Anti-Forensics
Account Misuse
Audit Trail Saturation
Clear Browser Artifacts
Clear Email Artifacts
Code Contribution Obfuscation and Misrepresentation
Cross-System Activity Fragmentation
Decrease Privileges
Delayed Execution Triggers
Delete User Account
Deletion of Volume Shadow Copy
Disable Logging
Disk Wiping
File Deletion
File Encryption
Hide Artifacts
Hiding or Destroying Command History
Incremental Data Collection
Log Deletion
Log Modification
Message Deletion
Message Modification
Modify Windows Registry
Network Obfuscation
Parent Process ID Spoofing
Physical Destruction of Storage Media
Physical Removal of Disk Storage
Retention Window Exploitation
Rootkit
Stalling
Steganography
System Shutdown
System Time Modification
Timestomping
Tripwires
Trusted Tool Misuse
Uninstalling Software
Virtualization
- ID: AF013.005
- Created: 05th August 2026
- Updated: 05th August 2026
- Platforms: Oracle Cloud Infrastructure (OCI)Google Cloud Platform (GCP)Microsoft AzureAmazon Web Services (AWS)
- Contributor: The ITM Team
Delete Cloud User Account
A subject deletes a cloud user account to conceal activity, disrupt attribution, remove access associations, interfere with an investigation, or remove information connected to the account. The deleted identity may be maintained within a cloud platform, cloud identity provider, or Software as a Service application and may include a member or guest account.
Deletion may be performed through an administration portal, command-line interface, Application Programming Interface (API), script, or automated identity-lifecycle workflow. Investigators should identify the initiating subject, target identity, deletion method, source address, privileged role used, approval record, and deletion time. They should also preserve and review the account’s prior authentication activity, group and role memberships, authentication methods, licenses, owned resources, mailbox or storage data, and recovery status. Cloud identity platforms retain audit records capable of identifying changes to users and other directory objects, while services such as AWS CloudTrail record account activity involving the creation, modification, or deletion of Identity and Access Management resources.
Routine account deletion performed through an authorized offboarding or identity-governance process should not be classified as anti-forensic activity. Classification should require evidence that the deletion was unauthorized, concealed, inconsistent with the approved lifecycle process, or intended to frustrate attribution or preservation.