CanDelete

Destructive; persistence/impact not escalation. Excluded from default paths. Produced by explicit normalization (delete-permission IAM actions) and by derived rules (evasion/cover-tracks primitives like disabling detective services).

resource_control CONTROL nature: both not walkable
Identity  ── CanDelete ──▸  *

Source types

Identity

Target types

*

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

natureboth

Rules that emit CanDelete 24

Delete an Access Analyzer, removing all findings and disabling ongoing IAM access analysis for the zone of trust - a hard delete of a detective control that reduces detection fidelity without granting access (non-walkable edge).
awsderived
Principal with cloudtrail:DeleteTrail can permanently destroy a trail, creating an irreversible audit blind spot. Existing S3 log objects are unaffected; only future event capture is eliminated.
awsderived
Principal with cloudtrail:DeleteEventDataStore can permanently destroy a CloudTrail Lake event data store, eliminating the long-term audit retention store for the organization. This is a high-impact anti-forensic primitive.
awsderived
cloudwatch:DeleteAlarms permanently removes one or more CloudWatch alarms, eliminating the detective control entirely - a higher-impact, more-detectable evasion than DisableAlarmActions.
awsderived
logs:DeleteLogGroup permanently deletes a log group and all its stored events - evidence destruction that eliminates forensic audit records.
awsderived
IAM principal with directconnect:DeleteVirtualInterface can disrupt existing Direct Connect routing (availability impact, not escalation).
awsderived
A principal with fms:DeletePolicy can permanently delete an existing Firewall Manager policy, eliminating org-wide enforcement of WAF/Shield/Security Group/ Network Firewall/DNS Firewall controls across all in-scope member accounts. This is an irreversible destructive action with maximum blast radius.
awsderived
A principal with fms:DeleteNotificationChannel can permanently remove the SNS topic that receives FMS compliance notifications, creating an irreversible silent-running state for FMS enforcement.
awsderived
Delete the GuardDuty detector, permanently eliminating threat detection in the account/region.
awsderived
Disabling Macie (macie2:DisableMacie) permanently disables the service, deletes all configurations and findings, and removes sensitive-data classification from the account - a weaken-defenses / cover-tracks / destructive primitive.
awsderived
Permanently delete a customer-managed Rule Group, breaking all Web ACLs that reference it (requires prior removal of all associations).
awsderived
Permanently delete a Web ACL, removing WAF protection from all previously associated resources (requires prior disassociation).
awsderived
Delete a Log Analytics workspace, destroying all ingested log evidence (defense evasion - cover tracks). Soft-delete for 14 days unless purge is forced. This is resource destruction (CanDelete), not data-row deletion (CanDeleteData). CanDeleteData target set [Storage, Data] excludes LoggingService (ManagementService), so CanDelete (target=*) is semantically correct for resource-level destruction.
azurederived
Purge specific log data from a Log Analytics workspace (irreversible - targeted evidence destruction). The purge/action operation is data-plane irreversible row deletion within an existing workspace (distinct from workspaces/delete which destroys the workspace resource). CanDeleteData target set [Storage, Data] excludes LoggingService (ManagementService), so CanDelete (target=*) is the correct fallback to model data-plane row deletion capability.
azurederived
Delete a diagnostic setting on an Azure resource or at subscription scope, stopping export of that resource's (or subscription's) Activity Log and resource logs to a Log Analytics workspace, storage account, or Event Hub. Headline defense-evasion primitive: subsequent attacker API activity goes unrecorded in the monitored scope.
azurederived
Delete the subscription-level Activity Log export profile (legacy Microsoft.Insights/logProfiles), stopping archive of all ARM management-plane events for the entire subscription.
azurederived
Delete a scheduled query (log search) alert rule, silencing automated detection based on KQL log queries - disables alerting on specific threat patterns or compliance baselines.
azurederived
Delete a metric alert rule, silencing automated detection triggered by metric thresholds (CPU, memory, network, custom metrics). Metric alerts fire independently of log-search alerts and are on distinct ARM resource types.
azurederived
Delete an activity log alert rule, silencing automated detection triggered by Azure Resource Manager (ARM) control-plane events (resource creation, deletion, policy changes, role assignments). Activity log alerts are distinct from scheduled-query and metric alerts, on their own ARM resource type.
azurederived
Delete an action group, silencing the response actions (email, SMS, webhook, Azure Function, Logic App, Automation Runbook) for ALL alert rules that reference it - a high-blast-radius evasion against automated incident response.
azurederived
Delete a policy assignment, removing the guardrail at that scope. For Deny-effect assignments this unblocks all previously-denied ARM operations at the scope. Destructive impact (cover-tracks); not modeled as escalation.
azurederived
Delete a custom or _Default log bucket (logging.buckets.delete), permanently destroying all retained log history stored in it.
gcpderived
An identity with compute.forwardingRules.delete on a PSC consumer endpoint (forwarding rule with purpose=PRIVATE_SERVICE_CONNECT) can remove it. This is a destructive capability that disrupts private connectivity to the producer service, purely an availability impact rather than privilege escalation or data access.
gcpexplicit
move · open · esc close