Skip to content

PutGroupPolicy

AWS

PutGroupPolicy

service: AWS - IAM
techniques:

Event

Adds or replaces a named inline permissions policy on an IAM group. Updating an existing policy name replaces its document. It does not create a managed policy or edit a permissions boundary.

Security Context

An adversary could use this change to expand access for group members or maintain an unauthorized permission assignment. Normal provisioning and approved access changes use the same API. T1098 applies when account manipulation supports adversarial access; the event alone does not establish intent or continued authentication capability.

Effective access depends on the combined policy evaluation, including applicable boundaries, organization controls, session policies, and explicit denies. A broad Allow does not override these restrictions. Check historical group membership; the caller is not necessarily a member, and affected users can have different effective permissions.

Log Source

AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: PutGroupPolicy. Include IAM global-service events in your collection. Check errorCode and errorMessage; a recorded attempt is not necessarily a completed change, and responseElements: null alone does not establish failure.

Key Fields

FieldInvestigation value
userIdentityCaller and session context; compare with the target and approved automation.
requestParameters.groupNameTarget IAM group, interpreted with the account identity.
requestParameters.policyNameName scoped to this target; compare the previous inline document.
requestParameters.policyDocumentSubmitted permissions; retain raw data and decode an encoded representation before comparing statements.
eventTime, recipientAccountId, requestID, eventIDTimeline, account, and correlation identifiers.
sourceIPAddress, userAgentSupporting context, not proof of identity or malicious intent.
errorCode, errorMessageFailed requests must be distinguished from successful changes.

What to Investigate

  1. Confirm the outcome and match the caller, target, and timing to an approved change. Review failed attempts separately.
  2. Compare the submitted inline document with the prior document, including Allow, Deny, conditions, actions, and resources. An update can remove a restriction as well as add a grant.
  3. Check historical group membership; the caller is not necessarily a member, and affected users can have different effective permissions. Evaluate the resulting access with other applicable policies; confirm whether any sensitive permission actually became usable.
  4. Correlate other policy changes with subsequent API use by the affected identities. Separate persistence of the permission assignment from persistence of usable attacker credentials.

Sample Event

Synthetic suspicious scenario. Draco submits an inline wildcard Allow to Developers. This merits review, but the sample does not establish approval status, prior permissions, or successful use of expanded access.

This is an illustrative CloudTrail-shaped record. Exact field presence and policy-document serialization have not been verified against a captured event.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T21:42:08Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T23:55:34Z",
"eventSource": "iam.amazonaws.com",
"eventName": "PutGroupPolicy",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"groupName": "Developers",
"policyName": "developer-helper-policy",
"policyDocument": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Action\":\"*\",\"Resource\":\"*\"}]}"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000101101100",
"eventID": "90000000-0000-4000-8000-000101101101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.