Skip to content

CreateKeyPair

AWS

CreateKeyPair

service: AWS - EC2
techniques:

Event

Creates a regional EC2 key pair. The private key is returned at creation to the API caller and must be saved then; do not expect to retrieve it later from EC2. Neither operation installs a key into existing guest authorized_keys files. Launch configuration or a separate host change is needed. EC2 key pairs can support Linux SSH or Windows password decryption, depending on key type and platform.

Security Context

Unauthorized key preparation can support persistence when a key is actually installed for host authentication. T1098.004 is contextual to that later use; registering a key alone is not SSH lateral movement. Routine provisioning is common, and host/network access still matters.

Log Source

AWS CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: CreateKeyPair. Check errorCode and errorMessage; a null response alone does not establish success or failure.

Key Fields

FieldInvestigation value
requestParameters.keyNameRegional key-pair name; not proof of deployment to a host.
requestParameters.keyType, keyFormatRequested key algorithm and private-key output format.
responseElements.keyPairId, keyFingerprintCorrelation identifiers; the CloudTrail response is not a private-key backup.
eventTime, recipientAccountId, eventID, requestIDTimeline and correlation identifiers.
sourceIPAddress, userAgentSupporting context, not a definitive attacker fingerprint.

What to Investigate

  1. Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
  2. Match the caller and key ownership to approved provisioning. Determine whether the intended platform supports the key type.
  3. Find launches referencing this key and separate evidence of changes to existing hosts; creating/importing a key does not update those hosts automatically.
  4. Correlate actual SSH authentication and SendSSHPublicKey where relevant. Passing an IAM role is a separate requirement only when a role is assigned.

Sample Event

Synthetic scenario. Draco creates draco-backup-666. The sample does not show a launch or installation on an existing host.

Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T23:21:08Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "CreateKeyPair",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"keyName": "draco-backup-666",
"keyType": "rsa",
"keyFormat": "pem"
},
"responseElements": {
"requestId": "90000000-0000-4000-8000-000010001110",
"keyName": "draco-backup-666",
"keyFingerprint": "1f:51:ae:28:bf:89:e9:d8:1f:25:5d:37:2d:7d:b8:ca:9f:f5:f1:6f",
"keyPairId": "key-0123456789abcdef0"
},
"requestID": "90000000-0000-4000-8000-000010001110",
"eventID": "90000000-0000-4000-8000-000010001111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098.004 — SSH Authorized Keys — Adversaries may modify the SSH <code>authorized_keys</code> file to maintain persistence on a victim host. Linux distributions, macOS, and ESXi hypervisors commonly use key-based authentication to secure the authentication process of SSH sessions for remote management. The <code>authorized_keys</...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.