Data Destruction: Lifecycle-Triggered Deletion T1485.001
Tactic: Impact
Adversaries may modify the lifecycle policies of a cloud storage bucket to destroy all objects stored within.
Authoring guide
These 5 rules share fields, values, and exclusions.
Fields filtered most (10 distinct)
These fields appear most often in rule filters.
Top indicator values (14 distinct)
These values appear most often in rule predicates.
Exclusions (3 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Platform: AWS
Domain: Cloud
Elastic 3 rules
- AWS KMS Customer Managed Key Disabled or Scheduled for Deletion
- AWS KMS Imported Key Material Deleted
- AWS S3 Bucket Expiration Lifecycle Configuration Added