Skip to content

UpdateAccessKey

AWS

UpdateAccessKey

service: AWS - IAM
techniques:

Event

Changes an existing long-term key’s status. Inactive disables its use; Active permits its use subject to the owner’s permissions. This does not create a key, reveal its secret, or change the secret value. This operation does not target an ASIA temporary-session key. If userName is omitted, IAM determines the user from the signing credentials as documented by the API.

Security Context

Unauthorized deactivation may disrupt access (T1531), while reactivation can support account manipulation (T1098). Reactivation is useful to an adversary only with the corresponding secret; the key ID alone is insufficient. Other keys, console access, and already-issued sessions require separate assessment. Avoid claiming instantaneous universal lockout from one key operation.

Log Source

AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: UpdateAccessKey. Check errorCode and errorMessage; a null response alone does not establish success or failure. Include IAM global-service events in collection.

Key Fields

FieldInvestigation value
requestParameters.accessKeyIdTarget long-term key; distinguish it from the caller’s key.
requestParameters.userNameKey owner when specified; may differ from the caller.
requestParameters.statusRequested state; distinguish deactivation from reactivation.
eventTime, recipientAccountId, eventID, requestIDTimeline and correlation identifiers.
sourceIPAddress, userAgentSupporting context, not a definitive attacker fingerprint.

What to Investigate

  1. Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
  2. Recover ownership, prior status, last-use evidence, and the approved rotation or incident record.
  3. Correlate CreateAccessKey and dependent workload authentication failures; do not invent a replacement key.
  4. Check other credentials and issued sessions separately. Verify that the requested state was applied and whether the target key was later used.

Sample Event

Synthetic scenario. Draco requests Inactive for Hermione’s long-term key. This example illustrates deactivation, not reactivation, and does not target her temporary STS session.

Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T21:18:24Z",
"eventSource": "iam.amazonaws.com",
"eventName": "UpdateAccessKey",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"userName": "hermione",
"accessKeyId": "AKIAEXAMPLE0000000001",
"status": "Inactive"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000111000000",
"eventID": "90000000-0000-4000-8000-000111000001",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Impact

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
  • T1531 — Account Access Removal — Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts....
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.