GetSecretValue
GetSecretValue
Event
Returns SecretString or SecretBinary for a selected secret version; AWSCURRENT is used if neither version selector is supplied. If both versionId and versionStage are specified they must refer to the same version. Access requires secretsmanager:GetSecretValue and, for a customer-managed KMS key, kms:Decrypt authorization.
Security Context
Unauthorized retrieval of credentials maps to T1555.006. Applications routinely read secrets, so the event alone does not prove theft or discovery. Secret contents are excluded from CloudTrail; a name suggesting database access does not show the actual credential or prove a later database connection.
Log Source
AWS CloudTrail management event with eventSource: secretsmanager.amazonaws.com and eventName: GetSecretValue. Check errorCode and errorMessage; a null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.secretId | Target secret name or ARN; cross-account reads require an ARN. |
requestParameters.versionId, versionStage | Selected version; correlate with rotation history. |
userIdentity, resources | Caller and target resource context. |
eventTime, recipientAccountId, eventID, requestID | Timeline and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context, not a definitive attacker fingerprint. |
What to Investigate
- Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
- Compare the caller, target, timing, and volume with the application’s expected access pattern.
- Check the operation outcome and applicable secret/KMS policies. CloudTrail does not provide the secret value, and null responseElements does not indicate failure.
- Correlate use of the underlying credential with downstream service authentication and rotation history; do not invent a follow-on intrusion.
Sample Event
Synthetic scenario. Draco requests AWSCURRENT for bowtruckle/prod/db. This illustrates a read of a sensitive target, not proven exfiltration or a later RDS session.
Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "AKIADRAC0MALF0YEXAMP5", "userName": "draco" }, "eventTime": "2026-04-15T21:54:46Z", "eventSource": "secretsmanager.amazonaws.com", "eventName": "GetSecretValue", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "secretId": "arn:aws:secretsmanager:us-east-1:555123456789:secret:bowtruckle/prod/db-AbCdEf", "versionStage": "AWSCURRENT" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000101000100", "eventID": "90000000-0000-4000-8000-000101000101", "readOnly": true, "resources": [ { "accountId": "555123456789", "type": "AWS::SecretsManager::Secret", "ARN": "arn:aws:secretsmanager:us-east-1:555123456789:secret:bowtruckle/prod/db-AbCdEf" } ], "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "secretsmanager.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Credential Access
- T1555.006 — Cloud Secrets Management Stores — Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Terraform Vault.