KMS guards the keys that wrap everything else: SecureString parameters, encrypted S3 objects, EBS volumes, and application envelope-encrypted blobs. A principal with kms:Decrypt on the right key, or a key whose resource policy is too permissive, turns ciphertext you have exfiltrated into plaintext.
Decrypting with a held grant#
aws kms list-keys ; aws kms list-aliases
# decrypt a blob (ciphertext from an encrypted parameter, file, or object)
aws kms decrypt --ciphertext-blob fileb://blob.bin \
--query Plaintext --output text | base64 -d
Reading the key policy#
aws kms get-key-policy --key-id <id> --policy-name default --output text
# a Principal of "*" or a broad account root grants decrypt to more than intended
Exploitation notes#
kms:Decryptis the quiet partner of secret theft:GetParameter --with-decryptionand encrypted-object reads both depend on it.- Envelope encryption stores the wrapped data key next to the ciphertext; decrypt the data key with KMS, then decrypt the payload locally.
- A permissive key policy can allow cross-account decrypt, letting a foothold in one account read another's protected data.
Tools#
- AWS CLI (
kms decrypt,kms get-key-policy). - Pacu (
kms__enum): enumerate keys and policies.