DisableKey
DisableKey
Event
Changes an eligible KMS key to Disabled. This is a KMS key, not a plaintext data key. It does not erase ciphertext or key material and can be reversed with EnableKey. Management operations remain possible; service behavior and cached data keys affect when workloads experience failures. Multi-Region related keys have independent enabled states.
Security Context
Unauthorized disablement may disrupt dependent services (contextual T1489). Incident containment and key administration also disable keys. Do not promise immediate universal data inaccessibility or one error type across all services.
Log Source
CloudTrail management event with eventSource: kms.amazonaws.com and eventName: DisableKey. Check errors and resulting resource state; a null response does not by itself indicate failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.keyId, resources | Target key/account/Region and resolved ARN. |
userIdentity, eventTime | Caller and timing for correlation with actual service failures. |
eventTime, awsRegion, recipientAccountId, eventID | Timeline, service Region, account, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Verify the resulting key state and authorized maintenance/containment context.
- Inventory real key dependencies, cached access, and related regional keys; inspect observed failures rather than inferring them.
- Correlate later EnableKey or ScheduleKeyDeletion and assess recoverability separately from disabling.
Sample Event
Synthetic scenario. Draco disables a fictional KMS key. The sample does not establish all dependent resources or instantaneous failures across S3, EBS, and RDS.
Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T20:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:31:18Z", "eventSource": "kms.amazonaws.com", "eventName": "DisableKey", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "keyId": "60000000-0000-4000-8000-000000000001" }, "responseElements": { "keyId": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000001" }, "requestID": "90000000-0000-4000-8000-000100110000", "eventID": "90000000-0000-4000-8000-000100110001", "readOnly": false, "resources": [ { "accountId": "555123456789", "type": "AWS::KMS::Key", "ARN": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000001" } ], "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "kms.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1489 — Service Stop — Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services or processes can inhibit or stop response to an incident or aid in the adversary's overall objectives to cause damage to the environment.