ModifyImageAttribute
ModifyImageAttribute
Event
Changes an AMI attribute. Launch-permission additions can share an image with accounts, organizations, or OUs, or make eligible images public; other attribute changes may not share data at all.
Security Context
Unauthorized AMI sharing can support transfer to another cloud account (T1537). Approved image distribution is common. Sharing is regional and does not prove a recipient launched or copied the image. Encrypted backing snapshots require suitable KMS access; AMIs using the default AWS managed encryption key cannot be shared. The request does not reveal image contents.
The mapping describes a possible adversarial sequence, not a verdict on every occurrence.
Log Source
CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: ModifyImageAttribute. Check collection scope and retention before interpreting absent records.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.imageId | Regional AMI. |
requestParameters.launchPermission | Inspect additions versus removals and account, organization, OU, or public-group recipients. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the caller and correlate with approved work. |
recipientAccountId, awsRegion | Account and recording Region; distinguish caller, target, and resource scope. |
errorCode, errorMessage | Check request failures and confirm resulting state; null response alone is not proof of success. |
What to Investigate
- Confirm approval and inspect errors or DryRunOperation before treating the request as a change.
- Compare DescribeImageAttribute launch permissions with the prior state and identify the actual recipient ownership.
- Review backing snapshot encryption and required KMS access; do not assume sharing alone permits every launch or copy.
- Correlate recipient launch/copy evidence where available with ModifyInstanceAttribute. Review image contents separately before claiming sensitive-data exposure.
Sample Event
Synthetic scenario. Draco adds fictional account 555666661337 to a fictional AMI’s launch permissions. Adversarial ownership, embedded secrets, usable encryption keys, and subsequent launch are assumptions requiring separate evidence. No top-level error is shown. Exact CloudTrail serialization and optional identity/session fields remain unverified by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T21:42:08Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T22:41:09Z", "eventSource": "ec2.amazonaws.com", "eventName": "ModifyImageAttribute", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "imageId": "ami-0123456789abcdef0", "launchPermission": { "add": { "items": [ { "userId": "555666661337" } ] } } }, "responseElements": { "requestId": "90000000-0000-4000-8000-000101010100", "_return": true }, "requestID": "90000000-0000-4000-8000-000101010100", "eventID": "90000000-0000-4000-8000-000101010101", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Exfiltration
- T1537 — Transfer Data to Cloud Account — Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.