Skip to content

ScheduleKeyDeletion

AWS

ScheduleKeyDeletion

service: AWS - KMS
techniques:

Event

Schedules deletion with a 7–30 day waiting period, defaulting to 30. A key in PendingDeletion cannot perform cryptographic operations, so disruption can precede final deletion. A multi-Region primary with replicas instead waits in PendingReplicaDeletion; its countdown starts after the last replica is deleted.

Security Context

Unauthorized key destruction can cause data loss (T1485) and impair tools that depend on it (T1685). Approved key retirement is also legitimate. Assess key type, replicas, dependent ciphertext, and independent recoverable copies rather than claiming every encrypted record is immediately destroyed.

The mapping describes a possible adversarial sequence, not a verdict on every occurrence.

Log Source

CloudTrail management event with eventSource: kms.amazonaws.com and eventName: ScheduleKeyDeletion. Check collection scope and retention before interpreting absent records. Check whether KMS events were excluded from the retained trail or event-data-store collection.

Key Fields

FieldInvestigation use
requestParameters.keyIdKey ID or ARN; identify actual dependencies.
requestParameters.pendingWindowInDaysRequested waiting period.
responseElements.keyState, responseElements.deletionDateReturned state and scheduled date when present; confirm with DescribeKey.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the caller and correlate with approved work.
recipientAccountId, awsRegionAccount and recording Region; distinguish caller, target, and resource scope.
errorCode, errorMessageCheck request failures and confirm resulting state; null response alone is not proof of success.

What to Investigate

  1. Confirm approval, inspect errors, and verify key state with DescribeKey.
  2. Identify key type, multi-Region replicas, affected services, and remaining usable copies of data.
  3. For unauthorized scheduling, use the approved recovery process before final deletion. CancelKeyDeletion leaves the key Disabled; EnableKey is a separate step.
  4. Correlate with DeleteObjects and verify dependent services and decryption recover after remediation.

Sample Event

Synthetic scenario. Draco requests a seven-day deletion window for a fictional key. The illustration assumes a single-Region key, but does not prove CloudTrail usage or loss of every log copy. The displayed deletion-date encoding is illustrative. No top-level error is shown. Exact CloudTrail serialization and optional identity/session fields remain unverified by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:08:42Z",
"eventSource": "kms.amazonaws.com",
"eventName": "ScheduleKeyDeletion",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"keyId": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000010",
"pendingWindowInDays": 7
},
"responseElements": {
"keyId": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000010",
"deletionDate": "Apr 22, 2026 8:08:42 PM",
"keyState": "PendingDeletion",
"pendingWindowInDays": 7
},
"requestID": "90000000-0000-4000-8000-000110100100",
"eventID": "90000000-0000-4000-8000-000110100101",
"readOnly": false,
"resources": [
{
"accountId": "555123456789",
"type": "AWS::KMS::Key",
"ARN": "arn:aws:kms:us-east-1:555123456789:key/60000000-0000-4000-8000-000000000010"
}
],
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "kms.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact Defense Impairment

Techniques:
  • T1485 — Data Destruction — Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources. Data destruction is likely to render stored data irrecoverable by forensic techniques through overwriting files or data on local and r...
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.