Enabled customer managed KMS keys with no aliases and no measured or billed use
What does ZopNight detect here?
ZopNight flags an enabled, customer managed AWS KMS key that has zero aliases and shows no request activity. Each KMS key you create costs $1/month, prorated hourly, so scheduling deletion of a key nothing uses recovers that fee. Measured requests or a bill above $1 keep a key off; unmeasured keys are flagged only if billing shows just that fee.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-058 |
| Category | orphan |
| Severity | low |
| Metric | none — pure configuration read |
| Threshold | 0 aliases, and 0 measured requests or, if unmeasured, billed cost of only the $1 fee |
| Evaluation window | 30d |
| Source | ZopNight |
| Permissions used | kms:ListKeys · kms:DescribeKey · kms:ListAliases |
Where it applies
Every customer managed key has a monthly fee
AWS KMS pricing states that each KMS key you create costs $1/month, prorated hourly, and that the first and second rotation of a key each add another $1/month. Creating and storing AWS managed and AWS owned keys carries no charge. Keys created for a project, a migration or a proof of concept tend to stay enabled long after the data they protected is gone.
Finding keys without aliases
aws kms list-keys --query 'Keys[].KeyId' --output text
aws kms describe-key --key-id 1234abcd-12ab-34cd-56ef-1234567890ab \ --query 'KeyMetadata.[KeyManager,KeyState,CreationDate,Description]'
aws kms list-aliases --key-id 1234abcd-12ab-34cd-56ef-1234567890abKeep the keys where KeyManager is CUSTOMER and KeyState is Enabled. An empty alias list
is a hint, not proof, so check CloudTrail for Encrypt, Decrypt and GenerateDataKey calls
against the key ARN before going further.
A missing alias plus no evidence of use
ZopNight requires three things from the key’s metadata: Enabled state, CUSTOMER key manager and
an alias count of exactly zero. Keys without an alias count are skipped. Then it looks for signs of
use. Measured request activity above zero ends the finding. So does a billed monthly cost above the
$1 standing fee, which means paid cryptographic requests. A measured zero is positive evidence of
idleness and lets the finding through. When activity cannot be measured but billing data shows
only the $1 fee, the finding also goes through. That fee alone does not prove the key is idle: the
KMS free tier covers 20,000 requests a month, so a lightly used key still bills exactly $1.
When the key is left alone
If request activity cannot be measured and the cost is not backed by billing data, ZopNight does not guess; it raises nothing. That guard exists for month boundaries and accounts without billing access, where a live key could otherwise look unused. AWS managed keys are excluded because they cannot be deleted. The recommendation is always a guided action that asks you to confirm, never an automatic deletion.
The key fee is the saving
saving = the key's monthly cost (normally $1)cost after fix = 0Retiring an unused key safely
- Search code, infrastructure templates and service configurations for the key ID and ARN.
- Check CloudTrail for recent use of the key.
- Consider disabling it first with
aws kms disable-key, which can be reversed. - Schedule deletion with
aws kms schedule-key-deletion --key-idand--pending-window-in-daysbetween 7 and 30; the default is 30.