CreateVirtualMFADevice
CreateVirtualMFADevice
Event
Creates a virtual MFA device and returns enrollment material to the caller. EnableMFADevice is a separate operation that associates it with a user. The device name does not identify an association, and creation does not replace an existing MFA device.
Security Context
Creating a device can prepare unauthorized MFA enrollment, contextually related to T1098.005. Normal enrollment is common. Possession of an MFA seed alone does not grant access or survive a password reset as a complete authentication method; IAM supports multiple MFA devices, so an additional device does not automatically lock out the owner.
Log Source
AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: CreateVirtualMFADevice. Check errorCode and errorMessage; a null response alone does not establish success or failure. Include IAM global-service events in collection.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.virtualMFADeviceName, path | Requested device identity, not the associated user. |
responseElements.virtualMFADevice.serialNumber | Device ARN for later EnableMFADevice correlation; seed material is sensitive. |
eventTime, recipientAccountId, eventID, requestID | Timeline and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context, not a definitive attacker fingerprint. |
What to Investigate
- Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
- Match creation to an enrollment request and inspect the caller; do not infer ownership from the device name.
- Find a subsequent EnableMFADevice for the same serial number and identify the target user. Creation alone leaves enrollment incomplete.
- Inspect existing devices and DeactivateMFADevice activity, then correlate authentication evidence. Do not request or expose the seed.
Sample Event
Synthetic scenario. Draco creates draco-totp. No enablement or removal of another device is shown, so the sample does not establish enrollment or lockout.
Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-16T01:44:21Z", "eventSource": "iam.amazonaws.com", "eventName": "CreateVirtualMFADevice", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "virtualMFADeviceName": "draco-totp" }, "responseElements": { "virtualMFADevice": { "serialNumber": "arn:aws:iam::555123456789:mfa/draco-totp" } }, "requestID": "90000000-0000-4000-8000-000010100110", "eventID": "90000000-0000-4000-8000-000010100111", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098.005 — Device Registration — Adversaries may register a device to an adversary-controlled account. Devices may be registered in a multifactor authentication (MFA) system, which handles authentication to the network, or in a device management system, which handles device access and compliance.