Skip to content

GetSecretValue

AWS

GetSecretValue

service: AWS - SecretsManager
techniques:

Event

Returns SecretString or SecretBinary for a selected secret version; AWSCURRENT is used if neither version selector is supplied. If both versionId and versionStage are specified they must refer to the same version. Access requires secretsmanager:GetSecretValue and, for a customer-managed KMS key, kms:Decrypt authorization.

Security Context

Unauthorized retrieval of credentials maps to T1555.006. Applications routinely read secrets, so the event alone does not prove theft or discovery. Secret contents are excluded from CloudTrail; a name suggesting database access does not show the actual credential or prove a later database connection.

Log Source

AWS CloudTrail management event with eventSource: secretsmanager.amazonaws.com and eventName: GetSecretValue. Check errorCode and errorMessage; a null response alone does not establish success or failure.

Key Fields

FieldInvestigation value
requestParameters.secretIdTarget secret name or ARN; cross-account reads require an ARN.
requestParameters.versionId, versionStageSelected version; correlate with rotation history.
userIdentity, resourcesCaller and target resource context.
eventTime, recipientAccountId, eventID, requestIDTimeline and correlation identifiers.
sourceIPAddress, userAgentSupporting context, not a definitive attacker fingerprint.

What to Investigate

  1. Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
  2. Compare the caller, target, timing, and volume with the application’s expected access pattern.
  3. Check the operation outcome and applicable secret/KMS policies. CloudTrail does not provide the secret value, and null responseElements does not indicate failure.
  4. Correlate use of the underlying credential with downstream service authentication and rotation history; do not invent a follow-on intrusion.

Sample Event

Synthetic scenario. Draco requests AWSCURRENT for bowtruckle/prod/db. This illustrates a read of a sensitive target, not proven exfiltration or a later RDS session.

Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "AKIADRAC0MALF0YEXAMP5",
"userName": "draco"
},
"eventTime": "2026-04-15T21:54:46Z",
"eventSource": "secretsmanager.amazonaws.com",
"eventName": "GetSecretValue",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"secretId": "arn:aws:secretsmanager:us-east-1:555123456789:secret:bowtruckle/prod/db-AbCdEf",
"versionStage": "AWSCURRENT"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000101000100",
"eventID": "90000000-0000-4000-8000-000101000101",
"readOnly": true,
"resources": [
{
"accountId": "555123456789",
"type": "AWS::SecretsManager::Secret",
"ARN": "arn:aws:secretsmanager:us-east-1:555123456789:secret:bowtruckle/prod/db-AbCdEf"
}
],
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "secretsmanager.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Credential Access

Techniques:
  • T1555.006 — Cloud Secrets Management Stores — Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Terraform Vault.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.