DeleteWebACL
DeleteWebACL
Event
Deletes a web ACL after it is disassociated from resources. This API requires ManagedByFirewallManager to be false. Check previous disassociation or CloudFront distribution updates to find when protection actually changed.
Security Context
Unauthorized deletion can be part of cloud-firewall impairment, while approved migration or retirement is legitimate. The deleted ACL may already have been replaced. Do not infer that all application-layer protection disappeared or that a later request was accepted.
T1686.001 applies when the change deliberately impairs cloud firewall controls; the API name alone does not establish malicious intent.
Log Source
CloudTrail management event with eventSource: wafv2.amazonaws.com and eventName: DeleteWebACL. Search regional Event history or retained management-event logs, accounting for collection scope and retention.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.name, requestParameters.id | Web ACL identity. |
requestParameters.scope | REGIONAL or CLOUDFRONT; account for the us-east-1 endpoint for CloudFront. |
requestParameters.lockToken | Optimistic-lock token; stale tokens reject the change. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the request and compare with approved work. |
awsRegion, recipientAccountId | Scope the account and regional context. |
errorCode, errorMessage | Distinguish rejection from an apparent completed request; verify actual state. |
What to Investigate
- Confirm approval and inspect association, Firewall Manager, and concurrency-related failures.
- Recover historical associations and locate DisassociateWebACL or CloudFront UpdateDistribution operations.
- Verify any replacement ACL, resource associations, and effective rules rather than relying on the deleted name.
- Correlate with DeleteRuleGroup and application/request evidence to establish the protection gap.
Sample Event
Synthetic scenario. Draco requests deletion of a regional fictional ACL assumed already disassociated and not managed by Firewall Manager. This single event does not establish an ALB’s current protection. No top-level error is shown. Exact CloudTrail serialization and optional fields remain unverified by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:11:55Z", "eventSource": "wafv2.amazonaws.com", "eventName": "DeleteWebACL", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "name": "billywig-public-webacl", "scope": "REGIONAL", "id": "60000000-0000-4000-8000-000100001100", "lockToken": "b2c3d4e5-6789-01ab-cdef-2345678901bc" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000100001010", "eventID": "90000000-0000-4000-8000-000100001011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "wafv2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1686.001 — Cloud Firewall — Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.