DeleteVirtualMFADevice
DeleteVirtualMFADevice
Event
Deletes a virtual MFA device. An assigned device must first be deactivated. The delete request therefore is not itself evidence that active MFA enforcement was removed at this moment.
Security Context
Unauthorized cleanup can accompany MFA tampering (T1556.006), but removal of unassigned devices during replacement or offboarding is normal. This API does not enroll an attacker-controlled replacement or demonstrate that the user has no other device.
The mapping describes a possible adversarial use, not a verdict on every occurrence.
Log Source
CloudTrail management event with eventSource: iam.amazonaws.com and eventName: DeleteVirtualMFADevice. Review IAM global-service event collection and retention, rather than searching only the workload’s Region. This audit record describes the request, not every downstream access outcome.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.serialNumber | Device ARN; it does not independently establish the previously associated user. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute and correlate the caller’s activity. |
recipientAccountId, awsRegion | Account and recording Region; IAM resources are not regional. |
errorCode, errorMessage | Check failures; a null response alone does not prove success. |
What to Investigate
- Confirm approval and inspect errors, including DeleteConflict.
- Recover the prior device association and locate DeactivateMFADevice for the same serial number.
- Check remaining devices and subsequent enrollment; distinguish legitimate replacement from unauthorized control.
- Review sign-in and API activity around the actual deactivation interval, not only the later deletion.
Sample Event
Synthetic scenario. Draco requests deletion of the fictional draco-totp device, assumed already deactivated. No replacement enrollment or loss of all MFA protection is demonstrated. No error fields are shown. Exact CloudTrail serialization and optional identity/session fields have not been validated by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:13:21Z", "eventSource": "iam.amazonaws.com", "eventName": "DeleteVirtualMFADevice", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "serialNumber": "arn:aws:iam::555123456789:mfa/draco-totp" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000100000110", "eventID": "90000000-0000-4000-8000-000100000111", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Defense Impairment
- T1556.006 — Multi-Factor Authentication — Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.