Skip to content

DetachRolePolicy

AWS

DetachRolePolicy

service: AWS - IAM
techniques:

Event

Removes a managed-policy attachment from the named role. It does not delete the policy or an inline policy. Detaching an ordinary permissions policy is distinct from removing a permissions boundary.

Security Context

Removing allows can reduce access; removing explicit denies can expand access where valid grants remain. Approved policy cleanup or replacement is common. T1098 applies contextually to unauthorized permission manipulation, not to every detachment. Recover the active policy version and evaluate other controls before asserting escalation or loss of response capability.

The mapping describes a possible adversarial sequence, not a verdict on every occurrence.

Log Source

CloudTrail management event with eventSource: iam.amazonaws.com and eventName: DetachRolePolicy. Check collection scope and retention before interpreting absent records. IAM resources are global; account for global-service event collection rather than searching only the workload Region.

Key Fields

FieldInvestigation use
requestParameters.roleNameTarget identity, distinct from the caller.
requestParameters.policyArnManaged policy; its name does not reveal statements or attachment type.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the caller and correlate with approved work.
recipientAccountId, awsRegionAccount and recording Region; distinguish caller, target, and resource scope.
errorCode, errorMessageCheck request failures and confirm resulting state; null response alone is not proof of success.

What to Investigate

  1. Confirm the change owner and inspect errors. Verify current attachments and any immediate replacement.
  2. Recover the policy version in effect at the event time; distinguish removed allows from denies.
  3. Evaluate the role’s remaining permissions, permissions boundary, Organizations restrictions, and applicable resource policies.
  4. Correlate with DeleteRolePolicy and subsequent activity to establish the actual access change.

Sample Event

Synthetic scenario. Draco detaches a policy from IncidentResponseRole. The name does not prove the role operated a particular security automation or that detachment disabled it. No top-level error is shown. Exact CloudTrail serialization and optional identity/session fields remain unverified by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T20:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:18:46Z",
"eventSource": "iam.amazonaws.com",
"eventName": "DetachRolePolicy",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"roleName": "IncidentResponseRole",
"policyArn": "arn:aws:iam::555123456789:policy/IncidentResponseEnforcementPolicy"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000100101100",
"eventID": "90000000-0000-4000-8000-000100101101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.