elastic
medium
kql
AWS WAF Access Control List Deletion
Identifies the deletion of an AWS Web Application Firewall (WAF) Web ACL. Web ACLs are the core enforcement objects in
AWS WAF, defining which traffic is inspected, allowed, or blocked for protected applications. Deleting a Web ACL removes
all associated rules, protections, and logging configurations. Adversaries who obtain sufficient privileges may delete a
Web ACL to disable critical security controls, evade detection, or prepare for downstream attacks such as
web-application compromise, data