UpdateAccessKey
UpdateAccessKey
Event
Changes an existing long-term key’s status. Inactive disables its use; Active permits its use subject to the owner’s permissions. This does not create a key, reveal its secret, or change the secret value. This operation does not target an ASIA temporary-session key. If userName is omitted, IAM determines the user from the signing credentials as documented by the API.
Security Context
Unauthorized deactivation may disrupt access (T1531), while reactivation can support account manipulation (T1098). Reactivation is useful to an adversary only with the corresponding secret; the key ID alone is insufficient. Other keys, console access, and already-issued sessions require separate assessment. Avoid claiming instantaneous universal lockout from one key operation.
Log Source
AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: UpdateAccessKey. Check errorCode and errorMessage; a null response alone does not establish success or failure. Include IAM global-service events in collection.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.accessKeyId | Target long-term key; distinguish it from the caller’s key. |
requestParameters.userName | Key owner when specified; may differ from the caller. |
requestParameters.status | Requested state; distinguish deactivation from reactivation. |
eventTime, recipientAccountId, eventID, requestID | Timeline and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context, not a definitive attacker fingerprint. |
What to Investigate
- Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
- Recover ownership, prior status, last-use evidence, and the approved rotation or incident record.
- Correlate CreateAccessKey and dependent workload authentication failures; do not invent a replacement key.
- Check other credentials and issued sessions separately. Verify that the requested state was applied and whether the target key was later used.
Sample Event
Synthetic scenario. Draco requests Inactive for Hermione’s long-term key. This example illustrates deactivation, not reactivation, and does not target her temporary STS session.
Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:18:24Z", "eventSource": "iam.amazonaws.com", "eventName": "UpdateAccessKey", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "userName": "hermione", "accessKeyId": "AKIAEXAMPLE0000000001", "status": "Inactive" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000111000000", "eventID": "90000000-0000-4000-8000-000111000001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Impact
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
- T1531 — Account Access Removal — Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts....