Skip to content

DeleteUser

AWS

DeleteUser

service: AWS - IAM
tactics:
techniques:

Event

Programmatic deletion requires prior cleanup of the user’s password, access keys, signing certificates, SSH public keys, service-specific credentials, MFA associations, inline policies, managed-policy attachments, and group memberships. Remaining dependencies can produce DeleteConflict. Console workflows may handle cleanup separately.

Security Context

Unauthorized deletion can remove legitimate access (T1531); offboarding is normal. This removes an IAM identity, not the AWS account or resources the user created. Recreating a name does not restore the original unique user identity or all references to it.

Log Source

AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: DeleteUser. Check errorCode and errorMessage; a null response alone does not establish success or failure. Include IAM global-service events in collection.

Key Fields

FieldInvestigation value
requestParameters.userNameTarget user; recover its prior stable user ID and dependencies.
errorCode, errorMessageDeleteConflict and other failures distinguish attempts from completed removal.
eventTime, recipientAccountId, eventID, requestIDTimeline and correlation identifiers.
sourceIPAddress, userAgentSupporting context, not a definitive attacker fingerprint.

What to Investigate

  1. Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
  2. Validate the offboarding or response approval and confirm deletion rather than assuming all dependencies were removed.
  3. Correlate DeleteLoginProfile, DeleteAccessKey, group removals, and policy changes. There is no mandatory single event order.
  4. Assess affected operators and workloads using historical identity and resource-policy records; distinguish user deletion from data destruction.

Sample Event

Synthetic scenario. Draco targets hermione for deletion. The sample does not contain the required cleanup history or prove that response activity was disrupted.

Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:01:48Z",
"eventSource": "iam.amazonaws.com",
"eventName": "DeleteUser",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"userName": "hermione"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000100000000",
"eventID": "90000000-0000-4000-8000-000100000001",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1531 — Account Access Removal — Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts....
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.