CreateStack
CreateStack
Event
Begins asynchronous resource provisioning from a template. CAPABILITY_NAMED_IAM acknowledges named IAM resources; it does not grant IAM permissions. With RoleARN, CloudFormation uses the specified service role; otherwise it uses a temporary session derived from the caller’s credentials. A returned stack ID is not CREATE_COMPLETE.
Security Context
Unauthorized orchestration can abuse deployment tooling (contextual T1072). The template must be inspected before asserting creation of a backdoor, account, or executable payload. Routine infrastructure deployment generates the same event.
Log Source
CloudTrail management event with eventSource: cloudformation.amazonaws.com and eventName: CreateStack. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.
Key Fields
Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.
| Field | Investigation value |
|---|---|
stackName, templateURL, templateBody | Stack and template reference/content; identify the exact submitted artifact. |
roleARN, capabilities, onFailure | Execution authorization, acknowledgements, and failure handling. |
userIdentity, eventTime, awsRegion, eventID (top level) | Caller/session, timeline, Region, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Recover the submitted template and parameter values through approved records; a bucket/key name does not establish resource contents.
- Check caller or service-role permissions and the resulting stack events and resource inventory.
- Verify completion/failure, rollback behavior, and residual resources. DO_NOTHING can leave resources from a failed deployment.
Sample Event
Synthetic scenario. The request references a fictional S3 template and acknowledges named IAM resources. Neither template contents nor successful provisioning are shown.
Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-16T01:18:42Z", "eventSource": "cloudformation.amazonaws.com", "eventName": "CreateStack", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "stackName": "OccamyMonitoringEnhancement", "templateURL": "https://s3.amazonaws.com/draco-exfil-bucket-666/templates/monitoring-666.yaml", "capabilities": [ "CAPABILITY_NAMED_IAM" ], "onFailure": "DO_NOTHING" }, "responseElements": { "stackId": "arn:aws:cloudformation:us-east-1:555123456789:stack/OccamyMonitoringEnhancement/66666666-0000-4000-8000-001010011010" }, "requestID": "90000000-0000-4000-8000-000010100010", "eventID": "90000000-0000-4000-8000-000010100011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "cloudformation.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Execution
- T1072 — Software Deployment Tools — Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network. Configuration management and software deployment applications may be used in an enterprise network or cloud environment for routine adminis...