Skip to content

DeleteVirtualMFADevice

AWS

DeleteVirtualMFADevice

service: AWS - IAM
techniques:

Event

Deletes a virtual MFA device. An assigned device must first be deactivated. The delete request therefore is not itself evidence that active MFA enforcement was removed at this moment.

Security Context

Unauthorized cleanup can accompany MFA tampering (T1556.006), but removal of unassigned devices during replacement or offboarding is normal. This API does not enroll an attacker-controlled replacement or demonstrate that the user has no other device.

The mapping describes a possible adversarial use, not a verdict on every occurrence.

Log Source

CloudTrail management event with eventSource: iam.amazonaws.com and eventName: DeleteVirtualMFADevice. Review IAM global-service event collection and retention, rather than searching only the workload’s Region. This audit record describes the request, not every downstream access outcome.

Key Fields

FieldInvestigation use
requestParameters.serialNumberDevice ARN; it does not independently establish the previously associated user.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute and correlate the caller’s activity.
recipientAccountId, awsRegionAccount and recording Region; IAM resources are not regional.
errorCode, errorMessageCheck failures; a null response alone does not prove success.

What to Investigate

  1. Confirm approval and inspect errors, including DeleteConflict.
  2. Recover the prior device association and locate DeactivateMFADevice for the same serial number.
  3. Check remaining devices and subsequent enrollment; distinguish legitimate replacement from unauthorized control.
  4. Review sign-in and API activity around the actual deactivation interval, not only the later deletion.

Sample Event

Synthetic scenario. Draco requests deletion of the fictional draco-totp device, assumed already deactivated. No replacement enrollment or loss of all MFA protection is demonstrated. No error fields are shown. Exact CloudTrail serialization and optional identity/session fields have not been validated by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:13:21Z",
"eventSource": "iam.amazonaws.com",
"eventName": "DeleteVirtualMFADevice",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"serialNumber": "arn:aws:iam::555123456789:mfa/draco-totp"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000100000110",
"eventID": "90000000-0000-4000-8000-000100000111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Defense Impairment

Techniques:
  • T1556.006 — Multi-Factor Authentication — Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.