1 Answer
- Newest
- Most votes
- Most comments
-2
How to trace who performed this action
Use CloudTrail and check the delete event details: (userIdentity, sourceIPAddress eventTime etc.) this works if you have enabled CloudTrail events
Is it possible to recover deleted S3 data?
Only if Versioning was enabled before the deletion.
How to prevent this in future?
Enable S3 Versioning, enable CloudTrail data events for important buckets, use MFA if possible
Relevant content
- asked 2 years ago
- asked 5 years ago
- AWS OFFICIALUpdated 7 months ago
- AWS OFFICIALUpdated a year ago
- AWS OFFICIALUpdated 2 years ago
