Skip to content
Threat Feed
low advisory

Detection of Unauthorized AWS Lambda Function Deletion

This brief details a detection strategy for identifying the unauthorized deletion of AWS Lambda functions, a technique used by adversaries to disrupt operations, hide backdoors, or erase evidence.

Adversaries may delete AWS Lambda functions to disrupt business operations, destroy attacker-deployed backdoors, or remove evidence after achieving their objectives. Deleting a function is a destructive and often irreversible action that removes the code, configuration, published versions, and aliases of the function. This activity is frequently observed during security incidents where attackers attempt to inhibit incident response efforts or clean up their tracks. While legitimate Lambda function deletion occurs during routine environment teardowns, application decommissioning, and infrastructure-as-code (IaC) maintenance cycles, unexpected deletions performed by unauthorized principals should be flagged for review. Defenders can monitor AWS CloudTrail logs for 'DeleteFunction' events to identify potentially malicious activity, particularly when performed by principals that have not historically executed such operations.

Impact

Successful unauthorized deletion of Lambda functions can result in the immediate disruption of critical serverless workloads and automated workflows. If the functions contain proprietary code or backdoors, their deletion can also hinder forensic investigations by destroying evidence of the attacker's activities. Organizations should maintain backups in source control or infrastructure-as-code repositories to ensure rapid recovery.

Recommendation

  • Implement the provided detection logic to monitor AWS CloudTrail logs for 'DeleteFunction' events, specifically focusing on identities that have not previously performed this action.
  • Review and validate all Lambda function deletions that occur outside of approved change windows or maintenance periods.
  • Constrain 'lambda:DeleteFunction' permissions to a minimal set of trusted IAM roles and service accounts to reduce the attack surface.
  • Utilize IaC tools such as Terraform or Pulumi for function management and exclude these known service roles from the detection logic to reduce false positives.
  • Ensure all Lambda code, configurations, and environment variables are stored in version-controlled repositories to facilitate rapid restoration after accidental or malicious deletion.

Immediate actions

Deploy the Sigma detection rule to monitor for unauthorized function deletion.

Detection Engineering 48h

Threat Hunt

Search for all successful 'DeleteFunction' events in CloudTrail logs from the past 30 days to establish a baseline of authorized users and automation tools.

T1485 medium high confidence hunt now

Data: AWS CloudTrail logs

Mitigations

Review and audit IAM policies to ensure the 'lambda:DeleteFunction' permission is restricted to trusted principals only.

short_term IT Operations

Unauthorized resource destruction

Detection coverage 1

Detect AWS Lambda Function Deletion by Unusual User

low

Detects the first time a given identity in an AWS account successfully deletes a Lambda function, potentially indicating malicious activity or unauthorized disruption.

sigma tactics: impact techniques: T1485, T1489 sources: cloudtrail, aws

Detection queries are available on the platform. Get full rules →