A 50x spike in KMS Decrypt calls looked exactly like credential exfiltration.
A 50x spike in KMS Decrypt calls, Z-score of 573, was traced to 59 Lambda functions running with full administrative privileges.
An elevated service role combined with high-volume KMS Decrypt calls is identical to a post-compromise credential exfiltration pattern. Detecting this requires understanding what's normal for each service, not just what looks bad in isolation.
All 59 Lambda functions were mapped to their owning teams. Each made exactly 61 KMS calls. Systematic, not random.