Skip to content

GetPasswordData

AWS

GetPasswordData

service: AWS - EC2
techniques:

Event

Retrieves encrypted administrator-password data generated for a Windows instance. Decryption requires the private key corresponding to the launch key pair. Generation can take several minutes; the API may return an empty passwordData value while unavailable. Retrieval does not reset or reveal the current password in plaintext.

Security Context

Unexpected reads can be part of credential access (contextual T1552), but routine Windows administration also uses this API. Establish availability of password data, possession of the matching private key, and successful host authentication separately.

Log Source

AWS CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: GetPasswordData. Check errorCode and errorMessage; a null response alone does not establish success or failure.

Key Fields

FieldInvestigation value
requestParameters.instanceIdTarget Windows instance; resolve launch key and provisioning history.
requestParameters.dryRunWhen present, a permission probe rather than retrieval.
responseElementsA null log response does not prove a nonempty password blob was returned.
eventTime, recipientAccountId, eventID, requestIDTimeline and correlation identifiers.
sourceIPAddress, userAgentSupporting context, not a definitive attacker fingerprint.

What to Investigate

  1. Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
  2. Confirm the target platform, launch history, and approved administrative task.
  3. Establish whether encrypted data was available and whether the corresponding private key could have been accessed. Do not assume a prior secret-store read contained that key.
  4. Correlate Windows authentication and network activity with GetSecretValue only where there is an evidenced relationship.

Sample Event

Synthetic scenario. Draco requests password data for a fictional Windows instance. The sample shows neither decryption nor the alleged prior theft of a launch key.

Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "AKIADRAC0MALF0YEXAMP5",
"userName": "draco"
},
"eventTime": "2026-04-15T21:48:31Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "GetPasswordData",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"instanceId": "i-0fedcba9876543210"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000101000010",
"eventID": "90000000-0000-4000-8000-000101000011",
"readOnly": true,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Credential Access

Techniques:
  • T1552 — Unsecured Credentials — Adversaries may search compromised systems to find and obtain insecurely stored credentials. These credentials can be stored and/or misplaced in many locations on a system, including plaintext files (e.g. [Shell History](https://attack.mitre.org/techniques/T1552/003)), operating system or applica...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.