PutRolePolicy
PutRolePolicy
Event
Adds or replaces a named inline permissions policy on an IAM role. Updating an existing policy name replaces its document. It does not create a managed policy or edit a permissions boundary. Role trust is separate and is changed through UpdateAssumeRolePolicy.
Security Context
An adversary could use this change to expand access for the target identity or maintain an unauthorized permission assignment. Normal provisioning and approved access changes use the same API. T1098 applies when account manipulation supports adversarial access; the event alone does not establish intent or continued authentication capability.
Effective access depends on the combined policy evaluation, including applicable boundaries, organization controls, session policies, and explicit denies. A broad Allow does not override these restrictions. Inspect the role trust policy and actual role sessions. This operation does not change who can assume the role or issue credentials.
Log Source
AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: PutRolePolicy. Include IAM global-service events in your collection. Check errorCode and errorMessage; a recorded attempt is not necessarily a completed change, and responseElements: null alone does not establish failure.
Key Fields
| Field | Investigation value |
|---|---|
userIdentity | Caller and session context; compare with the target and approved automation. |
requestParameters.roleName | Target IAM role, interpreted with the account identity. |
requestParameters.policyName | Name scoped to this target; compare the previous inline document. |
requestParameters.policyDocument | Submitted permissions; retain raw data and decode an encoded representation before comparing statements. |
eventTime, recipientAccountId, requestID, eventID | Timeline, account, and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context, not proof of identity or malicious intent. |
errorCode, errorMessage | Failed requests must be distinguished from successful changes. |
What to Investigate
- Confirm the outcome and match the caller, target, and timing to an approved change. Review failed attempts separately.
- Compare the submitted inline document with the prior document, including Allow, Deny, conditions, actions, and resources. An update can remove a restriction as well as add a grant.
- Inspect the role trust policy and actual role sessions. This operation does not change who can assume the role or issue credentials. Evaluate the resulting access with other applicable policies; confirm whether any sensitive permission actually became usable.
- Correlate other policy changes with subsequent API use by the affected identities. Separate persistence of the permission assignment from persistence of usable attacker credentials.
Sample Event
Synthetic suspicious scenario. Draco submits an inline wildcard Allow to OccamyPipelineRole. This merits review, but the sample does not establish approval status, prior permissions, or successful use of expanded access.
This is an illustrative CloudTrail-shaped record. Exact field presence and policy-document serialization have not been verified against a captured event.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:21:33Z", "eventSource": "iam.amazonaws.com", "eventName": "PutRolePolicy", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "roleName": "OccamyPipelineRole", "policyName": "draco-backdoor-policy", "policyDocument": "%7B%22Version%22%3A%222012-10-17%22%2C%22Statement%22%3A%5B%7B%22Effect%22%3A%22Allow%22%2C%22Action%22%3A%22%2A%22%2C%22Resource%22%3A%22%2A%22%7D%5D%7D" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000110010010", "eventID": "90000000-0000-4000-8000-000110010011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...