CreateAccount
CreateAccount
Event
Creates a member account asynchronously from the organization management account. The request identifies an email address, account name, and optional administration role name. IN_PROGRESS is not completed creation; correlate the request ID with DescribeCreateAccountStatus or CreateAccountResult.
Security Context
Unauthorized account creation can establish additional cloud infrastructure or access (contextual T1136.003). Approved account provisioning is common. Creating a member account does not automatically create an independent backdoor into existing accounts; effective access depends on trust, policies, and subsequent credentials.
Log Source
AWS CloudTrail management event with eventSource: organizations.amazonaws.com and eventName: CreateAccount. Verify collection across the relevant accounts and Regions. Inspect response and error fields; the event does not by itself prove downstream use.
Key Fields
| Field | Investigation value |
|---|---|
userIdentity, sourceIPAddress | Recorded identity/client context, not proof of malicious intent. |
eventName, eventSource, awsRegion | Operation and collection context; distinguish requested target Region when applicable. |
requestParameters, responseElements | Request scope and outcome, where present. |
eventID, eventTime, errorCode, errorMessage | Timing, correlation, and errors; inspect related completion/sign-in records. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify the management-account actor, approved account owner/email, and requested role name.
- Follow the creation request to SUCCEEDED or FAILED and recover the actual new account ID.
- Review organization policies, new-account access roles, root-access management, and subsequent account activity.
Sample Event
Synthetic scenario. Hermione requests a sandbox member account. The response is IN_PROGRESS, with no completed account or subsequent access shown. The session MFA field is illustrative and does not establish business approval.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDAHERM10NE000ADM1N", "arn": "arn:aws:iam::555700070007:user/hermione", "accountId": "555700070007", "accessKeyId": "ASIAHERM10NEEXAMPLE1", "userName": "hermione", "sessionContext": { "attributes": { "creationDate": "2026-04-15T13:42:11Z", "mfaAuthenticated": "true" } } }, "eventTime": "2026-04-15T16:08:55Z", "eventSource": "organizations.amazonaws.com", "eventName": "CreateAccount", "awsRegion": "us-east-1", "sourceIPAddress": "198.51.100.42", "userAgent": "aws-cli/2.15.30 Python/3.11.6 Linux/5.15.0-1052-aws exe/x86_64.ubuntu.22 prompt/off command/organizations.create-account", "requestParameters": { "email": "aws-luna-sandbox@fantasticlogs.cloud", "accountName": "Luna Onboarding Sandbox", "iamUserAccessToBilling": "DENY", "roleName": "OrganizationAccountAccessRole" }, "responseElements": { "createAccountStatus": { "id": "car-0123456789abcdef0123456789abcdef", "accountName": "Luna Onboarding Sandbox", "state": "IN_PROGRESS", "requestedTimestamp": "Apr 15, 2026, 4:08:55 PM" } }, "requestID": "90000000-0000-4000-8000-000001111110", "eventID": "90000000-0000-4000-8000-000001111111", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555700070007", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence
- T1136.003 — Cloud Account — Adversaries may create a cloud account to maintain access to victim systems. With a sufficient level of access, such accounts may be used to establish secondary credentialed access that does not require persistent remote access tools to be deployed on the system.