Skip to content

PutKeyPolicy

AWS

PutKeyPolicy

service: AWS - KMS
techniques:

Event

Replaces the named key policy, normally default. It can broaden or restrict access. Cross-account use requires key-policy authorization and external IAM authorization and is supported only for designated KMS operations; kms:* does not enable every administrative operation across accounts. The lockout safety check addresses future policy administration, not whether a policy is least privilege.

Security Context

Unauthorized policy changes can manipulate access (T1098), but approved key administration is routine. Account-principal delegation does not give everyone in that account automatic decryption rights. KMS authorization does not itself supply ciphertext, access to storage, or satisfy encryption-context conditions.

Log Source

CloudTrail management event with eventSource: kms.amazonaws.com and eventName: PutKeyPolicy. Check errors and resulting resource state; a null response does not by itself indicate failure.

Key Fields

FieldInvestigation value
requestParameters.keyId, policyNameTarget KMS key and policy.
requestParameters.policyFull replacement document; parse the embedded JSON.
requestParameters.bypassPolicyLockoutSafetyCheckWhether the policy-administration safety check was bypassed.
eventTime, awsRegion, recipientAccountId, eventIDTimeline, service Region, account, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Compare prior/new statements, including removed administrators, conditions, and denies.
  3. Check external identities’ IAM authorization, supported operations, grants, key state, and access to relevant encrypted data.
  4. Correlate actual cryptographic use and GetObject where appropriate. A policy update alone is not data extraction.

Sample Event

Synthetic scenario. Draco submits a policy delegating kms:* to an external account while retaining the owner-account statement. It does not show external IAM delegation, ciphertext access, or successful decryption.

Exact CloudTrail field presence, service-event details, response nesting, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not establish content sensitivity, ownership intent, or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T21:42:08Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-16T00:11:53Z",
"eventSource": "kms.amazonaws.com",
"eventName": "PutKeyPolicy",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"keyId": "60000000-0000-4000-8000-000000000001",
"policyName": "default",
"policy": "{\n \"Version\" : \"2012-10-17\",\n \"Id\" : \"key-default-1\",\n \"Statement\" : [ {\n \"Sid\" : \"Enable IAM User Permissions\",\n \"Effect\" : \"Allow\",\n \"Principal\" : {\n \"AWS\" : \"arn:aws:iam::555123456789:root\"\n },\n \"Action\" : \"kms:*\",\n \"Resource\" : \"*\"\n }, {\n \"Sid\" : \"AllowExternalAccess\",\n \"Effect\" : \"Allow\",\n \"Principal\" : {\n \"AWS\" : \"arn:aws:iam::555666661337:root\"\n },\n \"Action\" : \"kms:*\",\n \"Resource\" : \"*\"\n } ]\n}",
"bypassPolicyLockoutSafetyCheck": false
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000101110000",
"eventID": "90000000-0000-4000-8000-000101110001",
"readOnly": false,
"resources": [
{
"accountId": "555123456789",
"type": "AWS::KMS::Key",
"ARN": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000001"
}
],
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "kms.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.