Skip to content

CreateLoginProfile

AWS

CreateLoginProfile

service: AWS - IAM
techniques:

Event

Creates a console password for an existing IAM user. An existing login profile must be updated instead; this operation does not create the IAM user or API access keys.

Security Context

An unauthorized console credential can provide an additional access path, contextually matching T1098.001. Approved onboarding does the same. Neither operation grants permissions, removes MFA devices, or changes access keys. A password setting is not proof of a successful console sign-in.

Log Source

AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: CreateLoginProfile. Include IAM global-service events in collection. Check errorCode and errorMessage; responseElements: null alone does not establish failure.

Key Fields

Request fields below are under requestParameters unless another path is shown.

FieldInvestigation value
userIdentityCaller and session context; distinguish the caller from the target.
userNameTarget IAM user, distinct from the calling identity.
passwordResetRequiredWhether the user must change the password at next sign-in; false does not bypass MFA.
passwordSensitive input; do not expect a readable password in CloudTrail or infer its value from a redaction.
eventTime, recipientAccountId, eventID, requestIDTimeline, account, and correlation identifiers.
sourceIPAddress, userAgentSupporting context; neither proves malicious intent.
errorCode, errorMessageDistinguish failed attempts from completed changes.

What to Investigate

  1. Confirm the request outcome, calling identity, account, and approved change. A recorded attempt is not necessarily a completed change.
  2. Check the approved onboarding or reset record and confirm exactly which settings changed. Account password-policy requirements and operation errors matter.
  3. Inspect MFA configuration and existing permissions separately. Do not assume this event disables MFA, revokes API keys, or invalidates every existing session.
  4. Correlate ConsoleLogin outcomes and subsequent user activity; investigate DeactivateMFADevice only if separate evidence shows it occurred.

Sample Event

Synthetic scenario. Draco creates a login profile for luna, with the password redacted and passwordResetRequired false. This provides no evidence of the user’s prior programmatic access or successful console use.

This is an illustrative CloudTrail-shaped record. Exact field presence, timestamp formatting, and policy-document serialization have not been verified against a captured event. Preserve raw records before decoding any nested policy documents.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T23:33:25Z",
"eventSource": "iam.amazonaws.com",
"eventName": "CreateLoginProfile",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"userName": "luna",
"password": "HIDDEN_DUE_TO_SECURITY_REASONS",
"passwordResetRequired": false
},
"responseElements": {
"loginProfile": {
"userName": "luna",
"createDate": "Apr 15, 2026, 11:33:25 PM",
"passwordResetRequired": false
}
},
"requestID": "90000000-0000-4000-8000-000010010000",
"eventID": "90000000-0000-4000-8000-000010010001",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098.001 — Additional Cloud Credentials — Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment.
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.