DeleteVolume
DeleteVolume
Event
Deletes an EBS volume in the available state; an attached volume must first be detached. Deletion removes the volume, not snapshots already made from it. Verify completion and recovery copies separately.
Security Context
Unauthorized volume deletion can destroy data (T1485); approved storage cleanup is routine. The request does not show whether the volume was a root device, whether an instance was terminated, or whether a usable backup exists.
Log Source
AWS CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: DeleteVolume. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.volumeId | Target volume; recover state, attachments, and snapshot lineage. |
responseElements, errorCode | Deletion outcome rather than proof of total data loss. |
userIdentity, sourceIPAddress, userAgent | Caller and supporting context; not proof of malicious intent. |
eventTime, awsRegion, recipientAccountId, eventID, requestID | Timeline, scope, and correlation identifiers. |
What to Investigate
- Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
- Recover prior attachments, current state, ownership, and the approved deletion task.
- Identify snapshots, replicas, and application-level backups without assuming they are usable until verified.
- Correlate detachment and TerminateInstances only if history shows them. Volume deletion does not prove both occurred.
Sample Event
Synthetic scenario. Draco deletes a fictional available volume. Its former root-volume role and a preceding termination are not established.
Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:09:42Z", "eventSource": "ec2.amazonaws.com", "eventName": "DeleteVolume", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "volumeId": "vol-0fedcba9876543210" }, "responseElements": { "requestId": "90000000-0000-4000-8000-000100001000", "_return": true }, "requestID": "90000000-0000-4000-8000-000100001000", "eventID": "90000000-0000-4000-8000-000100001001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...