GetPasswordData
GetPasswordData
Event
Retrieves encrypted administrator-password data generated for a Windows instance. Decryption requires the private key corresponding to the launch key pair. Generation can take several minutes; the API may return an empty passwordData value while unavailable. Retrieval does not reset or reveal the current password in plaintext.
Security Context
Unexpected reads can be part of credential access (contextual T1552), but routine Windows administration also uses this API. Establish availability of password data, possession of the matching private key, and successful host authentication separately.
Log Source
AWS CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: GetPasswordData. Check errorCode and errorMessage; a null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.instanceId | Target Windows instance; resolve launch key and provisioning history. |
requestParameters.dryRun | When present, a permission probe rather than retrieval. |
responseElements | A null log response does not prove a nonempty password blob was returned. |
eventTime, recipientAccountId, eventID, requestID | Timeline and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context, not a definitive attacker fingerprint. |
What to Investigate
- Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
- Confirm the target platform, launch history, and approved administrative task.
- Establish whether encrypted data was available and whether the corresponding private key could have been accessed. Do not assume a prior secret-store read contained that key.
- Correlate Windows authentication and network activity with GetSecretValue only where there is an evidenced relationship.
Sample Event
Synthetic scenario. Draco requests password data for a fictional Windows instance. The sample shows neither decryption nor the alleged prior theft of a launch key.
Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "AKIADRAC0MALF0YEXAMP5", "userName": "draco" }, "eventTime": "2026-04-15T21:48:31Z", "eventSource": "ec2.amazonaws.com", "eventName": "GetPasswordData", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "instanceId": "i-0fedcba9876543210" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000101000010", "eventID": "90000000-0000-4000-8000-000101000011", "readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Credential Access
- T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...