Skip to content

SendSerialConsoleSSHPublicKey

AWS

SendSerialConsoleSSHPublicKey

service: AWS - EC2InstanceConnect
techniques:

Event

Publishes a public key for serial port 0, the currently supported port. The key remains available for 60 seconds to establish an SSH connection to the serial-console service. The 60-second window is for establishing authentication, not a promise that an established session ends after 60 seconds. API success does not prove a connection or guest login.

Security Context

Serial-console access uses a separate service path rather than the instance’s normal network interface. Supported running instances, account/Region access configuration, IAM permissions, and guest prerequisites still apply; access to the serial transport is not automatically an OS shell. T1021.004 is contextual to unauthorized SSH use; routine troubleshooting generates this event.

Log Source

AWS CloudTrail management event with eventSource: ec2-instance-connect.amazonaws.com and eventName: SendSerialConsoleSSHPublicKey. Check errorCode and errorMessage; a null response alone does not establish success or failure.

Key Fields

FieldInvestigation value
requestParameters.instanceIdTarget instance; confirm platform and support.
requestParameters.serialPortSerial port or guest login account being targeted.
requestParameters.sSHPublicKeyPublished public key; correlate its fingerprint with client and host evidence.
responseElements.successKey publication result, not proof of established access.
eventTime, recipientAccountId, eventID, requestIDTimeline and correlation identifiers.
sourceIPAddress, userAgentSupporting context, not a definitive attacker fingerprint.

What to Investigate

  1. Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
  2. Confirm authorization and the relevant instance, account, Region, and guest prerequisites.
  3. Correlate the short publication window with client and host logs. Check OS-level serial login/recovery configuration independently.
  4. Investigate subsequent host activity and any persistent changes separately. Correlate EnableSerialConsoleAccess configuration changes.

Sample Event

Synthetic scenario. Draco publishes an illustrative public test key and the API reports success. No established connection, guest login, or persistent host modification is shown.

Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:21:50Z",
"eventSource": "ec2-instance-connect.amazonaws.com",
"eventName": "SendSerialConsoleSSHPublicKey",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"instanceId": "i-0fedcba9876543210",
"serialPort": 0,
"sSHPublicKey": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINdamAGCsQq31Uv+08lkBzoO4XLz2qYjJa8CGmj3B1Ea synthetic-public-test-key"
},
"responseElements": {
"requestId": "90000000-0000-4000-8000-000110101000",
"success": true
},
"requestID": "90000000-0000-4000-8000-000110101000",
"eventID": "90000000-0000-4000-8000-000110101001",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2-instance-connect.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Lateral Movement

Techniques:
  • T1021.004 — SSH — Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.