CreateUser
CreateUser
Event
Creates an IAM user, optionally with tags, a path, and a permissions boundary. Access keys, a console password, group membership, and identity-policy grants are separate operations.
Security Context
An unauthorized user may be preparation for persistent access, matching T1136.003 when created for adversarial use. User creation alone does not prove the new identity can authenticate or perform privileged actions. Normal onboarding also uses this API.
Log Source
AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: CreateUser. Include IAM global-service events in collection. Check errorCode and errorMessage; responseElements: null alone does not establish failure.
Key Fields
Request fields below are under requestParameters unless another path is shown.
| Field | Investigation value |
|---|---|
userIdentity | Caller and session context; distinguish the caller from the target. |
userName, path, tags | Requested identity and optional organizational context; names are not proof of purpose. |
permissionsBoundary | Optional limit on identity-based grants; not itself a grant. |
responseElements.user | Returned ARN and user ID; use the ID to distinguish deletion and recreation. |
eventTime, recipientAccountId, eventID, requestID | Timeline, account, and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context; neither proves malicious intent. |
errorCode, errorMessage | Distinguish failed attempts from completed changes. |
What to Investigate
- Confirm the request outcome, calling identity, account, and approved change. A recorded attempt is not necessarily a completed change.
- Match the user to approved onboarding or automation and inspect any supplied boundary and tags.
- Correlate CreateAccessKey and CreateLoginProfile before claiming usable credentials exist.
- Review group and policy assignments and actual authentication or API activity. A matching employee name does not establish impersonation without additional evidence.
Sample Event
Synthetic scenario. Draco creates luna. The event shows no password, access keys, or permission assignment. Any relationship to a planned new hire or subsequent credential creation requires separate evidence.
This is an illustrative CloudTrail-shaped record. Exact field presence, timestamp formatting, and policy-document serialization have not been verified against a captured event. Preserve raw records before decoding any nested policy documents.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-16T01:31:08Z", "eventSource": "iam.amazonaws.com", "eventName": "CreateUser", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "userName": "luna" }, "responseElements": { "user": { "path": "/", "userName": "luna", "userId": "AIDA0666LUNA0BACKDOOR", "arn": "arn:aws:iam::555123456789:user/luna", "createDate": "Apr 16, 2026, 1:31:08 AM" } }, "requestID": "90000000-0000-4000-8000-000010100100", "eventID": "90000000-0000-4000-8000-000010100101", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence
- T1136.003 — Cloud Account — Adversaries may create a cloud account to maintain access to victim systems. With a sufficient level of access, such accounts may be used to establish secondary credentialed access that does not require persistent remote access tools to be deployed on the system.