Skip to content

Invoke

AWS

Invoke

service: AWS - Lambda
tactics:
techniques:

Event

RequestResponse waits for a synchronous result; Event queues an asynchronous invocation; DryRun checks parameters and authorization without running the function. API acceptance does not establish function success. Asynchronous processing can retry and produce duplicate execution.

Security Context

Unauthorized use of an existing function can support serverless execution (T1648). The function’s deployed code determines how input is handled; an invocation payload does not inherently provide arbitrary code execution.

Log Source

CloudTrail data event with eventSource: lambda.amazonaws.com and eventName: Invoke. Lambda data-event collection must be configured for the relevant resources in a trail or event data store; these events are not included in Event history or default management-event collection. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.

Key Fields

Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.

FieldInvestigation value
functionName, qualifierFunction and requested version or alias.
invocationTypeDistinguish synchronous, queued, and dry-run requests.
userIdentity, eventTime, awsRegion, eventID (top level)Caller/session, timeline, Region, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Resolve the version actually invoked and the caller’s intended workflow.
  3. Inspect invocation errors and function logs/metrics; null responseElements does not prove success or failure.
  4. Correlate runtime behavior and any asynchronous retries before counting executions or claiming data access.

Sample Event

Synthetic scenario. A synchronous request selects $LATEST. No function output or runtime success is shown.

Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T21:42:08Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T22:09:48Z",
"eventSource": "lambda.amazonaws.com",
"eventName": "Invoke",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"functionName": "arn:aws:lambda:us-east-1:555123456789:function:phoenix-restore-handler",
"invocationType": "RequestResponse",
"qualifier": "$LATEST"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000101001100",
"eventID": "90000000-0000-4000-8000-000101001101",
"readOnly": false,
"resources": [
{
"accountId": "555123456789",
"type": "AWS::Lambda::Function",
"ARN": "arn:aws:lambda:us-east-1:555123456789:function:phoenix-restore-handler"
}
],
"eventType": "AwsApiCall",
"managementEvent": false,
"recipientAccountId": "555123456789",
"eventCategory": "Data",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "lambda.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Execution

Techniques:
  • T1648 — Serverless Execution — Adversaries may abuse serverless computing, integration, and automation services to execute arbitrary code in cloud environments. Many cloud providers offer a variety of serverless resources, including compute engines, application integration services, and web servers.
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.