AddUserToGroup
AddUserToGroup
Event
Adds the specified IAM user to the specified IAM group. The group’s managed and inline policies affect the user through membership. The operation does not create credentials or edit those policy documents.
Security Context
Unauthorized membership in a privileged group can expand access or maintain a permission assignment (T1098). Group names and self-addition alone are not proof of escalation. Onboarding, role changes, and offboarding are common legitimate reasons. Evaluate Allow and Deny statements together with the user’s other policies, boundary, and applicable organization controls.
Log Source
AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: AddUserToGroup. Include IAM global-service events in collection. Check errorCode and errorMessage; responseElements: null alone does not establish failure.
Key Fields
Request fields below are under requestParameters unless another path is shown.
| Field | Investigation value |
|---|---|
userIdentity | Caller and session context; distinguish the caller from the target. |
userName | Target user; distinguish this from userIdentity, the caller. |
groupName | Affected group; inspect actual policies rather than trusting a name such as Administrators. |
eventTime, recipientAccountId, eventID, requestID | Timeline, account, and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context; neither proves malicious intent. |
errorCode, errorMessage | Distinguish failed attempts from completed changes. |
What to Investigate
- Confirm the request outcome, calling identity, account, and approved change. A recorded attempt is not necessarily a completed change.
- Recover group membership and the group’s managed and inline policy documents at the event time.
- Compare effective access before and after the membership change, including remaining grants and removed or added denies. Verify approval and the target’s operational role.
- Correlate RemoveUserFromGroup and subsequent user activity. Establish whether sensitive access became available or needed access actually failed.
Sample Event
Synthetic scenario. Draco adds his user to Administrators. The group’s documents and other controls are absent, so administrator access and malicious intent are not established.
This is an illustrative CloudTrail-shaped record. Exact field presence, timestamp formatting, and policy-document serialization have not been verified against a captured event. Preserve raw records before decoding any nested policy documents.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:03:18Z", "eventSource": "iam.amazonaws.com", "eventName": "AddUserToGroup", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "groupName": "Administrators", "userName": "draco" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000001101000", "eventID": "90000000-0000-4000-8000-000001101001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...