CreateRole
CreateRole
Event
Creates a role and its trust policy. Permissions policies are assigned separately; an optional permissions boundary limits grants rather than providing permissions. maxSessionDuration configures a session-duration ceiling, not evidence that a session was issued for that duration.
Security Context
Unauthorized role creation can prepare persistent access through a trusted principal. Approved workload and cross-account roles are routine. T1098.003 is contextual to additional-role access; creation alone is not proof of privileged credentials. An account principal such as arn:aws:iam::555666661337:root delegates trust to that account; it is not restricted to its root user and does not automatically authorize every identity there. Cross-account callers also need permission to assume the role, and trust conditions and other applicable restrictions must be satisfied.
Log Source
AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: CreateRole. Include IAM global-service events in collection. Check errorCode and errorMessage; responseElements: null alone does not establish failure.
Key Fields
Request fields below are under requestParameters unless another path is shown.
| Field | Investigation value |
|---|---|
userIdentity | Caller and session context; distinguish the caller from the target. |
roleName, assumeRolePolicyDocument | New role and trust principals, actions, and conditions. |
permissionsBoundary, maxSessionDuration | Optional boundary and duration settings; inspect any supplied values. |
responseElements.role | Returned role ARN and stable role ID for correlation. |
eventTime, recipientAccountId, eventID, requestID | Timeline, account, and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context; neither proves malicious intent. |
errorCode, errorMessage | Distinguish failed attempts from completed changes. |
What to Investigate
- Confirm the request outcome, calling identity, account, and approved change. A recorded attempt is not necessarily a completed change.
- Inspect every trust principal and condition against the intended workload or partner relationship. Verify ownership of external accounts.
- Correlate AttachRolePolicy and inline permissions, including boundaries. Establish what the role could actually do.
- Look for successful AssumeRole events and subsequent role-session activity; distinguish preparation from exercised access.
Sample Event
Synthetic scenario. Draco creates IncidentResponseSupport trusting an external account and sets a 43,200-second maximum. The sample does not establish malicious account ownership, attached permissions, or any successful role assumption.
This is an illustrative CloudTrail-shaped record. Exact field presence, timestamp formatting, and policy-document serialization have not been verified against a captured event. Preserve raw records before decoding any nested policy documents.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-16T00:38:14Z", "eventSource": "iam.amazonaws.com", "eventName": "CreateRole", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "roleName": "IncidentResponseSupport", "description": "Cross-account incident response support role.", "assumeRolePolicyDocument": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Principal\":{\"AWS\":\"arn:aws:iam::555666661337:root\"},\"Action\":\"sts:AssumeRole\"}]}", "maxSessionDuration": 43200 }, "responseElements": { "role": { "path": "/", "roleName": "IncidentResponseSupport", "roleId": "AROA0666BACKDOORROLE", "arn": "arn:aws:iam::555123456789:role/IncidentResponseSupport", "createDate": "Apr 16, 2026, 12:38:14 AM", "assumeRolePolicyDocument": "%7B%22Version%22%3A%222012-10-17%22%2C%22Statement%22%3A%5B%7B%22Effect%22%3A%22Allow%22%2C%22Principal%22%3A%7B%22AWS%22%3A%22arn%3Aaws%3Aiam%3A%3A555666661337%3Aroot%22%7D%2C%22Action%22%3A%22sts%3AAssumeRole%22%7D%5D%7D" } }, "requestID": "90000000-0000-4000-8000-000010011010", "eventID": "90000000-0000-4000-8000-000010011011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...