Skip to content

DeleteTrail

AWS

DeleteTrail

service: AWS - CloudTrail
techniques:

Event

DeleteTrail removes a CloudTrail trail and stops its future collection. It does not delete previously delivered S3 log files, the destination bucket, or the associated CloudWatch Logs log group. The request must use the trail’s home Region. A multi-Region trail’s deletion affects its collection across Regions; a single-Region trail’s deletion affects that trail’s Region. AWS API reference.

Security Context

Unexpected deletion of a production trail can interrupt an audit feed and the alerts that depend on it. Establish what that trail collected before deciding how much visibility was lost.

Legitimate uses: retiring a duplicate trail, cleaning up a test environment, or replacing a collection configuration. Confirm the approved change and whether replacement collection was working before deletion.

Mapping rationale: malicious removal of a cloud audit collection path fits Disable or Modify Cloud Log. The operation alone does not prove malicious intent or destruction of historical evidence.

Log Source

Search CloudTrail management events for eventSource: cloudtrail.amazonaws.com and eventName: DeleteTrail. For retained trail collection, include write management events. Check the event’s account and Region rather than assuming every copy arrives in the deleted trail’s destination.

Collection boundary: Event history is independent of trails and retains 90 days of regional management events. Other collection paths may remain available. Event history does not provide a replacement for missing data events or organization-wide aggregation. AWS Event history documentation.

Key Fields

FieldInvestigation use
requestParameters.nameIdentify the deleted trail by name or ARN; recover its previous configuration to establish scope.
userIdentity.arn and userIdentity.sessionContextIdentify the caller and any session context available for attribution.
eventTime, awsRegion, and recipientAccountIdEstablish the affected account, regional record, and investigation window.
sourceIPAddress and userAgentCompare the origin and client with approved administration.
errorCode and errorMessageSeparate rejected attempts from apparent success. A null response alone does not establish deletion.

What to Investigate

  1. Confirm the request outcome and reconcile it with the current trail inventory. Recover the prior trail configuration from deployment records or retained configuration history; the ARN alone does not tell you every resource or event type it covered.
  2. Trace the caller’s access, including preceding AssumeRole activity where applicable. Verify the change with the responsible owner.
  3. Look for nearby StopLogging, UpdateTrail, and PutEventSelectors calls. Reconstruct the sequence without assuming any one of them was a prerequisite.
  4. Preserve previously delivered records and investigate destination changes separately. Check which independent feeds and alerts continued operating, and document the collection gap until replacement logging was confirmed.

Sample Event

Synthetic scenario — suspicious deletion. Draco deletes the account trail fantasticlogs-prod-trail in us-east-1. The sample illustrates a request without error fields; it does not establish the trail’s prior regional scope or which other collection paths remained. No claim is made that an earlier stop avoids a GuardDuty finding.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:39:17Z",
"eventSource": "cloudtrail.amazonaws.com",
"eventName": "DeleteTrail",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"name": "arn:aws:cloudtrail:us-east-1:555123456789:trail/fantasticlogs-prod-trail"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000011111110",
"eventID": "90000000-0000-4000-8000-000011111111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "cloudtrail.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.