AWS KMS Imported Key Material Usage

 Original Source: [Sigma source]
Title: AWS KMS Imported Key Material Usage
Status: experimental
Description:Detects the import or deletion of key material in AWS KMS, which can be used as part of ransomware attacks. This activity is uncommon and provides a high certainty signal.
References:
  -https://www.chrisfarris.com/post/effective-aws-ransomware/
  -https://docs.aws.amazon.com/kms/latest/developerguide/ct-importkeymaterial.html
  -https://docs.aws.amazon.com/kms/latest/developerguide/ct-deleteimportedkeymaterial.html
Author: toopricey
Date: 2025-10-18
modified:None
Tags:
  • -'attack.impact'
  • -'attack.t1486'
  • -'attack.resource-development'
  • -'attack.t1608.003'
Logsource:
  • product: aws
  • service: cloudtrail
Detection:
  selection:
    eventSource: 'kms.amazonaws.com'
    eventName:
      -'ImportKeyMaterial'
      -'DeleteImportedKeyMaterial'

  condition:selection
Falsepositives:
  -Legitimate use cases for imported key material are rare, but may include, Organizations with hybrid cloud architectures that import external key material for compliance requirements.
  -Development or testing environments that simulate external key management scenarios. Even in these cases, such activity is typically infrequent and should not add significant noise.
Level: high