CreatePolicyVersion
CreatePolicyVersion
Event
Creates another version of an existing customer-managed policy. setAsDefault: true selects the new document for use; a nondefault version does not replace the operative document. A managed policy can hold up to five versions, requiring deletion of a nondefault version before adding another at the limit.
Security Context
An unauthorized default-version change can expand access without changing policy attachments. It can also alter restrictions when the policy is used as a boundary. This does not guarantee administrator access or affect all identities equally. Approved policy deployments use the same operation; T1098 is contextual to adversarial manipulation.
Log Source
AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: CreatePolicyVersion. Include IAM global-service events in collection. Check errorCode and errorMessage; responseElements: null alone does not establish failure.
Key Fields
Request fields below are under requestParameters unless another path is shown.
| Field | Investigation value |
|---|---|
userIdentity | Caller and session context; distinguish the caller from the target. |
policyArn | Policy being versioned; identify both permission attachments and boundary usage. |
policyDocument, setAsDefault | New document and whether it is selected for use. |
responseElements.policyVersion | Returned version ID and default status. |
eventTime, recipientAccountId, eventID, requestID | Timeline, account, and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context; neither proves malicious intent. |
errorCode, errorMessage | Distinguish failed attempts from completed changes. |
What to Investigate
- Confirm the request outcome, calling identity, account, and approved change. A recorded attempt is not necessarily a completed change.
- Compare the new document with the previously operative version. Check Allow, Deny, conditions, and resources, not just wildcard actions.
- Confirm default status and subsequent SetDefaultPolicyVersion events. Do not treat a staged nondefault version as an active access change.
- Enumerate affected users, groups, roles, and boundary consumers at the event time; verify newly possible actions and actual use. Account for IAM propagation rather than promising instantaneous results.
Sample Event
Synthetic scenario. Draco submits a wildcard Allow with setAsDefault: true; the illustrative response selects v2. The sample does not show the previous document, consumers, or resulting effective access.
This is an illustrative CloudTrail-shaped record. Exact field presence, timestamp formatting, and policy-document serialization have not been verified against a captured event. Preserve raw records before decoding any nested policy documents.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-16T00:24:51Z", "eventSource": "iam.amazonaws.com", "eventName": "CreatePolicyVersion", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "policyArn": "arn:aws:iam::555123456789:policy/OccamyPipelineLeastPrivilege", "policyDocument": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Action\":\"*\",\"Resource\":\"*\"}]}", "setAsDefault": true }, "responseElements": { "policyVersion": { "versionId": "v2", "isDefaultVersion": true, "createDate": "Apr 16, 2026, 12:24:51 AM" } }, "requestID": "90000000-0000-4000-8000-000010011000", "eventID": "90000000-0000-4000-8000-000010011001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...