DetachRolePolicy
DetachRolePolicy
Event
Removes a managed-policy attachment from the named role. It does not delete the policy or an inline policy. Detaching an ordinary permissions policy is distinct from removing a permissions boundary.
Security Context
Removing allows can reduce access; removing explicit denies can expand access where valid grants remain. Approved policy cleanup or replacement is common. T1098 applies contextually to unauthorized permission manipulation, not to every detachment. Recover the active policy version and evaluate other controls before asserting escalation or loss of response capability.
The mapping describes a possible adversarial sequence, not a verdict on every occurrence.
Log Source
CloudTrail management event with eventSource: iam.amazonaws.com and eventName: DetachRolePolicy. Check collection scope and retention before interpreting absent records. IAM resources are global; account for global-service event collection rather than searching only the workload Region.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.roleName | Target identity, distinct from the caller. |
requestParameters.policyArn | Managed policy; its name does not reveal statements or attachment type. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the caller and correlate with approved work. |
recipientAccountId, awsRegion | Account and recording Region; distinguish caller, target, and resource scope. |
errorCode, errorMessage | Check request failures and confirm resulting state; null response alone is not proof of success. |
What to Investigate
- Confirm the change owner and inspect errors. Verify current attachments and any immediate replacement.
- Recover the policy version in effect at the event time; distinguish removed allows from denies.
- Evaluate the role’s remaining permissions, permissions boundary, Organizations restrictions, and applicable resource policies.
- Correlate with DeleteRolePolicy and subsequent activity to establish the actual access change.
Sample Event
Synthetic scenario. Draco detaches a policy from IncidentResponseRole. The name does not prove the role operated a particular security automation or that detachment disabled it. No top-level error is shown. Exact CloudTrail serialization and optional identity/session fields remain unverified by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T20:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:18:46Z", "eventSource": "iam.amazonaws.com", "eventName": "DetachRolePolicy", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "roleName": "IncidentResponseRole", "policyArn": "arn:aws:iam::555123456789:policy/IncidentResponseEnforcementPolicy" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000100101100", "eventID": "90000000-0000-4000-8000-000100101101", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...