DeleteSnapshot
DeleteSnapshot
Event
Deletes an owned EBS snapshot. A snapshot covered by a Recycle Bin retention rule is retained for recovery rather than immediately erased. Registered AMI root-snapshot dependencies and snapshot protection can block deletion; AWS Backup-managed recovery points require the AWS Backup deletion path. Deleting an incremental snapshot does not corrupt remaining snapshots or delete the source volume.
Security Context
Unauthorized deletion can destroy a recovery point (T1485) or inhibit recovery (T1490). Routine retention cleanup is common. An EC2 snapshot is not an RDS-managed DB snapshot, and losing one copy does not establish that all recovery options are gone.
Log Source
AWS CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: DeleteSnapshot. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.snapshotId | Owned EBS snapshot and recovery dependencies. |
responseElements, errorCode | Accepted request versus blocked deletion; verify retained state separately. |
userIdentity, sourceIPAddress, userAgent | Caller and supporting context; not proof of malicious intent. |
eventTime, awsRegion, recipientAccountId, eventID, requestID | Timeline, scope, and correlation identifiers. |
What to Investigate
- Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
- Check ownership, retention policy, Recycle Bin, snapshot lock, AMI dependencies, and backup-management scope.
- Confirm the actual snapshot state and remaining independent copies. A pending snapshot may finish before deletion takes effect.
- Correlate DeleteVolume and other backup changes; establish recovery impact before calling the loss irreversible.
Sample Event
Synthetic scenario. Draco targets a fictional EBS backup snapshot. It is not described as the underlying RDS service volume, and the sample does not show retention or other copies.
Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:05:14Z", "eventSource": "ec2.amazonaws.com", "eventName": "DeleteSnapshot", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "snapshotId": "snap-0abcdef0123456789" }, "responseElements": { "requestId": "90000000-0000-4000-8000-000011111100", "_return": true }, "requestID": "90000000-0000-4000-8000-000011111100", "eventID": "90000000-0000-4000-8000-000011111101", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
- T1490 — Inhibit System Recovery — Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.