Skip to content

DeleteRolePolicy

AWS

DeleteRolePolicy

service: AWS - IAM
techniques:

Event

Deletes an inline policy embedded in the named role. It does not delete the role, detach a managed policy, or modify the role’s trust policy. The request contains the policy name, not its statements.

Security Context

An attacker may remove an explicit deny to expand permissions when valid allows remain, which can support account manipulation (T1098). Removing allows can instead reduce access. Approved policy replacement or cleanup is common. Assess permissions boundaries, session policies, Organizations controls, resource policies, and remaining denies before asserting escalation.

The mapping describes a possible adversarial use, not a verdict on every occurrence.

Log Source

CloudTrail management event with eventSource: iam.amazonaws.com and eventName: DeleteRolePolicy. Review IAM global-service event collection and retention, rather than searching only the workload’s Region. This audit record describes the request, not every downstream access outcome.

Key Fields

FieldInvestigation use
requestParameters.roleNameTarget role; distinguish it from the caller.
requestParameters.policyNameInline policy name, not evidence of its actual effect.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute and correlate the caller’s activity.
recipientAccountId, awsRegionAccount and recording Region; IAM resources are not regional.
errorCode, errorMessageCheck failures; a null response alone does not prove success.

What to Investigate

  1. Confirm authorization and inspect errors; verify the inline policy’s absence and any replacement.
  2. Recover the policy document from retained configuration or infrastructure code, separating removed allows from denies.
  3. Evaluate the target role’s remaining effective permissions and who can assume it. A policy deletion does not change the trust relationship.
  4. Correlate with AssumeRole and later role-session activity to determine whether expanded access was actually used.

Sample Event

Synthetic scenario. Draco requests deletion of DenyDestructiveOps from OccamyPipelineRole. Its deny contents and the existence of other allowing policies are scenario assumptions, not facts encoded in the name. No error fields are shown. Exact CloudTrail serialization and optional identity/session fields have not been validated by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:36:33Z",
"eventSource": "iam.amazonaws.com",
"eventName": "DeleteRolePolicy",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"roleName": "OccamyPipelineRole",
"policyName": "DenyDestructiveOps"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000011111000",
"eventID": "90000000-0000-4000-8000-000011111001",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.