Detection rules › Sigma
AWS Bucket Deleted
Detects the deletion of S3 buckets in AWS CloudTrail logs. Monitoring the deletion of S3 buckets is critical for security and data integrity, as it may indicate potential data loss or unauthorized access attempts.
Known false positives
- During maintenance operations or testing, authorized administrators may delete S3 buckets as part of routine data management or cleanup activities.
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Stealth | No specific technique |
Rules detecting the same action
These rules filter on the same operation.
- Detect Spike in S3 Bucket deletion (Splunk)
Rule body
title: AWS Bucket Deleted
id: 39c9f26d-6e3b-4dbb-9c7a-4154b0281112
status: experimental
description: |
Detects the deletion of S3 buckets in AWS CloudTrail logs.
Monitoring the deletion of S3 buckets is critical for security and data integrity, as it may indicate potential data loss or unauthorized access attempts.
references:
- https://docs.aws.amazon.com/AmazonS3/latest/API/API_DeleteBucket.html
- https://awscli.amazonaws.com/v2/documentation/api/latest/reference/s3api/delete-bucket.html
author: Ivan Saakov, Nasreddine Bencherchali
date: 2025-10-19
tags:
- attack.stealth
logsource:
product: aws
service: cloudtrail
detection:
selection_event_name:
eventName: 'DeleteBucket'
selection_status_success:
errorCode: 'Success'
selection_status_null:
errorCode: null
condition: selection_event_name and 1 of selection_status_*
falsepositives:
- During maintenance operations or testing, authorized administrators may delete S3 buckets as part of routine data management or cleanup activities.
level: medium
Stages and Predicates
Stage 0: condition
selection_event_name and 1 of selection_status_*Stage 1: selection_event_name
selection_event_name:
eventName: 'DeleteBucket'
Stage 2: selection_status_success
selection_status_success:
errorCode: 'Success'
Stage 3: selection_status_null
selection_status_null:
errorCode: null
Indicators
These rows show field, operator, and value matches.
| Field | Kind | Values | Search |
|---|---|---|---|
errorCode | eq |
| field:"aws::errorCode" kind:eq value:"Success" |
errorCode | is_null | field:"aws::errorCode" kind:is_null | |
eventName | eq |
| field:"aws::eventName" kind:eq value:"DeleteBucket" |