PutTargets
PutTargets
Event
Associates target IDs with a rule and optional input transformations, retry settings, or dead-letter handling. The operation can partially fail even with an HTTP-success response; inspect failedEntryCount and failedEntries. Configuration propagation and successful event delivery are separate.
Security Context
Unauthorized targets can support event-triggered persistence (T1546). Cross-account Lambda targets are supported in the same Region and require an execution role in the event-bus account plus a permitting resource policy on the target. Target association alone does not prove invocation or payload behavior.
Log Source
CloudTrail management event with eventSource: events.amazonaws.com and eventName: PutTargets. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.
Key Fields
Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.
| Field | Investigation value |
|---|---|
rule, eventBusName, targets | Rule and each target ID/ARN, role, input configuration, retries, and dead-letter destination. |
userIdentity, eventTime, awsRegion, eventID (top level) | Caller/session, timeline, Region, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Compare every submitted target with the prior configuration and intended rule purpose.
- Verify the enabled rule, matching events, execution-role trust/permissions, and target resource policy.
- Check per-entry errors, delivery metrics, retries/dead-letter records, and actual target execution.
Sample Event
Synthetic scenario. The request associates a same-Region cross-account Lambda target and an illustrative execution role. Zero failed entries does not prove the separately required target policy exists or any event was delivered.
Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:28:42Z", "eventSource": "events.amazonaws.com", "eventName": "PutTargets", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "rule": "phoenix-restore-watch", "eventBusName": "default", "targets": [ { "id": "1", "arn": "arn:aws:lambda:us-east-1:555666661337:function:phoenix-credential-issuer", "roleArn": "arn:aws:iam::555123456789:role/EventBridgeCrossAccountInvokeRole" } ] }, "responseElements": { "failedEntryCount": 0, "failedEntries": [] }, "requestID": "90000000-0000-4000-8000-000110010110", "eventID": "90000000-0000-4000-8000-000110010111", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "events.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence
- T1546 — Event Triggered Execution — Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. Various operating systems have means to monitor and subscribe to events such as logons or other user activity such as running specific applications/binaries. Cl...