ChangePassword
ChangePassword
Event
Changes the IAM caller’s own password, requiring the old and new passwords and compliance with the account password policy. It does not change the root password. An administrator uses UpdateLoginProfile to change another IAM user’s password.
Security Context
An unauthorized change may impede the legitimate user’s password login (T1531) or support account manipulation (T1098). Routine password maintenance produces the same event. This does not remove MFA devices, rotate access keys, or establish that every existing session was revoked.
Log Source
AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: ChangePassword. Check errorCode and errorMessage; a null response alone does not establish success or failure. Include IAM global-service events in collection.
Key Fields
| Field | Investigation value |
|---|---|
userIdentity | Identifies the user whose password is changing; there is no target userName parameter. |
requestParameters | Sensitive password arguments may be omitted; never expect readable passwords. |
eventTime, recipientAccountId, eventID, requestID | Timeline and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context, not a definitive attacker fingerprint. |
What to Investigate
- Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
- Verify the user’s authorization and expected password-maintenance workflow; inspect error details before claiming the password changed.
- Correlate ConsoleLogin and UpdateLoginProfile activity to distinguish self-service from administrator resets.
- Assess actual access disruption and credential changes separately; a password event does not prove a complete account takeover.
Sample Event
Synthetic scenario. Draco calls ChangePassword. The sample omits password arguments and shows no outcome of later sign-in attempts; it does not establish that a legitimate owner was locked out.
Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:21:07Z", "eventSource": "iam.amazonaws.com", "eventName": "ChangePassword", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": null, "responseElements": null, "requestID": "90000000-0000-4000-8000-000000000111", "eventID": "90000000-0000-4000-8000-000000001000", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Impact
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
- T1531 — Account Access Removal — Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts....