AWSDetection & ResponseRetrospectives

Detecting Stolen AWS API Keys: CloudTrail, GuardDuty and Athena Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from August 2019, written in 2026 with the benefit of hindsight.

Stolen AWS API keys are frequently used for reconnaissance, data theft and resource abuse. These detections help you spot misuse quickly.

Signals worth watching

  • Access keys used from a new IP address, ASN or country.
  • Reconnaissance sequences: GetCallerIdentity, ListUsers, ListRoles, ListBuckets, DescribeSnapshots, DescribeDBSnapshots.
  • Snapshot sharing or copying: ModifySnapshotAttribute, ModifyDBSnapshotAttribute, CopySnapshot.
  • Creation of new users, keys or login profiles.
  • API calls in regions you don't use.

Where the data lives

  • CloudTrail (all regions; organization trail recommended).
  • GuardDuty findings for anomalous IAM user behavior and credential misuse.
  • IAM Access Analyzer for newly shared snapshots and resources.

A starting query

Snapshot sharing is a common data theft technique:

AWSCloudTrail
| where EventName in ("ModifySnapshotAttribute", "ModifyDBSnapshotAttribute", "ModifyDBClusterSnapshotAttribute")
| extend Params = tostring(RequestParameters)
| where Params has "createVolumePermission" or Params has "restore"
| project TimeGenerated, UserIdentityArn, UserIdentityAccessKeyId, SourceIpAddress, Params

Any snapshot shared with an unfamiliar account ID is a high-priority alert.

Response

  1. Deactivate the access key.
  2. Revoke any snapshot sharing and check for copies in external accounts (contact AWS Support if data may have left).
  3. Review all actions by the key across regions.
  4. Replace the use case with a role so the key isn't recreated.
detect stolen aws api keysImperva AWS key2019

More on this story