Skip to content

DeleteVolume

AWS

DeleteVolume

service: AWS - EC2
tactics:
techniques:

Event

Deletes an EBS volume in the available state; an attached volume must first be detached. Deletion removes the volume, not snapshots already made from it. Verify completion and recovery copies separately.

Security Context

Unauthorized volume deletion can destroy data (T1485); approved storage cleanup is routine. The request does not show whether the volume was a root device, whether an instance was terminated, or whether a usable backup exists.

Log Source

AWS CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: DeleteVolume. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.

Key Fields

FieldInvestigation value
requestParameters.volumeIdTarget volume; recover state, attachments, and snapshot lineage.
responseElements, errorCodeDeletion outcome rather than proof of total data loss.
userIdentity, sourceIPAddress, userAgentCaller and supporting context; not proof of malicious intent.
eventTime, awsRegion, recipientAccountId, eventID, requestIDTimeline, scope, and correlation identifiers.

What to Investigate

  1. Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
  2. Recover prior attachments, current state, ownership, and the approved deletion task.
  3. Identify snapshots, replicas, and application-level backups without assuming they are usable until verified.
  4. Correlate detachment and TerminateInstances only if history shows them. Volume deletion does not prove both occurred.

Sample Event

Synthetic scenario. Draco deletes a fictional available volume. Its former root-volume role and a preceding termination are not established.

Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T21:09:42Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "DeleteVolume",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"volumeId": "vol-0fedcba9876543210"
},
"responseElements": {
"requestId": "90000000-0000-4000-8000-000100001000",
"_return": true
},
"requestID": "90000000-0000-4000-8000-000100001000",
"eventID": "90000000-0000-4000-8000-000100001001",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.