AddPermission20150331v2
AddPermission20150331v2
Event
Adds a policy statement for a function, version, or alias; it does not replace the entire policy. The action determines the permission granted. Lambda does not support adding a policy to the $LATEST version qualifier.
Security Context
Unauthorized permission changes can manipulate access (T1098). Invocation permission does not allow uploading arbitrary function code or directly acquiring its execution-role credentials. External-account invocation also requires authorization for the external identity. Service principals should be constrained with applicable source conditions.
Log Source
CloudTrail management event with eventSource: lambda.amazonaws.com and eventName: AddPermission20150331v2. The dated suffix is part of the CloudTrail event name; the API documentation uses the undated operation name. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.
Key Fields
Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.
| Field | Investigation value |
|---|---|
functionName, qualifier | Function and any version/alias scope. |
statementId, action, principal, sourceArn, sourceAccount | New grant and source restrictions; inspect the returned embedded statement. |
userIdentity, eventTime, awsRegion, eventID (top level) | Caller/session, timeline, Region, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Compare prior and resulting policy statements and resolve the intended principal.
- Check effective cross-account authorization or service source restrictions, including explicit denies.
- Correlate subsequent Invoke activity and function outcome; a policy change is not a trigger or execution record.
Sample Event
Synthetic scenario. An account-principal statement allows lambda:InvokeFunction. It does not show which external identities can exercise the grant or any actual invocation.
Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:42:11Z", "eventSource": "lambda.amazonaws.com", "eventName": "AddPermission20150331v2", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "functionName": "occamy-log-processor", "statementId": "occamy-cross-account-trigger", "action": "lambda:InvokeFunction", "principal": "555666661337" }, "responseElements": { "statement": "{\"Sid\":\"occamy-cross-account-trigger\",\"Effect\":\"Allow\",\"Principal\":{\"AWS\":\"arn:aws:iam::555666661337:root\"},\"Action\":\"lambda:InvokeFunction\",\"Resource\":\"arn:aws:lambda:us-east-1:555123456789:function:occamy-log-processor\"}" }, "requestID": "90000000-0000-4000-8000-000001100100", "eventID": "90000000-0000-4000-8000-000001100101", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "lambda.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...