ImportKeyPair
ImportKeyPair
Event
Imports public key material as a regional EC2 key pair. The caller retains the separately generated private key; importing does not upload or recover it. Neither operation installs a key into existing guest authorized_keys files. Launch configuration or a separate host change is needed. EC2 key pairs can support Linux SSH or Windows password decryption, depending on key type and platform.
Security Context
Unauthorized key preparation can support persistence when a key is actually installed for host authentication. T1098.004 is contextual to that later use; registering a key alone is not SSH lateral movement. Routine provisioning is common, and host/network access still matters.
Log Source
AWS CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: ImportKeyPair. Check errorCode and errorMessage; a null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.keyName | Regional key-pair name; not proof of deployment to a host. |
requestParameters.publicKeyMaterial | Imported public key; inspect the encoding and fingerprint without treating it as a secret key. |
responseElements.keyPairId, keyFingerprint | Correlation identifiers; the CloudTrail response is not a private-key backup. |
eventTime, recipientAccountId, eventID, requestID | Timeline and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context, not a definitive attacker fingerprint. |
What to Investigate
- Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
- Match the caller and key ownership to approved provisioning. Determine whether the intended platform supports the key type.
- Find launches referencing this key and separate evidence of changes to existing hosts; creating/importing a key does not update those hosts automatically.
- Correlate actual SSH authentication and SendSSHPublicKey where relevant. Passing an IAM role is a separate requirement only when a role is assigned.
Sample Event
Synthetic scenario. Draco registers a public test key as draco-persistence-key. No matching launch or SSH session is shown; the example key must never be used for real access.
Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "AKIADRAC0MALF0YEXAMP5", "userName": "draco" }, "eventTime": "2026-04-15T22:02:17Z", "eventSource": "ec2.amazonaws.com", "eventName": "ImportKeyPair", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "keyName": "draco-persistence-key", "publicKeyMaterial": "c3NoLWVkMjU1MTkgQUFBQUMzTnphQzFsWkRJMU5URTVBQUFBSU5kYW1BR0NzUXEzMVV2KzA4bGtCem9PNFhMejJxWWpKYThDR21qM0IxRWEgc3ludGhldGljLXB1YmxpYy10ZXN0LWtleQ==" }, "responseElements": { "requestId": "90000000-0000-4000-8000-000101001010", "keyName": "draco-persistence-key", "keyFingerprint": "bbXpuKG6zhzdmnxq256TlqzFBzRl2f6OOg722cYNbU8", "keyPairId": "key-0badcafe000000666" }, "requestID": "90000000-0000-4000-8000-000101001010", "eventID": "90000000-0000-4000-8000-000101001011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098.004 — SSH Authorized Keys — Adversaries may modify the SSH <code>authorized_keys</code> file to maintain persistence on a victim host. Linux distributions, macOS, and ESXi hypervisors commonly use key-based authentication to secure the authentication process of SSH sessions for remote management. The <code>authorized_keys</...