Title:
AWS KMS Imported Key Material Usage
Status:
experimental
Description:Detects the import or deletion of key material in AWS KMS, which can be used as part of ransomware attacks. This activity is uncommon and provides a high certainty signal.
References:
-https://www.chrisfarris.com/post/effective-aws-ransomware/
-https://docs.aws.amazon.com/kms/latest/developerguide/ct-importkeymaterial.html
-https://docs.aws.amazon.com/kms/latest/developerguide/ct-deleteimportedkeymaterial.html
Author: toopricey
Date: 2025-10-18
modified:None
Tags:
- -'attack.impact'
- -'attack.t1486'
- -'attack.resource-development'
- -'attack.t1608.003'
Logsource:
- product: aws
- service: cloudtrail
Detection:
selection:
eventSource:
'kms.amazonaws.com'
eventName:
-'ImportKeyMaterial'
-'DeleteImportedKeyMaterial'
condition:
selection
Falsepositives:
-Legitimate use cases for imported key material are rare, but may include, Organizations with hybrid cloud architectures that import external key material for compliance requirements.
-Development or testing environments that simulate external key management scenarios. Even in these cases, such activity is typically infrequent and should not add significant noise.
Level:
high