Skip to content

PutBucketLifecycle

AWS

PutBucketLifecycle

service: AWS - S3
tactics:
techniques:

Event

Sets lifecycle configuration on an S3 bucket to automate object transitions or expiration over time.

Security Context

  • Impairing defenses allows adversaries to operate freely by removing security controls that would otherwise detect or block their activity.
  • Destructive deletion of cloud resources can cause significant operational disruption, data loss, and extended recovery times.

Log Source

CloudTrail

Sample Event

Adversarial — impact / data destruction. Ron’s old build pipeline tooling (still using the deprecated PutBucketLifecycle API) is the cover Draco uses to slip in a destructive lifecycle rule against the PHOENIX backup snapshots bucket (fantasticlogs-phoenix-backups). The 1-day expiration deletes all backup data, severely impacting recovery options before destructive follow-on actions. T1485 + T1685.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T21:42:08Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T23:31:54Z",
"eventSource": "s3.amazonaws.com",
"eventName": "PutBucketLifecycle",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "[aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6]",
"requestParameters": {
"bucketName": "fantasticlogs-phoenix-backups",
"Host": "fantasticlogs-phoenix-backups.s3.amazonaws.com",
"lifecycle": [
""
],
"LifecycleConfiguration": {
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/",
"Rule": [
{
"ID": "wipe-backups",
"Prefix": "snapshots/",
"Status": "Enabled",
"Expiration": {
"Days": 1
}
}
]
}
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000101100010",
"eventID": "90000000-0000-4000-8000-000101100011",
"readOnly": false,
"resources": [
{
"accountId": "555123456789",
"type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::fantasticlogs-phoenix-backups"
}
],
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "fantasticlogs-phoenix-backups.s3.amazonaws.com"
}
}

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
  • T1490 — Inhibit System Recovery — Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery. This may deny access to available backups and recovery options.