AddRoleToInstanceProfile
AddRoleToInstanceProfile
Event
Adds a role to an instance profile. A profile holds only one role; replacing that role requires removing the existing role first. This API does not itself associate the profile with an EC2 instance. The caller needs iam:PassRole on the role, and changes are subject to propagation delay.
Security Context
Unauthorized role assignment can expand the access available to workloads using a profile. Approved provisioning is routine. T1098 is contextual to permission manipulation; the event does not prove credential use, an invisible runtime change, or administrator access.
Log Source
AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: AddRoleToInstanceProfile. Check errorCode and errorMessage before treating an attempt as successful; responseElements: null alone does not indicate failure. Include IAM global-service events in collection.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.instanceProfileName | Profile being modified; find all consuming instances. |
requestParameters.roleName | Role being added; inspect trust and permissions. |
eventTime, recipientAccountId, eventID, requestID | Timeline, account, and correlation identifiers. |
What to Investigate
- Confirm the outcome and match the caller, target, and timing to an approved workflow. Review failed attempts separately.
- Recover prior profile contents and any RemoveRoleFromInstanceProfile operation. Do not interpret an add as an atomic swap.
- Resolve consuming instances, role trust for EC2, permissions, boundaries, and other applicable controls. Verify propagation and workload impact.
- Correlate AssociateIamInstanceProfile and downstream role-session activity; a profile change alone does not prove host compromise.
Sample Event
Synthetic scenario. Draco adds GraphornAdminRole to OccamyPipelineInstanceProfile. The record does not show a prior role, a consuming instance, or the role’s actual permissions.
Exact CloudTrail nesting, field presence, redaction, and timestamp formatting remain unverified against captured logs. Credential/token placeholders and metadata placeholders are illustrative, not usable credentials or complete provider metadata.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:55:46Z", "eventSource": "iam.amazonaws.com", "eventName": "AddRoleToInstanceProfile", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "instanceProfileName": "OccamyPipelineInstanceProfile", "roleName": "GraphornAdminRole" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000001100110", "eventID": "90000000-0000-4000-8000-000001100111", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...