Skip to content

EnableSerialConsoleAccess

AWS

EnableSerialConsoleAccess

service: AWS - EC2
techniques:

Event

Enables the regional account setting for serial-console access. It does not publish a key, establish a connection, or configure guest login. Organizational declarative policies can manage this setting and prevent an account-level change.

Security Context

An unexpected enablement may prepare an unauthorized remote-access path (contextual T1021), while troubleshooting is a common approved reason. IAM permissions, supported running instances, and guest prerequisites still apply. The serial path does not depend on ordinary instance SSH network reachability, but enablement alone is not a successful bypass or login.

Log Source

AWS CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: EnableSerialConsoleAccess. Check errorCode and errorMessage; a null response alone does not establish success or failure.

Key Fields

FieldInvestigation value
awsRegion, recipientAccountIdRegional account scope of the setting.
responseElementsReported enabled state; nesting is illustrative.
errorCode, errorMessageDistinguish denied or centrally managed changes from success.
eventTime, recipientAccountId, eventID, requestIDTimeline and correlation identifiers.
sourceIPAddress, userAgentSupporting context, not a definitive attacker fingerprint.

What to Investigate

  1. Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
  2. Verify regional access status and whether an organizational declarative policy manages it.
  3. Match the change to an approved troubleshooting task and supported target instance; inspect permissions and guest configuration.
  4. Correlate SendSerialConsoleSSHPublicKey and connection evidence. Do not infer host access from enablement alone.

Sample Event

Synthetic scenario. Draco requests regional enablement and the illustrative response reports true. The record contains no target instance or connection.

Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "AKIADRAC0MALF0YEXAMP5",
"userName": "draco"
},
"eventTime": "2026-04-15T21:01:47Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "EnableSerialConsoleAccess",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": null,
"responseElements": {
"EnableSerialConsoleAccessResponse": {
"requestId": "90000000-0000-4000-8000-000100111000",
"serialConsoleAccessEnabled": true
}
},
"requestID": "90000000-0000-4000-8000-000100111000",
"eventID": "90000000-0000-4000-8000-000100111001",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Lateral Movement

Techniques:
  • T1021 — Remote Services — Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into a service that accepts remote connections, such as telnet, SSH, and VNC. The adversary may then perform actions as the logged-on user.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.