Skip to content

ModifyInstanceAttribute

AWS

ModifyInstanceAttribute

service: AWS - EC2
techniques:

Event

Changes an EC2 instance attribute. Interpret the supplied attribute rather than treating every call as execution. Different attributes have different prerequisites; updating user data requires a stopped instance.

Security Context

Unauthorized compute changes may impair defenses (T1578). User-data changes can support script execution (T1059), but execution requires separate evidence. On Linux, user-data scripts normally run at initial launch, not every restart; guest configuration controls subsequent execution. Approved sizing, networking, and bootstrap maintenance are common.

Log Source

CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: ModifyInstanceAttribute. Search regional Event history or retained management-event logs, accounting for collection scope and retention. For APIs supporting dry runs, DryRunOperation reports sufficient permissions without making the change.

Key Fields

FieldInvestigation use
requestParameters.instanceIdAffected instance.
requestParameters.userData, requestParameters.groupSetExamples of changed attributes; inspect the actual request.
requestParameters.userData.valueMay be hidden; a placeholder is not evidence of payload contents.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the request and compare with approved work.
awsRegion, recipientAccountIdScope the account and regional context.
errorCode, errorMessageDistinguish rejection from an apparent completed request; verify actual state.

What to Investigate

  1. Confirm approval and inspect errors or dry-run status. Identify the actual attribute and compare prior/current state.
  2. For user data, verify the instance was stopped and obtain approved configuration evidence without treating redacted content as a known script.
  3. Check launch-agent or cloud-init configuration and host logs to establish whether changed data was executed.
  4. Correlate lifecycle and network changes, including AuthorizeSecurityGroupIngress, before drawing conclusions about persistence or access.

Sample Event

Synthetic scenario. Draco requests a user-data update on a fictional instance. The displayed value is a redaction placeholder. No SSH-key payload, reverse shell, or automatic execution on restart can be inferred from it. No top-level error is shown. Exact CloudTrail serialization and optional fields remain unverified by capture. The inherited request/response nesting is illustrative; API transport examples alone do not validate CloudTrail field encoding.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T21:42:08Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T22:48:51Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "ModifyInstanceAttribute",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"instanceId": "i-0123456789abcdef0",
"userData": {
"value": "<sensitiveDataRemoved>"
}
},
"responseElements": {
"requestId": "90000000-0000-4000-8000-000101010110",
"_return": true
},
"requestID": "90000000-0000-4000-8000-000101010110",
"eventID": "90000000-0000-4000-8000-000101010111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment Execution

Techniques:
  • T1578 — Modify Cloud Compute Infrastructure — An adversary may attempt to modify a cloud account's compute service infrastructure to evade defenses. A modification to the compute service infrastructure can include the creation, deletion, or modification of one or more components such as compute instances, virtual machines, and snapshots.
  • T1059 — Command and Scripting Interpreter — Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface a...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.