Skip to content

DisableKey

AWS

DisableKey

service: AWS - KMS
tactics:
techniques:

Event

Changes an eligible KMS key to Disabled. This is a KMS key, not a plaintext data key. It does not erase ciphertext or key material and can be reversed with EnableKey. Management operations remain possible; service behavior and cached data keys affect when workloads experience failures. Multi-Region related keys have independent enabled states.

Security Context

Unauthorized disablement may disrupt dependent services (contextual T1489). Incident containment and key administration also disable keys. Do not promise immediate universal data inaccessibility or one error type across all services.

Log Source

CloudTrail management event with eventSource: kms.amazonaws.com and eventName: DisableKey. Check errors and resulting resource state; a null response does not by itself indicate failure.

Key Fields

FieldInvestigation value
requestParameters.keyId, resourcesTarget key/account/Region and resolved ARN.
userIdentity, eventTimeCaller and timing for correlation with actual service failures.
eventTime, awsRegion, recipientAccountId, eventIDTimeline, service Region, account, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Verify the resulting key state and authorized maintenance/containment context.
  3. Inventory real key dependencies, cached access, and related regional keys; inspect observed failures rather than inferring them.
  4. Correlate later EnableKey or ScheduleKeyDeletion and assess recoverability separately from disabling.

Sample Event

Synthetic scenario. Draco disables a fictional KMS key. The sample does not establish all dependent resources or instantaneous failures across S3, EBS, and RDS.

Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T20:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:31:18Z",
"eventSource": "kms.amazonaws.com",
"eventName": "DisableKey",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"keyId": "60000000-0000-4000-8000-000000000001"
},
"responseElements": {
"keyId": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000001"
},
"requestID": "90000000-0000-4000-8000-000100110000",
"eventID": "90000000-0000-4000-8000-000100110001",
"readOnly": false,
"resources": [
{
"accountId": "555123456789",
"type": "AWS::KMS::Key",
"ARN": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000001"
}
],
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "kms.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1489 — Service Stop — Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services or processes can inhibit or stop response to an incident or aid in the adversary's overall objectives to cause damage to the environment.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.