Skip to content

CreatePolicyVersion

AWS

CreatePolicyVersion

service: AWS - IAM
techniques:

Event

Creates another version of an existing customer-managed policy. setAsDefault: true selects the new document for use; a nondefault version does not replace the operative document. A managed policy can hold up to five versions, requiring deletion of a nondefault version before adding another at the limit.

Security Context

An unauthorized default-version change can expand access without changing policy attachments. It can also alter restrictions when the policy is used as a boundary. This does not guarantee administrator access or affect all identities equally. Approved policy deployments use the same operation; T1098 is contextual to adversarial manipulation.

Log Source

AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: CreatePolicyVersion. Include IAM global-service events in collection. Check errorCode and errorMessage; responseElements: null alone does not establish failure.

Key Fields

Request fields below are under requestParameters unless another path is shown.

FieldInvestigation value
userIdentityCaller and session context; distinguish the caller from the target.
policyArnPolicy being versioned; identify both permission attachments and boundary usage.
policyDocument, setAsDefaultNew document and whether it is selected for use.
responseElements.policyVersionReturned version ID and default status.
eventTime, recipientAccountId, eventID, requestIDTimeline, account, and correlation identifiers.
sourceIPAddress, userAgentSupporting context; neither proves malicious intent.
errorCode, errorMessageDistinguish failed attempts from completed changes.

What to Investigate

  1. Confirm the request outcome, calling identity, account, and approved change. A recorded attempt is not necessarily a completed change.
  2. Compare the new document with the previously operative version. Check Allow, Deny, conditions, and resources, not just wildcard actions.
  3. Confirm default status and subsequent SetDefaultPolicyVersion events. Do not treat a staged nondefault version as an active access change.
  4. Enumerate affected users, groups, roles, and boundary consumers at the event time; verify newly possible actions and actual use. Account for IAM propagation rather than promising instantaneous results.

Sample Event

Synthetic scenario. Draco submits a wildcard Allow with setAsDefault: true; the illustrative response selects v2. The sample does not show the previous document, consumers, or resulting effective access.

This is an illustrative CloudTrail-shaped record. Exact field presence, timestamp formatting, and policy-document serialization have not been verified against a captured event. Preserve raw records before decoding any nested policy documents.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-16T00:24:51Z",
"eventSource": "iam.amazonaws.com",
"eventName": "CreatePolicyVersion",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"policyArn": "arn:aws:iam::555123456789:policy/OccamyPipelineLeastPrivilege",
"policyDocument": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Action\":\"*\",\"Resource\":\"*\"}]}",
"setAsDefault": true
},
"responseElements": {
"policyVersion": {
"versionId": "v2",
"isDefaultVersion": true,
"createDate": "Apr 16, 2026, 12:24:51 AM"
}
},
"requestID": "90000000-0000-4000-8000-000010011000",
"eventID": "90000000-0000-4000-8000-000010011001",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.