AttachUserPolicy
AttachUserPolicy
Event
Attaches a managed permissions policy to an IAM user. The attachment references an existing managed policy; its effective default version determines the policy content.
Security Context
An adversary could use this change to expand access for the target identity or maintain an unauthorized permission assignment. Normal provisioning and approved access changes use the same API. T1098 applies when account manipulation supports adversarial access; the event alone does not establish intent or continued authentication capability.
Effective access depends on the combined policy evaluation, including applicable boundaries, organization controls, session policies, and explicit denies. A broad Allow does not override these restrictions. Distinguish the calling identity from the target user. A policy change does not create credentials or prove that an attacker can still authenticate.
Log Source
AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: AttachUserPolicy. Include IAM global-service events in your collection. Check errorCode and errorMessage; a recorded attempt is not necessarily a completed change, and responseElements: null alone does not establish failure.
Key Fields
| Field | Investigation value |
|---|---|
userIdentity | Caller and session context; compare with the target and approved automation. |
requestParameters.userName | Target IAM user, interpreted with the account identity. |
requestParameters.policyArn | Managed policy attached; retrieve its default version and event-time history. |
eventTime, recipientAccountId, requestID, eventID | Timeline, account, and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context, not proof of identity or malicious intent. |
errorCode, errorMessage | Failed requests must be distinguished from successful changes. |
What to Investigate
- Confirm the outcome and match the caller, target, and timing to an approved change. Review failed attempts separately.
- Retrieve the managed policy document and the default version effective at the time. Check earlier attachments and subsequent policy-version changes.
- Distinguish the calling identity from the target user. A policy change does not create credentials or prove that an attacker can still authenticate. Evaluate the resulting access with other applicable policies; confirm whether any sensitive permission actually became usable.
- Correlate other policy changes with subsequent API use by the affected identities. Separate persistence of the permission assignment from persistence of usable attacker credentials.
Sample Event
Synthetic suspicious scenario. Draco attaches AdministratorAccess to draco. This merits review, but the sample does not establish approval status, prior permissions, or successful use of expanded access.
This is an illustrative CloudTrail-shaped record. Exact field presence and policy-document serialization have not been verified against a captured event.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:14:48Z", "eventSource": "iam.amazonaws.com", "eventName": "AttachUserPolicy", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "userName": "draco", "policyArn": "arn:aws:iam::aws:policy/AdministratorAccess" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000000000011", "eventID": "90000000-0000-4000-8000-000000000100", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...