Skip to content
Threat Feed
medium advisory

Monitoring Unauthorized Amazon EFS File System Deletion

Adversaries with high-privilege access can leverage the DeleteFileSystem API to permanently destroy data, disrupt cloud-native applications, or remove forensic evidence.

The deletion of an Amazon Elastic File System (EFS) via the DeleteFileSystem API is an irreversible operation that permanently removes all stored data. While legitimate lifecycle management and teardown workflows utilize this API, adversaries who have compromised cloud credentials can exploit this functionality to perform intentional data destruction, disrupt business operations, or engage in anti-forensic cleanup to impede incident response.

Defenders must differentiate between authorized automated infrastructure-as-code (IaC) workflows - typically originating from known service roles or CI/CD pipelines - and unauthorized manual invocations of this API. This threat is particularly critical for production environments where EFS provides shared storage for persistent applications, container workloads, and analytics pipelines. Monitoring for this event in CloudTrail is essential for detecting post-compromise activity or malicious preparation for ransomware scenarios.

Impact

Successful unauthorized execution of DeleteFileSystem results in total loss of stored file system data. This can cause immediate service disruption for dependent EC2 instances, ECS tasks, and serverless compute workloads. Depending on the organization's backup configuration, data may not be recoverable if AWS Backup policies were either absent or intentionally disabled by the attacker prior to the deletion event.

Recommendation

  • Deploy the provided Sigma-compatible detection logic to SIEM platforms to monitor for DeleteFileSystem events, ensuring filters are tuned to ignore known CI/CD automation principals (e.g., Terraform, Pulumi).
  • Restrict the elasticfilesystem:DeleteFileSystem IAM permission to specific, highly privileged administrative roles and implement condition keys such as aws:SourceIp or aws:PrincipalArn to prevent unauthorized execution.
  • Enable AWS Backup for all production EFS file systems and monitor for modifications to backup plans using AWS Config or Security Hub to ensure data remains recoverable.
  • Use CloudTrail alerts to notify the Security Operations Center (SOC) of any DeleteFileSystem events occurring outside of established change windows or from unusual IP addresses.

Immediate actions

Deploy the EFS deletion detection rule to SIEM environment.

Detection Engineering 48h

Mitigations

Restrict DeleteFileSystem permissions via IAM policy.

immediate IT Operations

T1485

Detection coverage 1

Detect Unauthorized AWS EFS File System Deletion

medium

Detects successful execution of the DeleteFileSystem API operation, which is a high-impact destructive action. Filtered to exclude common IaC tooling.

sigma tactics: impact techniques: T1485 sources: cloud_api, aws

Detection queries are available on the platform. Get full rules →