Skip to content

CreateAccessEntry

AWS

CreateAccessEntry

service: AWS - EKS
techniques:

Event

Associates an IAM principal with an EKS cluster using access-entry authentication. The cluster must use API or API_AND_CONFIG_MAP mode. A STANDARD entry can use Kubernetes groups, EKS access-policy associations, or both. A group name grants no Kubernetes privileges unless applicable RBAC bindings exist; creating the entry does not create IAM credentials.

Security Context

Unauthorized access-entry creation may manipulate persistent access or elevate privileges (T1098). Actual permissions depend on RBAC and associated access policies/scopes. The entry alone does not prove cluster-admin access, successful authentication, or workload changes.

Log Source

CloudTrail management event with eventSource: eks.amazonaws.com and eventName: CreateAccessEntry. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.

Key Fields

Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.

FieldInvestigation value
clusterName, principalArn, typeCluster, existing IAM principal, and access-entry type; preserve raw CloudTrail field spelling.
kubernetesGroupsGroup names to resolve against Kubernetes RBAC, not self-contained permission grants.
userIdentity, eventTime, awsRegion, eventID (top level)Caller/session, timeline, Region, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Check authentication mode, principal ownership, entry type, and change approval.
  3. Resolve group RoleBindings/ClusterRoleBindings and associated EKS access policies with their scopes.
  4. Allow for eventual consistency and correlate Kubernetes audit records with actual API actions.

Sample Event

Synthetic scenario. A STANDARD entry maps an IAM user to the custom group incident-reviewers. The sample does not include an RBAC binding or an EKS access-policy association, so no particular Kubernetes privilege is established.

Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T21:34:21Z",
"eventSource": "eks.amazonaws.com",
"eventName": "CreateAccessEntry",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"principalArn": "arn:aws:iam::555123456789:user/draco",
"kubernetesGroups": [
"incident-reviewers"
],
"type": "STANDARD",
"clientRequestToken": "60000000-0000-4000-8000-001010011010",
"clusterName": "demiguise-prod"
},
"responseElements": {
"accessEntry": {
"clusterName": "demiguise-prod",
"principalArn": "arn:aws:iam::555123456789:user/draco",
"kubernetesGroups": [
"incident-reviewers"
],
"accessEntryArn": "arn:aws:eks:us-east-1:555123456789:access-entry/demiguise-prod/user/555123456789/draco/60000000-0000-4000-8000-001010011010",
"createdAt": 1776288861.0,
"modifiedAt": 1776288861.0,
"tags": {},
"username": "arn:aws:iam::555123456789:user/draco",
"type": "STANDARD"
}
},
"requestID": "90000000-0000-4000-8000-000001111100",
"eventID": "90000000-0000-4000-8000-000001111101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "eks.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.