Skip to main content

Event Information

  • The DeleteAccessKey event in AWS for IAM refers to the action of deleting an access key associated with an IAM user.
  • This event is triggered when an administrator or the IAM user themselves initiates the deletion of an access key.
  • The DeleteAccessKey event is logged in the CloudTrail service, providing an audit trail of access key management activities for compliance and security purposes.

Examples

  • Unauthorized deletion of access keys: If an attacker gains access to an IAM user’s credentials, they can use the DeleteAccessKey API to delete the user’s access keys. This can lead to unauthorized access to resources and potential data breaches.
  • Disruption of service: If a legitimate user accidentally or maliciously deletes their own access key using the DeleteAccessKey API, it can result in a disruption of service. This can impact applications or services that rely on the access key for authentication and authorization.
  • Compliance violations: Deleting access keys without proper authorization or auditing can lead to compliance violations. Organizations that need to adhere to specific security standards, such as PCI DSS or HIPAA, may face penalties or loss of certification if access keys are deleted without proper controls and documentation.

Remediation

Using Console

  1. Example 1: Enforce strong password policy for IAM users
    • Step 1: Login to the AWS Management Console.
    • Step 2: Go to the IAM service.
    • Step 3: Click on “Account settings” in the left navigation pane.
    • Step 4: Under the “Password policy” section, click on “Edit”.
    • Step 5: Enable the “Require at least one uppercase letter” option.
    • Step 6: Enable the “Require at least one lowercase letter” option.
    • Step 7: Enable the “Require at least one number” option.
    • Step 8: Enable the “Require at least one non-alphanumeric character” option.
    • Step 9: Set the “Minimum password length” to an appropriate value.
    • Step 10: Click on “Apply password policy”.
  2. Example 2: Enable multi-factor authentication (MFA) for IAM users
    • Step 1: Login to the AWS Management Console.
    • Step 2: Go to the IAM service.
    • Step 3: Click on “Users” in the left navigation pane.
    • Step 4: Select the IAM user for which you want to enable MFA.
    • Step 5: Click on the “Security credentials” tab.
    • Step 6: Under the “Multi-factor authentication (MFA)” section, click on “Manage”.
    • Step 7: Click on “Activate MFA”.
    • Step 8: Choose the appropriate MFA device option (e.g., virtual MFA device, hardware MFA device).
    • Step 9: Follow the on-screen instructions to set up the MFA device.
    • Step 10: Click on “Assign MFA”.
  3. Example 3: Enable AWS CloudTrail for logging IAM events
    • Step 1: Login to the AWS Management Console.
    • Step 2: Go to the CloudTrail service.
    • Step 3: Click on “Trails” in the left navigation pane.
    • Step 4: Click on “Create trail”.
    • Step 5: Provide a name for the trail and choose the appropriate settings (e.g., log file validation, S3 bucket for storing logs).
    • Step 6: Under the “Management events” section, enable logging for IAM events.
    • Step 7: Click on “Create”.
    • Step 8: Once the trail is created, go to the IAM service.
    • Step 9: Click on “Policies” in the left navigation pane.
    • Step 10: Create a new IAM policy that allows the necessary permissions for accessing and reading the CloudTrail logs, and attach it to the IAM users or groups that require access.

Using CLI

  1. Ensure IAM users have strong passwords:
    • Use the update-login-profile command to set a strong password for an IAM user:
  2. Enable multi-factor authentication (MFA) for IAM users:
    • Use the enable-mfa-device command to enable MFA for an IAM user:
  3. Remove unnecessary IAM access keys:
    • Use the delete-access-key command to delete an IAM access key:

Using Python

  1. Ensure IAM users have strong passwords:
    • Use the boto3 library in Python to retrieve a list of IAM users.
    • For each user, check if their password is strong by validating it against a set of password complexity rules.
    • If a user’s password is weak, use the update_login_profile method to force a password reset for that user.
  1. Enable multi-factor authentication (MFA) for IAM users:
    • Use the boto3 library in Python to retrieve a list of IAM users.
    • For each user, check if MFA is enabled by calling the list_mfa_devices method.
    • If MFA is not enabled, use the enable_mfa method to enable it for the user.
  1. Remove unused IAM access keys:
    • Use the boto3 library in Python to retrieve a list of IAM users.
    • For each user, check if they have any access keys by calling the list_access_keys method.
    • If the user has unused access keys, use the delete_access_key method to remove them.