elastic
medium
kql
AWS KMS Customer Managed Key Disabled or Scheduled for Deletion
Identifies attempts to disable or schedule the deletion of an AWS customer managed KMS Key. Disabling or scheduling a
KMS key for deletion removes the ability to decrypt data encrypted under that key and can permanently destroy access to
critical resources. Adversaries may use these operations to cause irreversible data loss, disrupt business operations,
impede incident response, or hide evidence of prior activity. Because KMS keys often protect sensitive or regulated
data, any modification to t