Skip to content

CreateServiceLinkedRole

AWS

CreateServiceLinkedRole

service: AWS - IAM
techniques:

Event

Creates a service-linked role with service-defined trust and permissions. The linked service controls its policies and deletion prerequisites. The caller does not choose an arbitrary trust policy or gain the ability to assume the role simply by creating it.

Security Context

Creation is common when enabling an AWS service. Service-linked roles are not restricted by SCPs, but this exemption does not give the creator general unrestricted access: the relevant service must perform supported actions through its role. T1098.003 is contextual only where a broader unauthorized service workflow establishes additional access; creation alone does not show escalation.

Log Source

AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: CreateServiceLinkedRole. Check errorCode and errorMessage before treating an attempt as successful; responseElements: null alone does not indicate failure. Include IAM global-service events in collection.

Key Fields

FieldInvestigation value
requestParameters.aWSServiceNameLinked service principal; casing here follows the illustrative record.
responseElements.roleService-linked path, ARN, and trust document.
userIdentityActual logged caller; do not relabel an IAMUser as an AWSService identity.
eventTime, recipientAccountId, eventID, requestIDTimeline, account, and correlation identifiers.

What to Investigate

  1. Confirm the outcome and match the caller, target, and timing to an approved workflow. Review failed attempts separately.
  2. Match the service to an approved enablement or configuration change and its documented service-linked-role behavior.
  3. Inspect the service-defined trust and policy scope; identify which service operations the caller could actually invoke.
  4. Correlate service onboarding and subsequent service actions. Distinguish role creation from unauthorized use and check the recorded caller rather than inferring it from a user-agent string.

Sample Event

Synthetic scenario. Hermione directly requests the GuardDuty service-linked role. This sample uses IAMUser attribution and does not claim to reproduce the automatic CreateDetector onboarding flow.

Exact CloudTrail nesting, field presence, redaction, and timestamp formatting remain unverified against captured logs. Credential/token placeholders and metadata placeholders are illustrative, not usable credentials or complete provider metadata.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDAHERM10NE000ADM1N",
"arn": "arn:aws:iam::555123456789:user/hermione",
"accountId": "555123456789",
"accessKeyId": "ASIAHERM10NEEXAMPLE1",
"userName": "hermione",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T13:42:11Z",
"mfaAuthenticated": "true"
}
}
},
"eventTime": "2026-04-15T14:22:46Z",
"eventSource": "iam.amazonaws.com",
"eventName": "CreateServiceLinkedRole",
"awsRegion": "us-east-1",
"sourceIPAddress": "198.51.100.42",
"userAgent": "aws-cli/2.15.30 Python/3.11.6 Linux/5.15.0-1052-aws exe/x86_64.ubuntu.22 prompt/off command/iam.create-service-linked-role",
"requestParameters": {
"aWSServiceName": "guardduty.amazonaws.com",
"description": "Service-linked role for GuardDuty"
},
"responseElements": {
"role": {
"path": "/aws-service-role/guardduty.amazonaws.com/",
"roleName": "AWSServiceRoleForAmazonGuardDuty",
"roleId": "AROAGUARDDUTYSLR00001",
"arn": "arn:aws:iam::555123456789:role/aws-service-role/guardduty.amazonaws.com/AWSServiceRoleForAmazonGuardDuty",
"createDate": "Apr 15, 2026, 2:22:46 PM",
"assumeRolePolicyDocument": "%7B%22Version%22%3A%222012-10-17%22%2C%22Statement%22%3A%5B%7B%22Effect%22%3A%22Allow%22%2C%22Principal%22%3A%7B%22Service%22%3A%22guardduty.amazonaws.com%22%7D%2C%22Action%22%3A%22sts%3AAssumeRole%22%7D%5D%7D"
}
},
"requestID": "90000000-0000-4000-8000-000010011110",
"eventID": "90000000-0000-4000-8000-000010011111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation

Techniques:
  • T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.