Skip to content

ModifyImageAttribute

AWS

ModifyImageAttribute

service: AWS - EC2
techniques:

Event

Changes an AMI attribute. Launch-permission additions can share an image with accounts, organizations, or OUs, or make eligible images public; other attribute changes may not share data at all.

Security Context

Unauthorized AMI sharing can support transfer to another cloud account (T1537). Approved image distribution is common. Sharing is regional and does not prove a recipient launched or copied the image. Encrypted backing snapshots require suitable KMS access; AMIs using the default AWS managed encryption key cannot be shared. The request does not reveal image contents.

The mapping describes a possible adversarial sequence, not a verdict on every occurrence.

Log Source

CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: ModifyImageAttribute. Check collection scope and retention before interpreting absent records.

Key Fields

FieldInvestigation use
requestParameters.imageIdRegional AMI.
requestParameters.launchPermissionInspect additions versus removals and account, organization, OU, or public-group recipients.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the caller and correlate with approved work.
recipientAccountId, awsRegionAccount and recording Region; distinguish caller, target, and resource scope.
errorCode, errorMessageCheck request failures and confirm resulting state; null response alone is not proof of success.

What to Investigate

  1. Confirm approval and inspect errors or DryRunOperation before treating the request as a change.
  2. Compare DescribeImageAttribute launch permissions with the prior state and identify the actual recipient ownership.
  3. Review backing snapshot encryption and required KMS access; do not assume sharing alone permits every launch or copy.
  4. Correlate recipient launch/copy evidence where available with ModifyInstanceAttribute. Review image contents separately before claiming sensitive-data exposure.

Sample Event

Synthetic scenario. Draco adds fictional account 555666661337 to a fictional AMI’s launch permissions. Adversarial ownership, embedded secrets, usable encryption keys, and subsequent launch are assumptions requiring separate evidence. No top-level error is shown. Exact CloudTrail serialization and optional identity/session fields remain unverified by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T21:42:08Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T22:41:09Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "ModifyImageAttribute",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"imageId": "ami-0123456789abcdef0",
"launchPermission": {
"add": {
"items": [
{
"userId": "555666661337"
}
]
}
}
},
"responseElements": {
"requestId": "90000000-0000-4000-8000-000101010100",
"_return": true
},
"requestID": "90000000-0000-4000-8000-000101010100",
"eventID": "90000000-0000-4000-8000-000101010101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Exfiltration

Techniques:
  • T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.