Detecting Leaked AWS Root Keys: CloudTrail, GuardDuty and Athena Queries

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Leaked root keys give attackers unrestricted control of an AWS account. These detections focus on root key use and signs that exposed keys are being exploited.

Signals worth watching

  • Any API call made with root credentials (userIdentity.type = Root), especially programmatic calls.
  • Root or IAM user keys used from new IPs, ASNs or countries.
  • Reconnaissance immediately after first use: GetCallerIdentity, ListUsers, ListBuckets, GetAccountAuthorizationDetails.
  • SES activity from unexpected identities (SendEmail, SendRawEmail, GetSendQuota, CreateEmailIdentity) — seen in campaigns abusing stolen keys for phishing.
  • Attempts to disable logging or detection (StopLogging, DeleteDetector).
  • AWS Health notifications about exposed credentials.

Where the data lives

  • CloudTrail (all regions, organization trail).
  • GuardDuty findings.
  • AWS Health events.

Starting queries

Root API activity:

AWSCloudTrail
| where UserIdentityType == "Root"
| where EventName != "ConsoleLogin"
| project TimeGenerated, RecipientAccountId, EventName, SourceIpAddress, UserAgent, UserIdentityAccessKeyId

SES abuse indicators:

AWSCloudTrail
| where EventSource == "ses.amazonaws.com"
| where EventName in ("GetSendQuota", "ListIdentities", "CreateEmailIdentity", "VerifyEmailIdentity", "SendEmail", "SendRawEmail")
| summarize Calls = count() by UserIdentityArn, SourceIpAddress, EventName, bin(TimeGenerated, 1h)

Response

  1. Delete root keys; deactivate compromised IAM keys.
  2. Review all actions in all regions.
  3. Remove attacker-created resources and SES identities.
  4. Investigate the exposure source and enable centralized root management.

Sources

  1. Source
detect leaked aws root keys9,300 exposed AWS keys still active2026

More on this story