Skip to content

DetachUserPolicy

AWS

DetachUserPolicy

service: AWS - IAM
techniques:

Event

Removes a managed-policy attachment from the named user. It does not delete the policy or an inline policy. Detaching an ordinary permissions policy is distinct from removing a permissions boundary.

Security Context

Removing allows can reduce access; removing explicit denies can expand access where valid grants remain. Approved policy cleanup or replacement is common. T1098 applies contextually to unauthorized permission manipulation, not to every detachment. Recover the active policy version and evaluate other controls before asserting escalation or loss of response capability.

The mapping describes a possible adversarial sequence, not a verdict on every occurrence.

Log Source

CloudTrail management event with eventSource: iam.amazonaws.com and eventName: DetachUserPolicy. Check collection scope and retention before interpreting absent records. IAM resources are global; account for global-service event collection rather than searching only the workload Region.

Key Fields

FieldInvestigation use
requestParameters.userNameTarget identity, distinct from the caller.
requestParameters.policyArnManaged policy; its name does not reveal statements or attachment type.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the caller and correlate with approved work.
recipientAccountId, awsRegionAccount and recording Region; distinguish caller, target, and resource scope.
errorCode, errorMessageCheck request failures and confirm resulting state; null response alone is not proof of success.

What to Investigate

  1. Confirm the change owner and inspect errors. Verify current attachments and any immediate replacement.
  2. Recover the policy version in effect at the event time; distinguish removed allows from denies.
  3. Evaluate the user’s remaining permissions, permissions boundary, Organizations restrictions, and applicable resource policies.
  4. Correlate with DeleteUserPolicy and subsequent activity to establish the actual access change.

Sample Event

Synthetic scenario. Draco detaches a fictional managed permissions policy from his user. Despite the policy’s name, this is not removal of a permissions boundary or proof that privileged operations became allowed. No top-level error is shown. Exact CloudTrail serialization and optional identity/session fields remain unverified by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T20:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:24:03Z",
"eventSource": "iam.amazonaws.com",
"eventName": "DetachUserPolicy",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"userName": "draco",
"policyArn": "arn:aws:iam::555123456789:policy/DenyDangerousActionsBoundary"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000100101110",
"eventID": "90000000-0000-4000-8000-000100101111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.