Skip to content

CreatePolicy

AWS

CreatePolicy

service: AWS - IAM
techniques:

Event

Creates a customer-managed permissions policy and its initial default version, v1. Creating the policy does not attach it to an identity or select it as a permissions boundary.

Security Context

A broad policy can prepare for unauthorized access, but creation alone grants no access to its creator. Normal infrastructure provisioning also creates policies. The T1098 mapping requires evidence of a larger account-manipulation sequence; a name or wildcard statement alone does not establish malicious intent.

Log Source

AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: CreatePolicy. Include IAM global-service events in collection. Check errorCode and errorMessage; responseElements: null alone does not establish failure.

Key Fields

Request fields below are under requestParameters unless another path is shown.

FieldInvestigation value
userIdentityCaller and session context; distinguish the caller from the target.
policyName, pathIdentify the new policy; use the returned ARN to correlate later use.
policyDocumentSubmitted statements, including conditions and explicit denies.
responseElements.policyReturned ARN, policy ID, and default version; distinguish this from an attachment.
eventTime, recipientAccountId, eventID, requestIDTimeline, account, and correlation identifiers.
sourceIPAddress, userAgentSupporting context; neither proves malicious intent.
errorCode, errorMessageDistinguish failed attempts from completed changes.

What to Investigate

  1. Confirm the request outcome, calling identity, account, and approved change. A recorded attempt is not necessarily a completed change.
  2. Inspect the full policy document, preserving raw data and decoding an encoded representation before parsing. Compare it with the approved infrastructure definition.
  3. Correlate AttachUserPolicy, AttachRolePolicy, and boundary assignments using the returned ARN. Creation alone does not prove later attachment.
  4. Determine who actually gains access after the policy is used, considering other policies, boundaries, organization controls, and explicit denies.

Sample Event

Synthetic scenario. Draco creates OccamyPipelineDebugAccess with a wildcard Allow. The illustrative response shows zero attachments and boundary uses. Any later attachment, attacker control, or successful privileged action requires separate evidence.

This is an illustrative CloudTrail-shaped record. Exact field presence, timestamp formatting, and policy-document serialization have not been verified against a captured event. Preserve raw records before decoding any nested policy documents.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-16T00:11:32Z",
"eventSource": "iam.amazonaws.com",
"eventName": "CreatePolicy",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"policyName": "OccamyPipelineDebugAccess",
"policyDocument": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Action\":\"*\",\"Resource\":\"*\"}]}"
},
"responseElements": {
"policy": {
"policyName": "OccamyPipelineDebugAccess",
"policyId": "ANPA0CCAMYDEBUG666660",
"arn": "arn:aws:iam::555123456789:policy/OccamyPipelineDebugAccess",
"path": "/",
"defaultVersionId": "v1",
"attachmentCount": 0,
"permissionsBoundaryUsageCount": 0,
"isAttachable": true,
"createDate": "Apr 16, 2026, 12:11:32 AM",
"updateDate": "Apr 16, 2026, 12:11:32 AM"
}
},
"requestID": "90000000-0000-4000-8000-000010010110",
"eventID": "90000000-0000-4000-8000-000010010111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.