CreateLoginProfile
CreateLoginProfile
Event
Creates a console password for an existing IAM user. An existing login profile must be updated instead; this operation does not create the IAM user or API access keys.
Security Context
An unauthorized console credential can provide an additional access path, contextually matching T1098.001. Approved onboarding does the same. Neither operation grants permissions, removes MFA devices, or changes access keys. A password setting is not proof of a successful console sign-in.
Log Source
AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: CreateLoginProfile. Include IAM global-service events in collection. Check errorCode and errorMessage; responseElements: null alone does not establish failure.
Key Fields
Request fields below are under requestParameters unless another path is shown.
| Field | Investigation value |
|---|---|
userIdentity | Caller and session context; distinguish the caller from the target. |
userName | Target IAM user, distinct from the calling identity. |
passwordResetRequired | Whether the user must change the password at next sign-in; false does not bypass MFA. |
password | Sensitive input; do not expect a readable password in CloudTrail or infer its value from a redaction. |
eventTime, recipientAccountId, eventID, requestID | Timeline, account, and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context; neither proves malicious intent. |
errorCode, errorMessage | Distinguish failed attempts from completed changes. |
What to Investigate
- Confirm the request outcome, calling identity, account, and approved change. A recorded attempt is not necessarily a completed change.
- Check the approved onboarding or reset record and confirm exactly which settings changed. Account password-policy requirements and operation errors matter.
- Inspect MFA configuration and existing permissions separately. Do not assume this event disables MFA, revokes API keys, or invalidates every existing session.
- Correlate ConsoleLogin outcomes and subsequent user activity; investigate DeactivateMFADevice only if separate evidence shows it occurred.
Sample Event
Synthetic scenario. Draco creates a login profile for luna, with the password redacted and passwordResetRequired false. This provides no evidence of the user’s prior programmatic access or successful console use.
This is an illustrative CloudTrail-shaped record. Exact field presence, timestamp formatting, and policy-document serialization have not been verified against a captured event. Preserve raw records before decoding any nested policy documents.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T23:33:25Z", "eventSource": "iam.amazonaws.com", "eventName": "CreateLoginProfile", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "userName": "luna", "password": "HIDDEN_DUE_TO_SECURITY_REASONS", "passwordResetRequired": false }, "responseElements": { "loginProfile": { "userName": "luna", "createDate": "Apr 15, 2026, 11:33:25 PM", "passwordResetRequired": false } }, "requestID": "90000000-0000-4000-8000-000010010000", "eventID": "90000000-0000-4000-8000-000010010001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098.001 — Additional Cloud Credentials — Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment.