Skip to content

TerminateInstances

AWS

TerminateInstances

service: AWS - EC2
tactics:
techniques:

Event

Terminates the specified instances asynchronously. Instance-store data is lost; EBS volumes are deleted or retained according to DeleteOnTermination. Snapshots remain separate. Termination protection can block actions, and multi-instance requests involving protected instances across Availability Zones can have mixed outcomes. Auto Scaling may launch replacements.

Security Context

Unauthorized termination can disrupt services and destroy unretained data (T1485). Scaling and retirement generate the same API. Resource names alone do not prove backup destruction, and shutting-down is not final completion.

Log Source

AWS CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: TerminateInstances. Check errors and subsequent resource/task state; request acceptance is not always completion. A null response alone does not establish success or failure.

Key Fields

FieldInvestigation value
requestParameters.instancesSetAll targeted instances; resolve each independently.
responseElements.instancesSetPer-instance previous/current states.
errorCode, awsRegionErrors and regional context; assess Availability Zones and protection per target.
userIdentity, sourceIPAddress, userAgentCaller and supporting context; not proof of malicious intent.
eventTime, awsRegion, recipientAccountId, eventID, requestIDTimeline, scope, and correlation identifiers.

What to Investigate

  1. Confirm the operation outcome and compare caller, target, and timing with the approved workflow. Review failed attempts separately.
  2. Verify lifecycle approval, protection settings, group membership, and workload ownership for every target.
  3. Check final instance states, instance-store use, DeleteOnTermination settings, surviving volumes, and snapshots.
  4. Correlate DeleteVolume and application health, including replacement instances. Do not treat a batch request as proof of identical outcomes for all targets.

Sample Event

Synthetic scenario. Draco requests two terminations and both responses are shutting-down. The sample does not establish their operational roles, deleted storage, final states, or recovery loss.

Exact CloudTrail field presence, response wrappers, and timestamp serialization remain unverified against captured records. Resource identifiers are fictional; neither names nor this illustrative record establish data contents or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T21:14:51Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "TerminateInstances",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"instancesSet": {
"items": [
{
"instanceId": "i-0fedcba9876543210"
},
{
"instanceId": "i-0123456789abcdef0"
}
]
}
},
"responseElements": {
"requestId": "90000000-0000-4000-8000-000110111110",
"instancesSet": {
"items": [
{
"instanceId": "i-0fedcba9876543210",
"currentState": {
"code": 32,
"name": "shutting-down"
},
"previousState": {
"code": 16,
"name": "running"
}
},
{
"instanceId": "i-0123456789abcdef0",
"currentState": {
"code": 32,
"name": "shutting-down"
},
"previousState": {
"code": 16,
"name": "running"
}
}
]
}
},
"requestID": "90000000-0000-4000-8000-000110111110",
"eventID": "90000000-0000-4000-8000-000110111111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.