Skip to main content
orphan · aws

Secrets Manager secrets not accessed in more than 90 days

resource types
1
rule IDs covered
1
severity
low

What does ZopNight detect here?

ZopNight flags an AWS Secrets Manager secret whose `LastAccessedDate` is more than 90 days old, or that has never been retrieved and was created more than 90 days ago. Each secret is billed a flat monthly fee, $0.40 in AWS pricing examples, and deleting an unused one recovers exactly that charge.

Signal and threshold

How ZopNight evaluates Secrets Manager secrets not accessed in more than 90 days.
Field Value
Rule IDsRC-056
Categoryorphan
Severitylow
Metricnone — pure configuration read
Thresholdnot accessed for 90+ days
Evaluation window90d
SourceZopNight
Permissions usedsecretsmanager:ListSecrets · secretsmanager:DescribeSecret

Each secret carries a standing monthly fee

Secrets Manager pricing charges per secret per month, and counts a replica secret as a separate secret. The pricing examples work the per-secret rate out as $0.40 per month, plus API calls at $0.05 per 10,000. Secrets for decommissioned databases, rotated-out API keys and old service accounts keep that fee running long after anyone reads them.

Checking when a secret was last read

LastAccessedDate in the DescribeSecret response is the date the secret was last accessed in the Region, and the field is omitted entirely if the secret has never been retrieved there:

Terminal window
aws secretsmanager list-secrets \
--query 'SecretList[].[Name,LastAccessedDate,CreatedDate]' --output table

A blank LastAccessedDate on a secret created months ago means nothing has ever fetched it.

How the 90 days are measured

ZopNight needs real access evidence, not just the secret’s existence. If a last-access date is known, the secret must not have been accessed for more than 90 days. If the secret has never been accessed, ZopNight measures 90 days from its creation date instead. The finding states the measured number of days.

When a secret is not flagged

A secret with neither a last-access date nor a never-accessed marker plus creation date is skipped; unknown is not unused. Secrets accessed within the last 90 days are never flagged. Replicas are separate secrets with their own access record.

Pricing the per-secret fee

Terminal window
saving = the secret's monthly cost, or the published $0.40 per-secret fee when no priced cost is available
cost after fix = 0

Deleting a secret nobody reads

  1. Search application config, task definitions and Lambda environment variables for the secret name or ARN.
  2. Confirm with the owner that the credential it holds is retired.
  3. Delete it with a recovery window: aws secretsmanager delete-secret --secret-id my-secret --recovery-window-in-days 7. The window can be 7 to 30 days; without the option it is 30.
  4. Restore it with aws secretsmanager restore-secret if something breaks during the window.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·