DeleteRolePolicy
DeleteRolePolicy
Event
Deletes an inline policy embedded in the named role. It does not delete the role, detach a managed policy, or modify the role’s trust policy. The request contains the policy name, not its statements.
Security Context
An attacker may remove an explicit deny to expand permissions when valid allows remain, which can support account manipulation (T1098). Removing allows can instead reduce access. Approved policy replacement or cleanup is common. Assess permissions boundaries, session policies, Organizations controls, resource policies, and remaining denies before asserting escalation.
The mapping describes a possible adversarial use, not a verdict on every occurrence.
Log Source
CloudTrail management event with eventSource: iam.amazonaws.com and eventName: DeleteRolePolicy. Review IAM global-service event collection and retention, rather than searching only the workload’s Region. This audit record describes the request, not every downstream access outcome.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.roleName | Target role; distinguish it from the caller. |
requestParameters.policyName | Inline policy name, not evidence of its actual effect. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute and correlate the caller’s activity. |
recipientAccountId, awsRegion | Account and recording Region; IAM resources are not regional. |
errorCode, errorMessage | Check failures; a null response alone does not prove success. |
What to Investigate
- Confirm authorization and inspect errors; verify the inline policy’s absence and any replacement.
- Recover the policy document from retained configuration or infrastructure code, separating removed allows from denies.
- Evaluate the target role’s remaining effective permissions and who can assume it. A policy deletion does not change the trust relationship.
- Correlate with AssumeRole and later role-session activity to determine whether expanded access was actually used.
Sample Event
Synthetic scenario. Draco requests deletion of DenyDestructiveOps from OccamyPipelineRole. Its deny contents and the existence of other allowing policies are scenario assumptions, not facts encoded in the name. No error fields are shown. Exact CloudTrail serialization and optional identity/session fields have not been validated by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:36:33Z", "eventSource": "iam.amazonaws.com", "eventName": "DeleteRolePolicy", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "roleName": "OccamyPipelineRole", "policyName": "DenyDestructiveOps" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000011111000", "eventID": "90000000-0000-4000-8000-000011111001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...