SendSSHPublicKey
SendSSHPublicKey
Event
Publishes a public key for the specified instance and OS user for 60 seconds. The guest must support and be configured for EC2 Instance Connect, and the client needs network reachability to its SSH service. The 60-second window is for establishing authentication, not a promise that an established session ends after 60 seconds. API success does not prove a connection or guest login.
Security Context
The caller’s AWS authorization, the intended OS user, guest SSH configuration, and network controls all matter. Publishing a temporary key is not proof of a persistent authorized_keys modification. T1021.004 is contextual to unauthorized SSH use; routine troubleshooting generates this event.
Log Source
AWS CloudTrail management event with eventSource: ec2-instance-connect.amazonaws.com and eventName: SendSSHPublicKey. Check errorCode and errorMessage; a null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.instanceId | Target instance; confirm platform and support. |
requestParameters.instanceOSUser | Serial port or guest login account being targeted. |
requestParameters.sSHPublicKey | Published public key; correlate its fingerprint with client and host evidence. |
responseElements.success | Key publication result, not proof of established access. |
eventTime, recipientAccountId, eventID, requestID | Timeline and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context, not a definitive attacker fingerprint. |
What to Investigate
- Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
- Confirm authorization and the relevant instance, account, Region, and guest prerequisites.
- Correlate the short publication window with client and host logs. Check SSH routing, security groups, and guest authentication logs.
- Investigate subsequent host activity and any persistent changes separately. Compare ImportKeyPair activity without assuming the two mechanisms are equivalent.
Sample Event
Synthetic scenario. Draco publishes an illustrative public test key and the API reports success. No established connection, guest login, or persistent host modification is shown.
Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:24:13Z", "eventSource": "ec2-instance-connect.amazonaws.com", "eventName": "SendSSHPublicKey", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "instanceId": "i-0123456789abcdef0", "instanceOSUser": "ec2-user", "sSHPublicKey": "ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAINdamAGCsQq31Uv+08lkBzoO4XLz2qYjJa8CGmj3B1Ea synthetic-public-test-key", "availabilityZone": "us-east-1a" }, "responseElements": { "requestId": "90000000-0000-4000-8000-000110101010", "success": true }, "requestID": "90000000-0000-4000-8000-000110101010", "eventID": "90000000-0000-4000-8000-000110101011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2-instance-connect.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Lateral Movement
- T1021.004 — SSH — Adversaries may use [Valid Accounts](https://attack.mitre.org/techniques/T1078) to log into remote machines using Secure Shell (SSH). The adversary may then perform actions as the logged-on user.