PutKeyPolicy
PutKeyPolicy
Event
Replaces the named key policy, normally default. It can broaden or restrict access. Cross-account use requires key-policy authorization and external IAM authorization and is supported only for designated KMS operations; kms:* does not enable every administrative operation across accounts. The lockout safety check addresses future policy administration, not whether a policy is least privilege.
Security Context
Unauthorized policy changes can manipulate access (T1098), but approved key administration is routine. Account-principal delegation does not give everyone in that account automatic decryption rights. KMS authorization does not itself supply ciphertext, access to storage, or satisfy encryption-context conditions.
Log Source
CloudTrail management event with eventSource: kms.amazonaws.com and eventName: PutKeyPolicy. Check errors and resulting resource state; a null response does not by itself indicate failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.keyId, policyName | Target KMS key and policy. |
requestParameters.policy | Full replacement document; parse the embedded JSON. |
requestParameters.bypassPolicyLockoutSafetyCheck | Whether the policy-administration safety check was bypassed. |
eventTime, awsRegion, recipientAccountId, eventID | Timeline, service Region, account, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Compare prior/new statements, including removed administrators, conditions, and denies.
- Check external identities’ IAM authorization, supported operations, grants, key state, and access to relevant encrypted data.
- Correlate actual cryptographic use and GetObject where appropriate. A policy update alone is not data extraction.
Sample Event
Synthetic scenario. Draco submits a policy delegating kms:* to an external account while retaining the owner-account statement. It does not show external IAM delegation, ciphertext access, or successful decryption.
Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T21:42:08Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-16T00:11:53Z", "eventSource": "kms.amazonaws.com", "eventName": "PutKeyPolicy", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "keyId": "60000000-0000-4000-8000-000000000001", "policyName": "default", "policy": "{\n \"Version\" : \"2012-10-17\",\n \"Id\" : \"key-default-1\",\n \"Statement\" : [ {\n \"Sid\" : \"Enable IAM User Permissions\",\n \"Effect\" : \"Allow\",\n \"Principal\" : {\n \"AWS\" : \"arn:aws:iam::555123456789:root\"\n },\n \"Action\" : \"kms:*\",\n \"Resource\" : \"*\"\n }, {\n \"Sid\" : \"AllowExternalAccess\",\n \"Effect\" : \"Allow\",\n \"Principal\" : {\n \"AWS\" : \"arn:aws:iam::555666661337:root\"\n },\n \"Action\" : \"kms:*\",\n \"Resource\" : \"*\"\n } ]\n}", "bypassPolicyLockoutSafetyCheck": false }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000101110000", "eventID": "90000000-0000-4000-8000-000101110001", "readOnly": false, "resources": [ { "accountId": "555123456789", "type": "AWS::KMS::Key", "ARN": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000001" } ], "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "kms.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Privilege Escalation
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...