AWS CloudTrail S3 DeleteBucket Events with Successful Deletion

Flags successful CloudTrail DeleteBucket events indicating an S3 bucket was removed.

FreeReviewedSigma · Medium · v5
Product
aws
Service
cloudtrail
Author
Ivan Saakov, Nasreddine Bencherchali (SigmaHQ), DRL 1.1
Published
2025-10-19
Updated
2026-07-31

What it detects

This rule identifies S3 bucket deletion activity by matching CloudTrail events where the event name is DeleteBucket and the operation completed successfully. Bucket deletion is a high-impact action that can indicate attempted data loss or unauthorized resource removal. It relies on CloudTrail telemetry fields for eventName and errorCode, including handling for both explicit Success and null errorCode values.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.