ModifyInstanceAttribute
ModifyInstanceAttribute
Event
Changes an EC2 instance attribute. Interpret the supplied attribute rather than treating every call as execution. Different attributes have different prerequisites; updating user data requires a stopped instance.
Security Context
Unauthorized compute changes may impair defenses (T1578). User-data changes can support script execution (T1059), but execution requires separate evidence. On Linux, user-data scripts normally run at initial launch, not every restart; guest configuration controls subsequent execution. Approved sizing, networking, and bootstrap maintenance are common.
Log Source
CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: ModifyInstanceAttribute. Search regional Event history or retained management-event logs, accounting for collection scope and retention. For APIs supporting dry runs, DryRunOperation reports sufficient permissions without making the change.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.instanceId | Affected instance. |
requestParameters.userData, requestParameters.groupSet | Examples of changed attributes; inspect the actual request. |
requestParameters.userData.value | May be hidden; a placeholder is not evidence of payload contents. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the request and compare with approved work. |
awsRegion, recipientAccountId | Scope the account and regional context. |
errorCode, errorMessage | Distinguish rejection from an apparent completed request; verify actual state. |
What to Investigate
- Confirm approval and inspect errors or dry-run status. Identify the actual attribute and compare prior/current state.
- For user data, verify the instance was stopped and obtain approved configuration evidence without treating redacted content as a known script.
- Check launch-agent or cloud-init configuration and host logs to establish whether changed data was executed.
- Correlate lifecycle and network changes, including AuthorizeSecurityGroupIngress, before drawing conclusions about persistence or access.
Sample Event
Synthetic scenario. Draco requests a user-data update on a fictional instance. The displayed value is a redaction placeholder. No SSH-key payload, reverse shell, or automatic execution on restart can be inferred from it. No top-level error is shown. Exact CloudTrail serialization and optional fields remain unverified by capture. The inherited request/response nesting is illustrative; API transport examples alone do not validate CloudTrail field encoding.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T21:42:08Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T22:48:51Z", "eventSource": "ec2.amazonaws.com", "eventName": "ModifyInstanceAttribute", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "instanceId": "i-0123456789abcdef0", "userData": { "value": "<sensitiveDataRemoved>" } }, "responseElements": { "requestId": "90000000-0000-4000-8000-000101010110", "_return": true }, "requestID": "90000000-0000-4000-8000-000101010110", "eventID": "90000000-0000-4000-8000-000101010111", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment Execution
- T1578 — Modify Cloud Compute Infrastructure — An adversary may attempt to modify a cloud account's compute service infrastructure to evade defenses. A modification to the compute service infrastructure can include the creation, deletion, or modification of one or more components such as compute instances, virtual machines, and snapshots.
- T1059 — Command and Scripting Interpreter — Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface a...