Skip to content

PutBucketLifecycle

AWS

PutBucketLifecycle

service: AWS - S3
tactics:
techniques:

Event

Replaces the bucket lifecycle configuration. The legacy PutBucketLifecycle API is deprecated in favor of PutBucketLifecycleConfiguration, but the CloudTrail event name PutBucketLifecycle does not prove use of legacy client tooling. Rules apply to matching existing and new objects. Expiration is age-based and asynchronous; current-version expiration may create delete markers, while noncurrent-version expiration is separate.

Security Context

Unauthorized expiration can destroy data or inhibit recovery (T1485/T1490). Approved retention and cost management are common. A one-day rule on a prefix does not erase the entire bucket exactly 24 hours after this request.

Log Source

CloudTrail management event with eventSource: s3.amazonaws.com and eventName: PutBucketLifecycle. Check errors and resulting resource state; a null response does not by itself indicate failure.

Key Fields

FieldInvestigation value
requestParameters.bucketNameTarget bucket and versioning/retention context.
requestParameters.LifecycleConfigurationFull replacement rules, filters, status, and version-expiration actions.
eventTime, awsRegion, recipientAccountId, eventIDTimeline, service Region, account, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Compare the entire previous and submitted configuration; check both added rules and omitted existing rules.
  3. Resolve matching prefixes, object ages, versions, and retention protections. Establish which objects become eligible rather than assuming all data is deleted.
  4. Correlate resulting lifecycle actions and surviving versions; see PutBucketLifecycleConfiguration for the related API-oriented entry.

Sample Event

Synthetic scenario. Draco submits an enabled one-day rule for snapshots/. The sample proves neither deprecated-tool use nor expiration of every backup.

Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T21:42:08Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T23:31:54Z",
"eventSource": "s3.amazonaws.com",
"eventName": "PutBucketLifecycle",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "[aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6]",
"requestParameters": {
"bucketName": "fantasticlogs-phoenix-backups",
"Host": "fantasticlogs-phoenix-backups.s3.amazonaws.com",
"lifecycle": [
""
],
"LifecycleConfiguration": {
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/",
"Rule": [
{
"ID": "wipe-backups",
"Prefix": "snapshots/",
"Status": "Enabled",
"Expiration": {
"Days": 1
}
}
]
}
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000101100010",
"eventID": "90000000-0000-4000-8000-000101100011",
"readOnly": false,
"resources": [
{
"accountId": "555123456789",
"type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::fantasticlogs-phoenix-backups"
}
],
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "fantasticlogs-phoenix-backups.s3.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
  • T1490 — Inhibit System Recovery — Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.