TerminateInstances
TerminateInstances
Event
Terminates the specified instances asynchronously. Instance-store data is lost; EBS volumes are deleted or retained according to DeleteOnTermination. Snapshots remain separate. Termination protection can block actions, and multi-instance requests involving protected instances across Availability Zones can have mixed outcomes. Auto Scaling may launch replacements.
Security Context
Unauthorized termination can disrupt services and destroy unretained data (T1485). Scaling and retirement generate the same API. Resource names alone do not prove backup destruction, and shutting-down is not final completion.
Log Source
AWS CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: TerminateInstances. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.instancesSet | All targeted instances; resolve each independently. |
responseElements.instancesSet | Per-instance previous/current states. |
errorCode, awsRegion | Errors and regional context; assess Availability Zones and protection per target. |
userIdentity, sourceIPAddress, userAgent | Caller and supporting context; not proof of malicious intent. |
eventTime, awsRegion, recipientAccountId, eventID, requestID | Timeline, scope, and correlation identifiers. |
What to Investigate
- Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
- Verify lifecycle approval, protection settings, group membership, and workload ownership for every target.
- Check final instance states, instance-store use, DeleteOnTermination settings, surviving volumes, and snapshots.
- Correlate DeleteVolume and application health, including replacement instances. Do not treat a batch request as proof of identical outcomes for all targets.
Sample Event
Synthetic scenario. Draco requests two terminations and both responses are shutting-down. The sample does not establish their operational roles, deleted storage, final states, or recovery loss.
Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:14:51Z", "eventSource": "ec2.amazonaws.com", "eventName": "TerminateInstances", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "instancesSet": { "items": [ { "instanceId": "i-0fedcba9876543210" }, { "instanceId": "i-0123456789abcdef0" } ] } }, "responseElements": { "requestId": "90000000-0000-4000-8000-000110111110", "instancesSet": { "items": [ { "instanceId": "i-0fedcba9876543210", "currentState": { "code": 32, "name": "shutting-down" }, "previousState": { "code": 16, "name": "running" } }, { "instanceId": "i-0123456789abcdef0", "currentState": { "code": 32, "name": "shutting-down" }, "previousState": { "code": 16, "name": "running" } } ] } }, "requestID": "90000000-0000-4000-8000-000110111110", "eventID": "90000000-0000-4000-8000-000110111111", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...