Skip to content

ReplaceIamInstanceProfileAssociation

AWS

ReplaceIamInstanceProfileAssociation

service: AWS - EC2
techniques:

Event

Replaces the profile on a running instance without first disassociating the old profile. The request identifies the existing association, which must be resolved to an instance. The profile contains a role, which is distinct from the profile itself. iam:PassRole authorization applies to that role, not the profile ARN.

Security Context

An attacker with workload access could exploit an unauthorized assignment to use the role’s credentials. Approved application changes also use this API. Effective permissions, EC2 trust, metadata access, and actual credential use must be established; a profile name does not prove administrator access. T1098 is contextual to unauthorized permission changes.

Log Source

AWS CloudTrail management event with eventSource: ec2.amazonaws.com and eventName: ReplaceIamInstanceProfileAssociation. Check errorCode and errorMessage before treating an attempt as successful; responseElements: null alone does not indicate failure.

Key Fields

FieldInvestigation value
requestParametersTarget instance or association ID and requested profile; exact nesting is illustrated below.
responseElementsAssociation ID, instance, profile, and state; associating is not completion.
eventTime, recipientAccountId, eventID, requestIDTimeline, account, and correlation identifiers.

What to Investigate

  1. Confirm the outcome and match the caller, target, and timing to an approved workflow. Review failed attempts separately.
  2. Resolve the instance and previous profile, and compare the new role’s trust and effective permissions with the approved workload definition.
  3. Confirm the association reaches the expected state. Check metadata configuration and host access separately; the API event does not show credential retrieval.
  4. Correlate AddRoleToInstanceProfile with subsequent activity attributed to the instance role. Do not assume every process can access metadata or that existing credentials immediately stop working.

Sample Event

Synthetic scenario. Draco requests the Graphorn profile. The illustrative response is still associating; neither shell access nor successful use of elevated credentials is shown.

Exact CloudTrail nesting, field presence, redaction, and timestamp formatting remain unverified against captured logs. Credential/token placeholders and metadata placeholders are illustrative, not usable credentials or complete provider metadata.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:48:33Z",
"eventSource": "ec2.amazonaws.com",
"eventName": "ReplaceIamInstanceProfileAssociation",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"ReplaceIamInstanceProfileAssociationRequest": {
"AssociationId": "iip-assoc-0123456789abcdef0",
"IamInstanceProfile": {
"Arn": "arn:aws:iam::555123456789:instance-profile/GraphornAdminRole"
}
}
},
"responseElements": {
"ReplaceIamInstanceProfileAssociationResponse": {
"iamInstanceProfileAssociation": {
"associationId": "iip-assoc-0fedcba9876543210",
"instanceId": "i-0123456789abcdef0",
"iamInstanceProfile": {
"arn": "arn:aws:iam::555123456789:instance-profile/GraphornAdminRole",
"id": "AIPAGRAPH0RN1NSTPR0F1"
},
"state": "associating",
"timestamp": "2026-04-15T19:48:33Z"
}
}
},
"requestID": "90000000-0000-4000-8000-000110011110",
"eventID": "90000000-0000-4000-8000-000110011111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "ec2.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.