Skip to content

CreateOpenIDConnectProvider

AWS

CreateOpenIDConnectProvider

service: AWS - IAM
techniques:

Event

Registers an OIDC issuer URL and configured audiences with IAM. A supplied certificate thumbprint must be a 40-character hexadecimal SHA-1 value; thumbprints are optional, and AWS can use its trusted CA library for TLS verification. Registration alone creates neither an IAM user nor a role session. A role must trust the provider and the presented token or assertion must satisfy validation and trust conditions.

Security Context

Unauthorized federation configuration can prepare an alternative access path, contextually matching T1556 and T1484.002. Approved identity-provider onboarding is normal. Establish control of the provider and usable role trust before claiming persistence or elevated access.

Log Source

AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: CreateOpenIDConnectProvider. Check errorCode and errorMessage before treating an attempt as successful; responseElements: null alone does not indicate failure. Include IAM global-service events in collection.

Key Fields

FieldInvestigation value
requestParameters.url, clientIDListIssuer and configured audience/client identifiers.
requestParameters.thumbprintListOptional TLS certificate thumbprints; distinguish TLS validation from token signing keys.
responseElements.openIDConnectProviderArnProvider ARN for correlation with role trust.
eventTime, recipientAccountId, eventID, requestIDTimeline, account, and correlation identifiers.

What to Investigate

  1. Confirm the outcome and match the caller, target, and timing to an approved workflow. Review failed attempts separately.
  2. Verify the issuer, audiences, discovery configuration, and signing-key ownership against the approved provider.
  3. Find roles trusting the provider, including UpdateAssumeRolePolicy changes. Review audience, subject, and other applicable conditions.
  4. Correlate AssumeRoleWithWebIdentity and subsequent role activity. Provider creation is not evidence of successful federation.

Sample Event

Synthetic scenario. Draco registers a fictional issuer, audience, and syntactically valid placeholder thumbprint. The reserved example domain is not a working identity provider; successful validation and token issuance are not demonstrated.

Exact CloudTrail nesting, field presence, redaction, and timestamp formatting remain unverified against captured logs. Credential/token placeholders and metadata placeholders are illustrative, not usable credentials or complete provider metadata.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T23:58:02Z",
"eventSource": "iam.amazonaws.com",
"eventName": "CreateOpenIDConnectProvider",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"url": "https://draco-idp-666.example",
"clientIDList": [
"draco-attacker-app"
],
"thumbprintList": [
"0123456789abcdef0123456789abcdef01234567"
]
},
"responseElements": {
"openIDConnectProviderArn": "arn:aws:iam::555123456789:oidc-provider/draco-idp-666.example"
},
"requestID": "90000000-0000-4000-8000-000010010100",
"eventID": "90000000-0000-4000-8000-000010010101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation Defense Impairment

Techniques:
  • T1556 — Modify Authentication Process — Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts. The authentication process is handled by mechanisms, such as the Local Security Authentication Server (LSASS) process and the Security Accounts Manager (SA...
  • T1484.002 — Trust Modification — Adversaries may add new domain trusts, modify the properties of existing domain trusts, or otherwise change the configuration of trust relationships between domains and tenants to evade defenses and/or elevate privileges.Trust details, such as whether or not user identities are federated, allow a...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.