Skip to content

CreateDevEndpoint

AWS

CreateDevEndpoint

service: AWS - Glue
techniques:

Event

Provisions a development environment with an execution role and optional SSH public key/network settings. Development endpoints support Glue 0.9 and 1.0, not Glue 2.0 or later. They remain an API/CLI workflow after removal from the console; interactive sessions are a separate workflow. The legacy version in this sample is illustrative, not a recommendation.

Security Context

Unauthorized creation may establish access under a more privileged role (contextual T1098). Effective access depends on iam:PassRole, Glue role trust and permissions, endpoint readiness, network reachability, and possession of a matching private key. Creation does not grant unrestricted access to a VPC.

Log Source

CloudTrail management event with eventSource: glue.amazonaws.com and eventName: CreateDevEndpoint. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.

Key Fields

Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.

FieldInvestigation value
endpointName, roleArn, glueVersionEndpoint, execution role, and legacy runtime.
publicKey, subnetId, securityGroupIdsRequested SSH authentication and network settings where supplied.
userIdentity, eventTime, awsRegion, eventID (top level)Caller/session, timeline, Region, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Verify the role delegation and approved development workflow.
  3. Check final endpoint status, effective role access, subnet/security-group configuration, and actual reachability.
  4. Correlate endpoint connections and data operations before claiming role use or exfiltration.

Sample Event

Synthetic scenario. A Glue 1.0 endpoint is requested and remains PROVISIONING. The example public key was generated locally solely for illustration; its private key was discarded.

Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T22:18:42Z",
"eventSource": "glue.amazonaws.com",
"eventName": "CreateDevEndpoint",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"endpointName": "demiguise-debug-666",
"roleArn": "arn:aws:iam::555123456789:role/DemiguiseInferenceRole",
"publicKey": "ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC7jKZjbz9i7H+GAYLq2AyQN2G5axXRa6g+cvoXwHE7xxfK8VdIZG9TYIfBq82PsmKqLOWDuU3sOIwpMv5HdJZNvUARdgJC12URH+5JeLYlQ61mISA7SU2CdUVe8CPiR9YezvH71+u4LIVZqg4yID4rvhfdlwc1lB7aphrLGYjNoqw7Q0lyudCip2j0x7/9LDHZ2AY5l7KEYEsVTGAEtnHCet5RRV9S7OUyw2FsL6EVwep2P19nFbur25LmepVHslHLXJJzmlmYBscs//Fn/Hrbf91XxZ9MWE6KoWpsk5IKFqpa1jGNG67dyoe4lEA/gCIVo4RiYBMfD9NWHf7GX2lb synthetic-review-example",
"numberOfNodes": 5,
"glueVersion": "1.0",
"arguments": {
"--enable-glue-datacatalog": ""
}
},
"responseElements": {
"endpointName": "demiguise-debug-666",
"status": "PROVISIONING",
"roleArn": "arn:aws:iam::555123456789:role/DemiguiseInferenceRole",
"numberOfNodes": 5,
"glueVersion": "1.0",
"arguments": {
"--enable-glue-datacatalog": ""
},
"createdTimestamp": "Apr 15, 2026, 10:18:42 PM"
},
"requestID": "90000000-0000-4000-8000-000010000100",
"eventID": "90000000-0000-4000-8000-000010000101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "glue.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.