Skip to content

AddPermission20150331v2

AWS

AddPermission20150331v2

service: AWS - Lambda
techniques:

Event

Adds a policy statement for a function, version, or alias; it does not replace the entire policy. The action determines the permission granted. Lambda does not support adding a policy to the $LATEST version qualifier.

Security Context

Unauthorized permission changes can manipulate access (T1098). Invocation permission does not allow uploading arbitrary function code or directly acquiring its execution-role credentials. External-account invocation also requires authorization for the external identity. Service principals should be constrained with applicable source conditions.

Log Source

CloudTrail management event with eventSource: lambda.amazonaws.com and eventName: AddPermission20150331v2. The dated suffix is part of the CloudTrail event name; the API documentation uses the undated operation name. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.

Key Fields

Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.

FieldInvestigation value
functionName, qualifierFunction and any version/alias scope.
statementId, action, principal, sourceArn, sourceAccountNew grant and source restrictions; inspect the returned embedded statement.
userIdentity, eventTime, awsRegion, eventID (top level)Caller/session, timeline, Region, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Compare prior and resulting policy statements and resolve the intended principal.
  3. Check effective cross-account authorization or service source restrictions, including explicit denies.
  4. Correlate subsequent Invoke activity and function outcome; a policy change is not a trigger or execution record.

Sample Event

Synthetic scenario. An account-principal statement allows lambda:InvokeFunction. It does not show which external identities can exercise the grant or any actual invocation.

Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:42:11Z",
"eventSource": "lambda.amazonaws.com",
"eventName": "AddPermission20150331v2",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"functionName": "occamy-log-processor",
"statementId": "occamy-cross-account-trigger",
"action": "lambda:InvokeFunction",
"principal": "555666661337"
},
"responseElements": {
"statement": "{\"Sid\":\"occamy-cross-account-trigger\",\"Effect\":\"Allow\",\"Principal\":{\"AWS\":\"arn:aws:iam::555666661337:root\"},\"Action\":\"lambda:InvokeFunction\",\"Resource\":\"arn:aws:lambda:us-east-1:555123456789:function:occamy-log-processor\"}"
},
"requestID": "90000000-0000-4000-8000-000001100100",
"eventID": "90000000-0000-4000-8000-000001100101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "lambda.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.