Skip to content

AddRoleToInstanceProfile

AWS

AddRoleToInstanceProfile

service: AWS - IAM
techniques:

Event

Adds a role to an instance profile. A profile holds only one role; replacing that role requires removing the existing role first. This API does not itself associate the profile with an EC2 instance. The caller needs iam:PassRole on the role, and changes are subject to propagation delay.

Security Context

Unauthorized role assignment can expand the access available to workloads using a profile. Approved provisioning is routine. T1098 is contextual to permission manipulation; the event does not prove credential use, an invisible runtime change, or administrator access.

Log Source

AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: AddRoleToInstanceProfile. Check errorCode and errorMessage before treating an attempt as successful; responseElements: null alone does not indicate failure. Include IAM global-service events in collection.

Key Fields

FieldInvestigation value
requestParameters.instanceProfileNameProfile being modified; find all consuming instances.
requestParameters.roleNameRole being added; inspect trust and permissions.
eventTime, recipientAccountId, eventID, requestIDTimeline, account, and correlation identifiers.

What to Investigate

  1. Confirm the outcome and match the caller, target, and timing to an approved workflow. Review failed attempts separately.
  2. Recover prior profile contents and any RemoveRoleFromInstanceProfile operation. Do not interpret an add as an atomic swap.
  3. Resolve consuming instances, role trust for EC2, permissions, boundaries, and other applicable controls. Verify propagation and workload impact.
  4. Correlate AssociateIamInstanceProfile and downstream role-session activity; a profile change alone does not prove host compromise.

Sample Event

Synthetic scenario. Draco adds GraphornAdminRole to OccamyPipelineInstanceProfile. The record does not show a prior role, a consuming instance, or the role’s actual permissions.

Exact CloudTrail nesting, field presence, redaction, and timestamp formatting remain unverified against captured logs. Credential/token placeholders and metadata placeholders are illustrative, not usable credentials or complete provider metadata.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:55:46Z",
"eventSource": "iam.amazonaws.com",
"eventName": "AddRoleToInstanceProfile",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"instanceProfileName": "OccamyPipelineInstanceProfile",
"roleName": "GraphornAdminRole"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000001100110",
"eventID": "90000000-0000-4000-8000-000001100111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.