleting an incremental snapshot does not corrupt remaining snapshots or delete the source volume.

Security Context

Unauthorized deletion can destroy a recovery point (T1485) or inhibit recovery (T1490). Routine retention cleanup is common. An EC2 snapshot is not an RDS-managed DB snapshot, and losing one copy does not establish that all recovery options are gone.

Log Source

AWS CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: DeleteSnapshot. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.

Key Fields

FieldInvestigation value
requestParameters.snapshotIdOwned EBS snapshot and recovery dependencies.
responseElements, errorCodeAccepted request versus blocked deletion; verify retained state separately.
userIdentity, sourceIPAddress, userAgentCaller and supporting context; not proof of malicious intent.
eventTime, awsRegion, recipientAccountId, eventID, requestIDTimeline, scope, and correlation identifiers.

What to Investigate

  1. Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
  2. Check ownership, retention policy, Recycle Bin, snapshot lock, AMI dependencies, and backup-management scope.
  3. Confirm the actual snapshot state and remaining independent copies. A pending snapshot may finish before deletion takes effect.
  4. Correlate DeleteVolume and other backup changes; establish recovery impact before calling the loss irreversible.

Sample Event

Synthetic scenario. Draco targets a fictional EBS backup snapshot. It is not described as the underlying RDS service volume, and the sample does not show retention or other copies.

Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T21:05:14Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "DeleteSnapshot",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"snapshotId": "snap-0abcdef0123456789"
},
"responseElements": {
"requestId": "90000000-0000-4000-8000-000011111100",
"_return": true
},
"requestID": "90000000-0000-4000-8000-000011111100",
"eventID": "90000000-0000-4000-8000-000011111101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
  • T1490 — Inhibit System Recovery — Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.