Skip to content

PassRole

AWS

PassRole

service: AWS - IAM
techniques:

Event

iam:PassRole is an authorization check, not a callable API or standalone CloudTrail event. Investigate the service API that accepts the role, such as RunInstances with an instance profile. Passing a role requires appropriate service-operation permissions and compatible role trust; PassRole alone neither assumes the role nor returns credentials. The passed role must be in the same account as the service receiving it.

Security Context

Abuse can enable privilege escalation when a caller can configure a service to use a more powerful role and control useful work performed by that service. Normal deployment uses the same permission. T1548 is contextual to this escalation path; the event does not establish a universal MFA bypass or direct use of the role by the caller.

Log Source

There is no PassRole CloudTrail event. Use the underlying service management event; this sample shows RunInstances from ec2.amazonaws.com. Check errorCode and errorMessage before treating an attempt as successful; responseElements: null alone does not indicate failure.

Key Fields

FieldInvestigation value
eventName, eventSourceUnderlying service operation; the sample is ec2.amazonaws.com RunInstances.
requestParameters.iamInstanceProfileRequested profile; resolve the contained IAM role for the PassRole check.
responseElements.instancesSetCreated instance identifiers and launch state, not evidence of role credential use.
eventTime, recipientAccountId, eventID, requestIDTimeline, account, and correlation identifiers.

What to Investigate

  1. Confirm the outcome and match the caller, target, and timing to an approved workflow. Review failed attempts separately.
  2. Identify the service operation, role/profile, and caller. Check the caller’s service permissions and iam:PassRole scope, including iam:PassedToService conditions.
  3. Review role trust and effective permissions, and whether the caller could control the workload or access its credentials.
  4. Correlate instance or service execution and downstream role-session actions. Compare profile association changes and approved deployment records.

Sample Event

Synthetic scenario. Draco launches an instance with GraphornAdminInstanceProfile. The response shows a pending instance, not SSH access, metadata retrieval, or demonstrated administrator permissions.

Exact CloudTrail nesting, field presence, redaction, and timestamp formatting remain unverified against captured logs. Credential/token placeholders and metadata placeholders are illustrative, not usable credentials or complete provider metadata.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T21:42:08Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T23:03:11Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "RunInstances",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"instancesSet": {
"items": [
{
"imageId": "ami-0123456789abcdef0",
"minCount": 1,
"maxCount": 1
}
]
},
"instanceType": "t3.medium",
"iamInstanceProfile": {
"arn": "arn:aws:iam::555123456789:instance-profile/GraphornAdminInstanceProfile",
"name": "GraphornAdminInstanceProfile"
}
},
"responseElements": {
"requestId": "90000000-0000-4000-8000-000101011010",
"instancesSet": {
"items": [
{
"instanceId": "i-0fedcba9876543210",
"imageId": "ami-0123456789abcdef0",
"instanceState": {
"code": 0,
"name": "pending"
},
"instanceType": "t3.medium",
"iamInstanceProfile": {
"arn": "arn:aws:iam::555123456789:instance-profile/GraphornAdminInstanceProfile",
"id": "AIPAGRAPH0RNINSTPR0F"
}
}
]
}
},
"requestID": "90000000-0000-4000-8000-000101011010",
"eventID": "90000000-0000-4000-8000-000101011011",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation

Techniques:
  • T1548 — Abuse Elevation Control Mechanism — Adversaries may circumvent mechanisms designed to control privilege elevation to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user can perform on a machine. Authorization has to be granted to specific u...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.