GetParameters
GetParameters
Event
Retrieves specified parameter names, optionally with version or label selectors. withDecryption applies to SecureString and is ignored for String and StringList. The API can return valid parameters together with InvalidParameters; a successful request does not mean every requested name was returned.
Security Context
Unauthorized retrieval of stored credentials can match T1555.006. Decryption is also routine application behavior and is not proof of harvesting. Parameter names do not establish type or content. This is a named-value read, not inherently cloud-service enumeration.
Log Source
AWS CloudTrail management event with eventSource: ssm.amazonaws.com and eventName: GetParameters. Check errorCode and errorMessage; a null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.names | Requested parameters and any selectors; verify type and historical version. |
requestParameters.withDecryption | Decryption request, not evidence of malicious intent or successful decryption. |
responseElements | Values and per-name outcomes may be unavailable in CloudTrail; do not infer all-name success. |
eventTime, recipientAccountId, eventID, requestID | Timeline and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context, not a definitive attacker fingerprint. |
What to Investigate
- Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
- Check expected workload access and resolve the requested names to historical types, versions, and sensitivity.
- Assess SSM and KMS authorization and per-name outcomes using available application evidence; protect returned values rather than copying them into logs.
- Correlate subsequent use of any credentials with the relevant service logs. Compare GetSecretValue only when targets or callers establish a relationship.
Sample Event
Synthetic scenario. Draco requests three named parameters with decryption enabled. The sample does not prove they were all SecureString, all returned, or read using stolen instance credentials.
Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "AssumedRole", "principalId": "AROAOCCAMYP1PEL1NE02:i-0123456789abcdef0", "arn": "arn:aws:sts::555123456789:assumed-role/OccamyPipelineRole/i-0123456789abcdef0", "accountId": "555123456789", "accessKeyId": "ASIAOCCAMY1MDS5SESS01", "sessionContext": { "sessionIssuer": { "type": "Role", "principalId": "AROAOCCAMYP1PEL1NE02", "arn": "arn:aws:iam::555123456789:role/OccamyPipelineRole", "accountId": "555123456789", "userName": "OccamyPipelineRole" }, "attributes": { "creationDate": "2026-04-15T21:09:14Z", "mfaAuthenticated": "false" }, "ec2RoleDelivery": "2.0" } }, "eventTime": "2026-04-15T21:34:11Z", "eventSource": "ssm.amazonaws.com", "eventName": "GetParameters", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "names": [ "/bowtruckle/prod/db/master-password", "/bowtruckle/prod/api/stripe-webhook-secret", "/bowtruckle/prod/oauth/google-client-secret" ], "withDecryption": true }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000101000000", "eventID": "90000000-0000-4000-8000-000101000001", "readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Credential Access
- T1555.006 — Cloud Secrets Management Stores — Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Terraform Vault.