DeleteTrail
DeleteTrail
Event
DeleteTrail removes a CloudTrail trail and stops its future collection. It does not delete previously delivered S3 log files, the destination bucket, or the associated CloudWatch Logs log group. The request must use the trail’s home Region. A multi-Region trail’s deletion affects its collection across Regions; a single-Region trail’s deletion affects that trail’s Region. AWS API reference.
Security Context
Unexpected deletion of a production trail can interrupt an audit feed and the alerts that depend on it. Establish what that trail collected before deciding how much visibility was lost.
Legitimate uses: retiring a duplicate trail, cleaning up a test environment, or replacing a collection configuration. Confirm the approved change and whether replacement collection was working before deletion.
Mapping rationale: malicious removal of a cloud audit collection path fits Disable or Modify Cloud Log. The operation alone does not prove malicious intent or destruction of historical evidence.
Log Source
Search CloudTrail management events for eventSource: cloudtrail.amazonaws.com and eventName: DeleteTrail. For retained trail collection, include write management events. Check the event’s account and Region rather than assuming every copy arrives in the deleted trail’s destination.
Collection boundary: Event history is independent of trails and retains 90 days of regional management events. Other collection paths may remain available. Event history does not provide a replacement for missing data events or organization-wide aggregation. AWS Event history documentation.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.name | Identify the deleted trail by name or ARN; recover its previous configuration to establish scope. |
userIdentity.arn and userIdentity.sessionContext | Identify the caller and any session context available for attribution. |
eventTime, awsRegion, and recipientAccountId | Establish the affected account, regional record, and investigation window. |
sourceIPAddress and userAgent | Compare the origin and client with approved administration. |
errorCode and errorMessage | Separate rejected attempts from apparent success. A null response alone does not establish deletion. |
What to Investigate
- Confirm the request outcome and reconcile it with the current trail inventory. Recover the prior trail configuration from deployment records or retained configuration history; the ARN alone does not tell you every resource or event type it covered.
- Trace the caller’s access, including preceding AssumeRole activity where applicable. Verify the change with the responsible owner.
- Look for nearby StopLogging, UpdateTrail, and PutEventSelectors calls. Reconstruct the sequence without assuming any one of them was a prerequisite.
- Preserve previously delivered records and investigate destination changes separately. Check which independent feeds and alerts continued operating, and document the collection gap until replacement logging was confirmed.
Sample Event
Synthetic scenario — suspicious deletion. Draco deletes the account trail fantasticlogs-prod-trail in us-east-1. The sample illustrates a request without error fields; it does not establish the trail’s prior regional scope or which other collection paths remained. No claim is made that an earlier stop avoids a GuardDuty finding.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:39:17Z", "eventSource": "cloudtrail.amazonaws.com", "eventName": "DeleteTrail", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "name": "arn:aws:cloudtrail:us-east-1:555123456789:trail/fantasticlogs-prod-trail" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000011111110", "eventID": "90000000-0000-4000-8000-000011111111", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "cloudtrail.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...