Detection of Unauthorized AWS Lambda Function Deletion
This brief details a detection strategy for identifying the unauthorized deletion of AWS Lambda functions, a technique used by adversaries to disrupt operations, hide backdoors, or erase evidence.
Adversaries may delete AWS Lambda functions to disrupt business operations, destroy attacker-deployed backdoors, or remove evidence after achieving their objectives. Deleting a function is a destructive and often irreversible action that removes the code, configuration, published versions, and aliases of the function. This activity is frequently observed during security incidents where attackers attempt to inhibit incident response efforts or clean up their tracks. While legitimate Lambda function deletion occurs during routine environment teardowns, application decommissioning, and infrastructure-as-code (IaC) maintenance cycles, unexpected deletions performed by unauthorized principals should be flagged for review. Defenders can monitor AWS CloudTrail logs for 'DeleteFunction' events to identify potentially malicious activity, particularly when performed by principals that have not historically executed such operations.
Impact
Successful unauthorized deletion of Lambda functions can result in the immediate disruption of critical serverless workloads and automated workflows. If the functions contain proprietary code or backdoors, their deletion can also hinder forensic investigations by destroying evidence of the attacker's activities. Organizations should maintain backups in source control or infrastructure-as-code repositories to ensure rapid recovery.
Recommendation
- Implement the provided detection logic to monitor AWS CloudTrail logs for 'DeleteFunction' events, specifically focusing on identities that have not previously performed this action.
- Review and validate all Lambda function deletions that occur outside of approved change windows or maintenance periods.
- Constrain 'lambda:DeleteFunction' permissions to a minimal set of trusted IAM roles and service accounts to reduce the attack surface.
- Utilize IaC tools such as Terraform or Pulumi for function management and exclude these known service roles from the detection logic to reduce false positives.
- Ensure all Lambda code, configurations, and environment variables are stored in version-controlled repositories to facilitate rapid restoration after accidental or malicious deletion.
Immediate actions
Deploy the Sigma detection rule to monitor for unauthorized function deletion.
Threat Hunt
Search for all successful 'DeleteFunction' events in CloudTrail logs from the past 30 days to establish a baseline of authorized users and automation tools.
Data: AWS CloudTrail logs
Mitigations
Review and audit IAM policies to ensure the 'lambda:DeleteFunction' permission is restricted to trusted principals only.
Unauthorized resource destruction
Detection coverage 1
Detect AWS Lambda Function Deletion by Unusual User
lowDetects the first time a given identity in an AWS account successfully deletes a Lambda function, potentially indicating malicious activity or unauthorized disruption.
Detection queries are available on the platform. Get full rules →