Skip to content

AttachRolePolicy

AWS

AttachRolePolicy

service: AWS - IAM
techniques:

Event

Attaches a managed permissions policy to an IAM role. The attachment references an existing managed policy; its effective default version determines the policy content. Role trust is separate and is changed through UpdateAssumeRolePolicy.

Security Context

An adversary could use this change to expand access for the target identity or maintain an unauthorized permission assignment. Normal provisioning and approved access changes use the same API. T1098 applies when account manipulation supports adversarial access; the event alone does not establish intent or continued authentication capability.

Effective access depends on the combined policy evaluation, including applicable boundaries, organization controls, session policies, and explicit denies. A broad Allow does not override these restrictions. Inspect the role trust policy and actual role sessions. This operation does not change who can assume the role or issue credentials.

Log Source

AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: AttachRolePolicy. Include IAM global-service events in your collection. Check errorCode and errorMessage; a recorded attempt is not necessarily a completed change, and responseElements: null alone does not establish failure.

Key Fields

FieldInvestigation value
userIdentityCaller and session context; compare with the target and approved automation.
requestParameters.roleNameTarget IAM role, interpreted with the account identity.
requestParameters.policyArnManaged policy attached; retrieve its default version and event-time history.
eventTime, recipientAccountId, requestID, eventIDTimeline, account, and correlation identifiers.
sourceIPAddress, userAgentSupporting context, not proof of identity or malicious intent.
errorCode, errorMessageFailed requests must be distinguished from successful changes.

What to Investigate

  1. Confirm the outcome and match the caller, target, and timing to an approved change. Review failed attempts separately.
  2. Retrieve the managed policy document and the default version effective at the time. Check earlier attachments and subsequent policy-version changes.
  3. Inspect the role trust policy and actual role sessions. This operation does not change who can assume the role or issue credentials. Evaluate the resulting access with other applicable policies; confirm whether any sensitive permission actually became usable.
  4. Correlate other policy changes with subsequent API use by the affected identities. Separate persistence of the permission assignment from persistence of usable attacker credentials.

Sample Event

Synthetic suspicious scenario. Draco attaches AdministratorAccess to OccamyPipelineRole. This merits review, but the sample does not establish approval status, prior permissions, or successful use of expanded access.

This is an illustrative CloudTrail-shaped record. Exact field presence and policy-document serialization have not been verified against a captured event.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:48:33Z",
"eventSource": "iam.amazonaws.com",
"eventName": "AttachRolePolicy",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"roleName": "OccamyPipelineRole",
"policyArn": "arn:aws:iam::aws:policy/AdministratorAccess"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000001110100",
"eventID": "90000000-0000-4000-8000-000001110101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.