Detecting Leaked AWS Root Keys: CloudTrail, GuardDuty and Athena Queries
Leaked root keys give attackers unrestricted control of an AWS account. These detections focus on root key use and signs that exposed keys are being exploited.
Signals worth watching
- Any API call made with root credentials (
userIdentity.type = Root), especially programmatic calls. - Root or IAM user keys used from new IPs, ASNs or countries.
- Reconnaissance immediately after first use:
GetCallerIdentity,ListUsers,ListBuckets,GetAccountAuthorizationDetails. - SES activity from unexpected identities (
SendEmail,SendRawEmail,GetSendQuota,CreateEmailIdentity) — seen in campaigns abusing stolen keys for phishing. - Attempts to disable logging or detection (
StopLogging,DeleteDetector). - AWS Health notifications about exposed credentials.
Where the data lives
- CloudTrail (all regions, organization trail).
- GuardDuty findings.
- AWS Health events.
Starting queries
Root API activity:
AWSCloudTrail
| where UserIdentityType == "Root"
| where EventName != "ConsoleLogin"
| project TimeGenerated, RecipientAccountId, EventName, SourceIpAddress, UserAgent, UserIdentityAccessKeyId
SES abuse indicators:
AWSCloudTrail
| where EventSource == "ses.amazonaws.com"
| where EventName in ("GetSendQuota", "ListIdentities", "CreateEmailIdentity", "VerifyEmailIdentity", "SendEmail", "SendRawEmail")
| summarize Calls = count() by UserIdentityArn, SourceIpAddress, EventName, bin(TimeGenerated, 1h)
Response
- Delete root keys; deactivate compromised IAM keys.
- Review all actions in all regions.
- Remove attacker-created resources and SES identities.
- Investigate the exposure source and enable centralized root management.
Sources
- Thousands of Exposed AWS Access Keys Are Still Active (2026): Including Hundreds of Root Keys Incident Teardowns
- How to Find, Disable and Replace Long-Lived AWS Access Keys How-To & Hardening
- CIO Brief: Old Leaked Keys Are Still Open Doors CIO Briefings