Skip to content

CreateRole

AWS

CreateRole

service: AWS - IAM
techniques:

Event

Creates a role and its trust policy. Permissions policies are assigned separately; an optional permissions boundary limits grants rather than providing permissions. maxSessionDuration configures a session-duration ceiling, not evidence that a session was issued for that duration.

Security Context

Unauthorized role creation can prepare persistent access through a trusted principal. Approved workload and cross-account roles are routine. T1098.003 is contextual to additional-role access; creation alone is not proof of privileged credentials. An account principal such as arn:aws:iam::555666661337:root delegates trust to that account; it is not restricted to its root user and does not automatically authorize every identity there. Cross-account callers also need permission to assume the role, and trust conditions and other applicable restrictions must be satisfied.

Log Source

AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: CreateRole. Include IAM global-service events in collection. Check errorCode and errorMessage; responseElements: null alone does not establish failure.

Key Fields

Request fields below are under requestParameters unless another path is shown.

FieldInvestigation value
userIdentityCaller and session context; distinguish the caller from the target.
roleName, assumeRolePolicyDocumentNew role and trust principals, actions, and conditions.
permissionsBoundary, maxSessionDurationOptional boundary and duration settings; inspect any supplied values.
responseElements.roleReturned role ARN and stable role ID for correlation.
eventTime, recipientAccountId, eventID, requestIDTimeline, account, and correlation identifiers.
sourceIPAddress, userAgentSupporting context; neither proves malicious intent.
errorCode, errorMessageDistinguish failed attempts from completed changes.

What to Investigate

  1. Confirm the request outcome, calling identity, account, and approved change. A recorded attempt is not necessarily a completed change.
  2. Inspect every trust principal and condition against the intended workload or partner relationship. Verify ownership of external accounts.
  3. Correlate AttachRolePolicy and inline permissions, including boundaries. Establish what the role could actually do.
  4. Look for successful AssumeRole events and subsequent role-session activity; distinguish preparation from exercised access.

Sample Event

Synthetic scenario. Draco creates IncidentResponseSupport trusting an external account and sets a 43,200-second maximum. The sample does not establish malicious account ownership, attached permissions, or any successful role assumption.

This is an illustrative CloudTrail-shaped record. Exact field presence, timestamp formatting, and policy-document serialization have not been verified against a captured event. Preserve raw records before decoding any nested policy documents.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-16T00:38:14Z",
"eventSource": "iam.amazonaws.com",
"eventName": "CreateRole",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"roleName": "IncidentResponseSupport",
"description": "Cross-account incident response support role.",
"assumeRolePolicyDocument": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":{\"AWS\":\"arn:aws:iam::555666661337:root\"},\"Action\":\"sts:AssumeRole\"}]}",
"maxSessionDuration": 43200
},
"responseElements": {
"role": {
"path": "/",
"roleName": "IncidentResponseSupport",
"roleId": "AROA0666BACKDOORROLE",
"arn": "arn:aws:iam::555123456789:role/IncidentResponseSupport",
"createDate": "Apr 16, 2026, 12:38:14 AM",
"assumeRolePolicyDocument": "%7B%22Version%22%3A%222012-10-17%22%2C%22Statement%22%3A%5B%7B%22Effect%22%3A%22Allow%22%2C%22Principal%22%3A%7B%22AWS%22%3A%22arn%3Aaws%3Aiam%3A%3A555666661337%3Aroot%22%7D%2C%22Action%22%3A%22sts%3AAssumeRole%22%7D%5D%7D"
}
},
"requestID": "90000000-0000-4000-8000-000010011010",
"eventID": "90000000-0000-4000-8000-000010011011",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.