Skip to content

CreateAccount

AWS

CreateAccount

service: AWS - Organizations
tactics:
techniques:

Event

Creates a member account asynchronously from the organization management account. The request identifies an email address, account name, and optional administration role name. IN_PROGRESS is not completed creation; correlate the request ID with DescribeCreateAccountStatus or CreateAccountResult.

Security Context

Unauthorized account creation can establish additional cloud infrastructure or access (contextual T1136.003). Approved account provisioning is common. Creating a member account does not automatically create an independent backdoor into existing accounts; effective access depends on trust, policies, and subsequent credentials.

Log Source

AWS CloudTrail management event with eventSource: organizations.amazonaws.com and eventName: CreateAccount. Verify collection across the relevant accounts and Regions. Inspect response and error fields; the event does not by itself prove downstream use.

Key Fields

FieldInvestigation value
userIdentity, sourceIPAddressRecorded identity/client context, not proof of malicious intent.
eventName, eventSource, awsRegionOperation and collection context; distinguish requested target Region when applicable.
requestParameters, responseElementsRequest scope and outcome, where present.
eventID, eventTime, errorCode, errorMessageTiming, correlation, and errors; inspect related completion/sign-in records.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify the management-account actor, approved account owner/email, and requested role name.
  3. Follow the creation request to SUCCEEDED or FAILED and recover the actual new account ID.
  4. Review organization policies, new-account access roles, root-access management, and subsequent account activity.

Sample Event

Synthetic scenario. Hermione requests a sandbox member account. The response is IN_PROGRESS, with no completed account or subsequent access shown. The session MFA field is illustrative and does not establish business approval.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDAHERM10NE000ADM1N",
"arn": "arn:aws:iam::555700070007:user/hermione",
"accountId": "555700070007",
"accessKeyId": "ASIAHERM10NEEXAMPLE1",
"userName": "hermione",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T13:42:11Z",
"mfaAuthenticated": "true"
}
}
},
"eventTime": "2026-04-15T16:08:55Z",
"eventSource": "organizations.amazonaws.com",
"eventName": "CreateAccount",
"awsRegion": "us-east-1",
"sourceIPAddress": "198.51.100.42",
"userAgent": "aws-cli/2.15.30 Python/3.11.6 Linux/5.15.0-1052-aws exe/x86_64.ubuntu.22 prompt/off command/organizations.create-account",
"requestParameters": {
"email": "aws-luna-sandbox@fantasticlogs.cloud",
"accountName": "Luna Onboarding Sandbox",
"iamUserAccessToBilling": "DENY",
"roleName": "OrganizationAccountAccessRole"
},
"responseElements": {
"createAccountStatus": {
"id": "car-0123456789abcdef0123456789abcdef",
"accountName": "Luna Onboarding Sandbox",
"state": "IN_PROGRESS",
"requestedTimestamp": "Apr 15, 2026, 4:08:55 PM"
}
},
"requestID": "90000000-0000-4000-8000-000001111110",
"eventID": "90000000-0000-4000-8000-000001111111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555700070007",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence

Techniques:
  • T1136.003 — Cloud Account — Adversaries may create a cloud account to maintain access to victim systems. With a sufficient level of access, such accounts may be used to establish secondary credentialed access that does not require persistent remote access tools to be deployed on the system.
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.