aws-kms-random-bytes-output

GenerateRandom returns raw random bytes that callers often adopt as passwords, keys, or signing secrets.

awshigh service: aws:kms emits ExposesCredential

Where it sits

locationGenerateRandom.Plaintext
location kindoutput_value
data kindsencryption_key_material signing_secret credential
emits edgeExposesCredential
serviceKMS (aws:kms)

Collection recipe

access modecreation_response_only
operationGenerateRandom
response pathPlaintext
encodingbinary
params{"NumberOfBytes": "\u003c1-1024\u003e"}

Required permissions

kms:GenerateRandom

References

move · open · esc close