Skip to content

CreateVirtualMFADevice

AWS

CreateVirtualMFADevice

service: AWS - IAM
techniques:

Event

Creates a virtual MFA device and returns enrollment material to the caller. EnableMFADevice is a separate operation that associates it with a user. The device name does not identify an association, and creation does not replace an existing MFA device.

Security Context

Creating a device can prepare unauthorized MFA enrollment, contextually related to T1098.005. Normal enrollment is common. Possession of an MFA seed alone does not grant access or survive a password reset as a complete authentication method; IAM supports multiple MFA devices, so an additional device does not automatically lock out the owner.

Log Source

AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: CreateVirtualMFADevice. Check errorCode and errorMessage; a null response alone does not establish success or failure. Include IAM global-service events in collection.

Key Fields

FieldInvestigation value
requestParameters.virtualMFADeviceName, pathRequested device identity, not the associated user.
responseElements.virtualMFADevice.serialNumberDevice ARN for later EnableMFADevice correlation; seed material is sensitive.
eventTime, recipientAccountId, eventID, requestIDTimeline and correlation identifiers.
sourceIPAddress, userAgentSupporting context, not a definitive attacker fingerprint.

What to Investigate

  1. Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
  2. Match creation to an enrollment request and inspect the caller; do not infer ownership from the device name.
  3. Find a subsequent EnableMFADevice for the same serial number and identify the target user. Creation alone leaves enrollment incomplete.
  4. Inspect existing devices and DeactivateMFADevice activity, then correlate authentication evidence. Do not request or expose the seed.

Sample Event

Synthetic scenario. Draco creates draco-totp. No enablement or removal of another device is shown, so the sample does not establish enrollment or lockout.

Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-16T01:44:21Z",
"eventSource": "iam.amazonaws.com",
"eventName": "CreateVirtualMFADevice",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"virtualMFADeviceName": "draco-totp"
},
"responseElements": {
"virtualMFADevice": {
"serialNumber": "arn:aws:iam::555123456789:mfa/draco-totp"
}
},
"requestID": "90000000-0000-4000-8000-000010100110",
"eventID": "90000000-0000-4000-8000-000010100111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098.005 — Device Registration — Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.