CreatePolicy
CreatePolicy
Event
Creates a customer-managed permissions policy and its initial default version, v1. Creating the policy does not attach it to an identity or select it as a permissions boundary.
Security Context
A broad policy can prepare for unauthorized access, but creation alone grants no access to its creator. Normal infrastructure provisioning also creates policies. The T1098 mapping requires evidence of a larger account-manipulation sequence; a name or wildcard statement alone does not establish malicious intent.
Log Source
AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: CreatePolicy. Include IAM global-service events in collection. Check errorCode and errorMessage; responseElements: null alone does not establish failure.
Key Fields
Request fields below are under requestParameters unless another path is shown.
| Field | Investigation value |
|---|---|
userIdentity | Caller and session context; distinguish the caller from the target. |
policyName, path | Identify the new policy; use the returned ARN to correlate later use. |
policyDocument | Submitted statements, including conditions and explicit denies. |
responseElements.policy | Returned ARN, policy ID, and default version; distinguish this from an attachment. |
eventTime, recipientAccountId, eventID, requestID | Timeline, account, and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context; neither proves malicious intent. |
errorCode, errorMessage | Distinguish failed attempts from completed changes. |
What to Investigate
- Confirm the request outcome, calling identity, account, and approved change. A recorded attempt is not necessarily a completed change.
- Inspect the full policy document, preserving raw data and decoding an encoded representation before parsing. Compare it with the approved infrastructure definition.
- Correlate AttachUserPolicy, AttachRolePolicy, and boundary assignments using the returned ARN. Creation alone does not prove later attachment.
- Determine who actually gains access after the policy is used, considering other policies, boundaries, organization controls, and explicit denies.
Sample Event
Synthetic scenario. Draco creates OccamyPipelineDebugAccess with a wildcard Allow. The illustrative response shows zero attachments and boundary uses. Any later attachment, attacker control, or successful privileged action requires separate evidence.
This is an illustrative CloudTrail-shaped record. Exact field presence, timestamp formatting, and policy-document serialization have not been verified against a captured event. Preserve raw records before decoding any nested policy documents.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-16T00:11:32Z", "eventSource": "iam.amazonaws.com", "eventName": "CreatePolicy", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "policyName": "OccamyPipelineDebugAccess", "policyDocument": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Action\":\"*\",\"Resource\":\"*\"}]}" }, "responseElements": { "policy": { "policyName": "OccamyPipelineDebugAccess", "policyId": "ANPA0CCAMYDEBUG666660", "arn": "arn:aws:iam::555123456789:policy/OccamyPipelineDebugAccess", "path": "/", "defaultVersionId": "v1", "attachmentCount": 0, "permissionsBoundaryUsageCount": 0, "isAttachable": true, "createDate": "Apr 16, 2026, 12:11:32 AM", "updateDate": "Apr 16, 2026, 12:11:32 AM" } }, "requestID": "90000000-0000-4000-8000-000010010110", "eventID": "90000000-0000-4000-8000-000010010111", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...