EnableSerialConsoleAccess
EnableSerialConsoleAccess
Event
Enables the regional account setting for serial-console access. It does not publish a key, establish a connection, or configure guest login. Organizational declarative policies can manage this setting and prevent an account-level change.
Security Context
An unexpected enablement may prepare an unauthorized remote-access path (contextual T1021), while troubleshooting is a common approved reason. IAM permissions, supported running instances, and guest prerequisites still apply. The serial path does not depend on ordinary instance SSH network reachability, but enablement alone is not a successful bypass or login.
Log Source
AWS CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: EnableSerialConsoleAccess. Check errorCode and errorMessage; a null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
awsRegion, recipientAccountId | Regional account scope of the setting. |
responseElements | Reported enabled state; nesting is illustrative. |
errorCode, errorMessage | Distinguish denied or centrally managed changes from success. |
eventTime, recipientAccountId, eventID, requestID | Timeline and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context, not a definitive attacker fingerprint. |
What to Investigate
- Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
- Verify regional access status and whether an organizational declarative policy manages it.
- Match the change to an approved troubleshooting task and supported target instance; inspect permissions and guest configuration.
- Correlate SendSerialConsoleSSHPublicKey and connection evidence. Do not infer host access from enablement alone.
Sample Event
Synthetic scenario. Draco requests regional enablement and the illustrative response reports true. The record contains no target instance or connection.
Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "AKIADRAC0MALF0YEXAMP5", "userName": "draco" }, "eventTime": "2026-04-15T21:01:47Z", "eventSource": "ec2.amazonaws.com", "eventName": "EnableSerialConsoleAccess", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": null, "responseElements": { "EnableSerialConsoleAccessResponse": { "requestId": "90000000-0000-4000-8000-000100111000", "serialConsoleAccessEnabled": true } }, "requestID": "90000000-0000-4000-8000-000100111000", "eventID": "90000000-0000-4000-8000-000100111001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Lateral Movement
- T1021 — Remote Services — Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.