Skip to content

DeleteWebACL

AWS

DeleteWebACL

service: AWS - WAFV2
techniques:

Event

Deletes a web ACL after it is disassociated from resources. This API requires ManagedByFirewallManager to be false. Check previous disassociation or CloudFront distribution updates to find when protection actually changed.

Security Context

Unauthorized deletion can be part of cloud-firewall impairment, while approved migration or retirement is legitimate. The deleted ACL may already have been replaced. Do not infer that all application-layer protection disappeared or that a later request was accepted.

T1686.001 applies when the change deliberately impairs cloud firewall controls; the API name alone does not establish malicious intent.

Log Source

CloudTrail management event with eventSource: wafv2.amazonaws.com and eventName: DeleteWebACL. Search regional Event history or retained management-event logs, accounting for collection scope and retention.

Key Fields

FieldInvestigation use
requestParameters.name, requestParameters.idWeb ACL identity.
requestParameters.scopeREGIONAL or CLOUDFRONT; account for the us-east-1 endpoint for CloudFront.
requestParameters.lockTokenOptimistic-lock token; stale tokens reject the change.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the request and compare with approved work.
awsRegion, recipientAccountIdScope the account and regional context.
errorCode, errorMessageDistinguish rejection from an apparent completed request; verify actual state.

What to Investigate

  1. Confirm approval and inspect association, Firewall Manager, and concurrency-related failures.
  2. Recover historical associations and locate DisassociateWebACL or CloudFront UpdateDistribution operations.
  3. Verify any replacement ACL, resource associations, and effective rules rather than relying on the deleted name.
  4. Correlate with DeleteRuleGroup and application/request evidence to establish the protection gap.

Sample Event

Synthetic scenario. Draco requests deletion of a regional fictional ACL assumed already disassociated and not managed by Firewall Manager. This single event does not establish an ALB’s current protection. No top-level error is shown. Exact CloudTrail serialization and optional fields remain unverified by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:11:55Z",
"eventSource": "wafv2.amazonaws.com",
"eventName": "DeleteWebACL",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"name": "billywig-public-webacl",
"scope": "REGIONAL",
"id": "60000000-0000-4000-8000-000100001100",
"lockToken": "b2c3d4e5-6789-01ab-cdef-2345678901bc"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000100001010",
"eventID": "90000000-0000-4000-8000-000100001011",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "wafv2.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.