ScheduleKeyDeletion
ScheduleKeyDeletion
Event
Schedules deletion with a 7–30 day waiting period, defaulting to 30. A key in PendingDeletion cannot perform cryptographic operations, so disruption can precede final deletion. A multi-Region primary with replicas instead waits in PendingReplicaDeletion; its countdown starts after the last replica is deleted.
Security Context
Unauthorized key destruction can cause data loss (T1485) and impair tools that depend on it (T1685). Approved key retirement is also legitimate. Assess key type, replicas, dependent ciphertext, and independent recoverable copies rather than claiming every encrypted record is immediately destroyed.
The mapping describes a possible adversarial sequence, not a verdict on every occurrence.
Log Source
CloudTrail management event with eventSource: kms.amazonaws.com and eventName: ScheduleKeyDeletion. Check collection scope and retention before interpreting absent records. Check whether KMS events were excluded from the retained trail or event-data-store collection.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.keyId | Key ID or ARN; identify actual dependencies. |
requestParameters.pendingWindowInDays | Requested waiting period. |
responseElements.keyState, responseElements.deletionDate | Returned state and scheduled date when present; confirm with DescribeKey. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the caller and correlate with approved work. |
recipientAccountId, awsRegion | Account and recording Region; distinguish caller, target, and resource scope. |
errorCode, errorMessage | Check request failures and confirm resulting state; null response alone is not proof of success. |
What to Investigate
- Confirm approval, inspect errors, and verify key state with DescribeKey.
- Identify key type, multi-Region replicas, affected services, and remaining usable copies of data.
- For unauthorized scheduling, use the approved recovery process before final deletion. CancelKeyDeletion leaves the key Disabled; EnableKey is a separate step.
- Correlate with DeleteObjects and verify dependent services and decryption recover after remediation.
Sample Event
Synthetic scenario. Draco requests a seven-day deletion window for a fictional key. The illustration assumes a single-Region key, but does not prove CloudTrail usage or loss of every log copy. The displayed deletion-date encoding is illustrative. No top-level error is shown. Exact CloudTrail serialization and optional identity/session fields remain unverified by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:08:42Z", "eventSource": "kms.amazonaws.com", "eventName": "ScheduleKeyDeletion", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "keyId": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000010", "pendingWindowInDays": 7 }, "responseElements": { "keyId": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000010", "deletionDate": "Apr 22, 2026 8:08:42 PM", "keyState": "PendingDeletion", "pendingWindowInDays": 7 }, "requestID": "90000000-0000-4000-8000-000110100100", "eventID": "90000000-0000-4000-8000-000110100101", "readOnly": false, "resources": [ { "accountId": "555123456789", "type": "AWS::KMS::Key", "ARN": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000010" } ], "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "kms.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Impact Defense Impairment
- T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
- T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...