Skip to content

PasswordRecoveryRequested

AWS

PasswordRecoveryRequested

service: AWS - SignIn
tactics:
techniques:

Event

AWS documents PasswordRecoveryRequested as an event to investigate unexpected root password-reset emails. A request does not prove access to the email inbox, a completed password change, MFA bypass, or a successful root sign-in. Centralized root-access management can prevent recovery for member accounts without root credentials.

Security Context

An unexpected request may be account targeting or a mistaken request; legitimate recovery also generates it. No Valid Accounts technique is assigned because this event does not establish authenticated use. A Root identity label in the record is not evidence that the requester authenticated as root.

Log Source

AWS CloudTrail management event with eventSource: signin.amazonaws.com and eventName: PasswordRecoveryRequested. Verify collection across the relevant accounts and Regions. Inspect response and error fields; the event does not by itself prove downstream use. Sign-in event fields and Region placement can differ from ordinary API calls; do not rely on one assumed Region or identity wrapper. AWS confirms the event name in its root-password recovery guidance; the full example schema here still requires captured-log validation.

Key Fields

FieldInvestigation value
userIdentity, sourceIPAddressRecorded identity/client context, not proof of malicious intent.
eventName, eventSource, awsRegionOperation and collection context; distinguish requested target Region when applicable.
requestParameters, responseElementsRequest scope and outcome, where present.
eventID, eventTime, errorCode, errorMessageTiming, correlation, and errors; inspect related completion/sign-in records.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Verify the request with the account owner through an established channel and inspect relevant email notifications.
  3. Check centralized root-access configuration and correlate password changes, MFA changes, and successful or failed root ConsoleLogin events.
  4. Determine actual credential/email compromise before selecting containment; the source address alone is not actor attribution.

Sample Event

Synthetic scenario. The illustrative record reports a recovery request against the root account. Exact PasswordRecoveryRequested field serialization remains unverified against a captured AWS event.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"eventVersion": "1.08",
"userIdentity": {
"type": "Root",
"principalId": "555123456789",
"arn": "arn:aws:iam::555123456789:root",
"accountId": "555123456789",
"accessKeyId": ""
},
"eventTime": "2026-04-15T23:11:08Z",
"eventSource": "signin.amazonaws.com",
"eventName": "PasswordRecoveryRequested",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36",
"requestParameters": null,
"responseElements": {
"PasswordRecoveryRequested": "Success"
},
"additionalEventData": {
"MobileVersion": "No",
"MFAUsed": "No"
},
"eventID": "90000000-0000-4000-8000-000101011100",
"readOnly": false,
"eventType": "AwsConsoleSignIn",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "signin.aws.amazon.com"
}
}

Sources

Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.