PassRole
PassRole
Event
iam:PassRole is an authorization check, not a callable API or standalone CloudTrail event. Investigate the service API that accepts the role, such as RunInstances with an instance profile. Passing a role requires appropriate service-operation permissions and compatible role trust; PassRole alone neither assumes the role nor returns credentials. The passed role must be in the same account as the service receiving it.
Security Context
Abuse can enable privilege escalation when a caller can configure a service to use a more powerful role and control useful work performed by that service. Normal deployment uses the same permission. T1548 is contextual to this escalation path; the event does not establish a universal MFA bypass or direct use of the role by the caller.
Log Source
There is no PassRole CloudTrail event. Use the underlying service management event; this sample shows RunInstances from ec2.amazonaws.com. Check errorCode and errorMessage before treating an attempt as successful; responseElements: null alone does not indicate failure.
Key Fields
| Field | Investigation value |
|---|---|
eventName, eventSource | Underlying service operation; the sample is ec2.amazonaws.com RunInstances. |
requestParameters.iamInstanceProfile | Requested profile; resolve the contained IAM role for the PassRole check. |
responseElements.instancesSet | Created instance identifiers and launch state, not evidence of role credential use. |
eventTime, recipientAccountId, eventID, requestID | Timeline, account, and correlation identifiers. |
What to Investigate
- Confirm the outcome and match the caller, target, and timing to an approved workflow. Review failed attempts separately.
- Identify the service operation, role/profile, and caller. Check the caller’s service permissions and iam:PassRole scope, including iam:PassedToService conditions.
- Review role trust and effective permissions, and whether the caller could control the workload or access its credentials.
- Correlate instance or service execution and downstream role-session actions. Compare profile association changes and approved deployment records.
Sample Event
Synthetic scenario. Draco launches an instance with GraphornAdminInstanceProfile. The response shows a pending instance, not SSH access, metadata retrieval, or demonstrated administrator permissions.
Exact CloudTrail nesting, field presence, redaction, and timestamp formatting remain unverified against captured logs. Credential/token placeholders and metadata placeholders are illustrative, not usable credentials or complete provider metadata.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T21:42:08Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T23:03:11Z", "eventSource": "ec2.amazonaws.com", "eventName": "RunInstances", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "instancesSet": { "items": [ { "imageId": "ami-0123456789abcdef0", "minCount": 1, "maxCount": 1 } ] }, "instanceType": "t3.medium", "iamInstanceProfile": { "arn": "arn:aws:iam::555123456789:instance-profile/GraphornAdminInstanceProfile", "name": "GraphornAdminInstanceProfile" } }, "responseElements": { "requestId": "90000000-0000-4000-8000-000101011010", "instancesSet": { "items": [ { "instanceId": "i-0fedcba9876543210", "imageId": "ami-0123456789abcdef0", "instanceState": { "code": 0, "name": "pending" }, "instanceType": "t3.medium", "iamInstanceProfile": { "arn": "arn:aws:iam::555123456789:instance-profile/GraphornAdminInstanceProfile", "id": "AIPAGRAPH0RNINSTPR0F" } } ] } }, "requestID": "90000000-0000-4000-8000-000101011010", "eventID": "90000000-0000-4000-8000-000101011011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Privilege Escalation
- T1548 — Abuse Elevation Control Mechanism — Adversaries may circumvent mechanisms designed to control privilege elevation to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user can perform on a machine. Authorization has to be granted to specific u...