Skip to content

PutBucketLifecycleConfiguration

AWS

PutBucketLifecycleConfiguration

service: AWS - S3
techniques:

Event

Sets the complete lifecycle configuration, replacing any existing one. Rules can expire objects, transition storage, or manage versions; inspect every rule and filter, not just the operation name.

Security Context

Unauthorized expiration can shorten evidence retention (T1485 and T1685.002 in a destructive log scenario). Approved retention and storage management are common. Expiration is based on object age and processed asynchronously, not exactly 24 hours after the API call. Current-version expiration in a versioning-enabled bucket creates delete markers; noncurrent-version expiration is separate.

The mapping describes a possible adversarial sequence, not a verdict on every occurrence.

Log Source

CloudTrail management event with eventSource: s3.amazonaws.com and eventName: PutBucketLifecycle. Check collection scope and retention before interpreting absent records. The API title differs from the PutBucketLifecycle event name used in AWS’s documented CloudTrail filter pattern.

Key Fields

FieldInvestigation use
requestParameters.bucketNameTarget bucket.
requestParameters.LifecycleConfigurationIllustrated rule statuses, filters, expiration, and transitions; recover stored configuration for a complete comparison.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the caller and correlate with approved work.
recipientAccountId, awsRegionAccount and recording Region; distinguish caller, target, and resource scope.
errorCode, errorMessageCheck request failures and confirm resulting state; null response alone is not proof of success.

What to Investigate

  1. Confirm approval and request outcome, then compare GetBucketLifecycleConfiguration with the entire prior configuration.
  2. Evaluate matching existing and future objects, age thresholds, versioning, and Object Lock protections.
  3. Inspect object/version inventory and lifecycle notifications to establish what actually expired.
  4. Correlate with DeleteObjects, restore the approved retention configuration, and assess surviving versions and external copies.

Sample Event

Synthetic scenario. Draco requests a one-day current-version expiration rule across a fictional log bucket. It does not specify noncurrent-version expiration and does not prove permanent loss after 24 hours. The inherited XML-like CloudTrail field representation remains unverified. No top-level error is shown. Exact CloudTrail serialization and optional identity/session fields remain unverified by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T21:42:08Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T23:25:09Z",
"eventSource": "s3.amazonaws.com",
"eventName": "PutBucketLifecycle",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "[aws-cli/2.15.30 Python/3.11.6 Linux/5.15.0-1052-aws exe/x86_64.ubuntu.22 prompt/off command/s3api.put-bucket-lifecycle-configuration]",
"requestParameters": {
"bucketName": "fantasticlogs-cloudtrail",
"Host": "fantasticlogs-cloudtrail.s3.amazonaws.com",
"lifecycle": [
""
],
"LifecycleConfiguration": {
"xmlns": "http://s3.amazonaws.com/doc/2006-03-01/",
"Rule": [
{
"ID": "expire-cloudtrail-logs",
"Status": "Enabled",
"Filter": {
"Prefix": ""
},
"Expiration": {
"Days": 1
}
}
]
}
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000101100000",
"eventID": "90000000-0000-4000-8000-000101100001",
"readOnly": false,
"resources": [
{
"accountId": "555123456789",
"type": "AWS::S3::Bucket",
"ARN": "arn:aws:s3:::fantasticlogs-cloudtrail"
}
],
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "fantasticlogs-cloudtrail.s3.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact Defense Impairment

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
  • T1685.002 — Disable or Modify Cloud Log — An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection. Cloud environments allow for collection and analysis of audit and application logs that provide insight into what activities a user does within t...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.