Skip to content

DeleteLoginProfile

AWS

DeleteLoginProfile

service: AWS - IAM
tactics:
techniques:

Event

Deletes the target’s login password. For an IAM user, this removes password-based console sign-in; it does not delete the user or their access keys. The API also supports root-password removal through the documented AssumeRoot workflow.

Security Context

Unauthorized password removal can deny a legitimate user access and fits T1531. Approved offboarding, migration to federation, or centralized root-credential management can also explain the operation. Do not treat this as proof of complete lockout or termination of every existing session.

The mapping describes a possible adversarial use, not a verdict on every occurrence.

Log Source

CloudTrail management event with eventSource: iam.amazonaws.com and eventName: DeleteLoginProfile. Review IAM global-service event collection and retention, rather than searching only the workload’s Region. This audit record describes the request, not every downstream access outcome.

Key Fields

FieldInvestigation use
requestParameters.userNameTarget user when supplied; omitted-name cases require caller and AssumeRoot context.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute and correlate the caller’s activity.
recipientAccountId, awsRegionAccount and recording Region; IAM resources are not regional.
errorCode, errorMessageCheck failures; a null response alone does not prove success.

What to Investigate

  1. Confirm authorization and identify the actual target rather than assuming the caller is the affected user.
  2. Inspect request errors and verify login-profile state through GetLoginProfile.
  3. Assess remaining access keys, federation paths, and active sessions separately; password deletion is not a complete access-revocation procedure.
  4. Correlate with ConsoleLogin and other credential changes, then verify the approved recovery or offboarding outcome.

Sample Event

Synthetic scenario. Draco requests removal of Hermione’s console password. The request does not establish her administrative role, prove all her access stopped, or show that Draco’s access persisted. No error fields are shown. Exact CloudTrail serialization and optional identity/session fields have not been validated by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:55:48Z",
"eventSource": "iam.amazonaws.com",
"eventName": "DeleteLoginProfile",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"userName": "hermione"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000011101000",
"eventID": "90000000-0000-4000-8000-000011101001",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1531 — Account Access Removal — Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts....
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.