> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kms-key-policy-was-changed.md).

# KMS key policy was changed

### Synopsis

| Field                | Value                                                                                        |
| -------------------- | -------------------------------------------------------------------------------------------- |
| Activation Period    | 14 Days                                                                                      |
| Training Period      | 30 Days                                                                                      |
| Test Period          | N/A (single event)                                                                           |
| Deduplication Period | 1 Day                                                                                        |
| Required Data        | AWS Audit Log                                                                                |
| Detection Modules    | Cloud                                                                                        |
| Detector Tags        | Data Detection & Response                                                                    |
| ATT\&CK Tactic       | Privilege Escalation (TA0004), Persistence (TA0003)                                          |
| ATT\&CK Technique    | Account Manipulation (T1098), Account Manipulation: Additional Cloud Credentials (T1098.001) |
| Severity             | Informational                                                                                |

### Description

A cloud identity modified an AWS KMS key policy.

### Attacker's Goals

Modify KMS key policies to gain unauthorized access to encrypted data or to deny access to resources encrypted using this key.

### Investigative actions

* Investigate any unusual activity originating from the suspected identity.
* Confirm if the identity is authorized to modify KMS key policies.
* Review the KMS key policy changes to ensure they are legitimate.

### Variations

<details>

<summary>KMS key policy was modified to include a foreign principal</summary>

**Synopsis**

| Field             | Value                                                       |
| ----------------- | ----------------------------------------------------------- |
| ATT\&CK Tactic    | Impact (TA0040)                                             |
| ATT\&CK Technique | Data Encrypted for Impact (T1486), Data Destruction (T1485) |
| Severity          | Medium                                                      |

**Description**

A cloud identity modified a KMS key policy to include a foreign principal in an unknown account while bypassing the AWS PutKeyPolicy safety check. This could lead to a 'lockout' state where no users in the account have permission to manage or use the key, effectively making encrypted data irrecoverable.

**Attacker's Goals**

* Grant access to encryption keys to an external account under their control.
* Permanently deny access to encrypted data by creating a key policy lockout state, typical of data destruction or ransomware attacks.

**Investigative actions**

* Verify if the foreign principal is authorized to have access to this key.
* Investigate the relationship between the current account and the foreign account.
* Review the extent of permissions granted to the foreign principal.

</details>

<details>

<summary>Unusual KMS key policy modification</summary>

**Synopsis**

| Field             | Value                                                                                        |
| ----------------- | -------------------------------------------------------------------------------------------- |
| ATT\&CK Tactic    | Privilege Escalation (TA0004), Persistence (TA0003)                                          |
| ATT\&CK Technique | Account Manipulation (T1098), Account Manipulation: Additional Cloud Credentials (T1098.001) |
| Severity          | Medium                                                                                       |

**Description**

A Cloud identity that usually does not perform this action modified an AWS KMS key policy.

**Attacker's Goals**

Modify KMS key policies to gain unauthorized access to encrypted data or to deny access to resources encrypted using this key.

**Investigative actions**

* Investigate any unusual activity originating from the suspected identity.
* Confirm if the identity is authorized to modify KMS key policies.
* Review the KMS key policy changes to ensure they are legitimate.

</details>

<details>

<summary>Failed attempt to change KMS key policy</summary>

**Synopsis**

| Field             | Value                                                                                        |
| ----------------- | -------------------------------------------------------------------------------------------- |
| ATT\&CK Tactic    | Privilege Escalation (TA0004), Persistence (TA0003)                                          |
| ATT\&CK Technique | Account Manipulation (T1098), Account Manipulation: Additional Cloud Credentials (T1098.001) |
| Severity          | Low                                                                                          |

**Description**

A cloud identity failed to modify an AWS KMS key policy.

**Attacker's Goals**

Modify KMS key policies to gain unauthorized access to encrypted data or to deny access to resources encrypted using this key.

**Investigative actions**

* Investigate any unusual activity originating from the suspected identity.
* Confirm if the identity is authorized to modify KMS key policies.
* Review the KMS key policy changes to ensure they are legitimate.

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name/kms-key-policy-was-changed.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
