Secret stores

AWS secret stores exist to hand credentials to applications, which makes them a direct source for an attacker who holds the read permission. A principal that can call secretsmanager:GetSecretValue or ssm:GetParameter with decryption is reading database passwords, API keys, and other credentials straight out of the account.

What folds in here#

  • Secrets Manager: GetSecretValue across stored secrets.
  • Parameter Store: GetParameter/GetParameters over SecureString and plaintext values.
  • KMS: Decrypt and permissive key policies over envelope-encrypted data.

Sweeping the stores#

bash
aws secretsmanager list-secrets --query 'SecretList[].Name'
aws ssm describe-parameters --query 'Parameters[].Name'

References#

Cookie Consent

We use cookies to enhance your experience. Learn more