PasswordRecoveryRequested
PasswordRecoveryRequested
Event
AWS documents PasswordRecoveryRequested as an event to investigate unexpected root password-reset emails. A request does not prove access to the email inbox, a completed password change, MFA bypass, or a successful root sign-in. Centralized root-access management can prevent recovery for member accounts without root credentials.
Security Context
An unexpected request may be account targeting or a mistaken request; legitimate recovery also generates it. No Valid Accounts technique is assigned because this event does not establish authenticated use. A Root identity label in the record is not evidence that the requester authenticated as root.
Log Source
AWS CloudTrail management event with eventSource: signin.amazonaws.com and eventName: PasswordRecoveryRequested. Verify collection across the relevant accounts and Regions. Inspect response and error fields; the event does not by itself prove downstream use. Sign-in event fields and Region placement can differ from ordinary API calls; do not rely on one assumed Region or identity wrapper. AWS confirms the event name in its root-password recovery guidance; the full example schema here still requires captured-log validation.
Key Fields
| Field | Investigation value |
|---|---|
userIdentity, sourceIPAddress | Recorded identity/client context, not proof of malicious intent. |
eventName, eventSource, awsRegion | Operation and collection context; distinguish requested target Region when applicable. |
requestParameters, responseElements | Request scope and outcome, where present. |
eventID, eventTime, errorCode, errorMessage | Timing, correlation, and errors; inspect related completion/sign-in records. |
What to Investigate
- Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
- Verify the request with the account owner through an established channel and inspect relevant email notifications.
- Check centralized root-access configuration and correlate password changes, MFA changes, and successful or failed root ConsoleLogin events.
- Determine actual credential/email compromise before selecting containment; the source address alone is not actor attribution.
Sample Event
Synthetic scenario. The illustrative record reports a recovery request against the root account. Exact PasswordRecoveryRequested field serialization remains unverified against a captured AWS event.
Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.
{ "eventVersion": "1.08", "userIdentity": { "type": "Root", "principalId": "555123456789", "arn": "arn:aws:iam::555123456789:root", "accountId": "555123456789", "accessKeyId": "" }, "eventTime": "2026-04-15T23:11:08Z", "eventSource": "signin.amazonaws.com", "eventName": "PasswordRecoveryRequested", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36", "requestParameters": null, "responseElements": { "PasswordRecoveryRequested": "Success" }, "additionalEventData": { "MobileVersion": "No", "MFAUsed": "No" }, "eventID": "90000000-0000-4000-8000-000101011100", "readOnly": false, "eventType": "AwsConsoleSignIn", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "signin.aws.amazon.com" }}