Skip to content

SetDefaultPolicyVersion

AWS

SetDefaultPolicyVersion

service: AWS - IAM
techniques:

Event

Selects an existing version of a customer-managed policy as its default. It does not submit a new document. Permission attachments and uses as a boundary can be affected without a new attachment event.

Security Context

An attacker could select an older permissive document or a prepared version to change access. Version numbers alone reveal neither privilege level nor intent; approved rollback is common. Retain T1098 only as a contextual account-manipulation mapping, and evaluate the resulting permissions and restrictions.

Log Source

AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: SetDefaultPolicyVersion. Include IAM global-service events in collection. Check errorCode and errorMessage; responseElements: null alone does not establish failure.

Key Fields

Request fields below are under requestParameters unless another path is shown.

FieldInvestigation value
userIdentityCaller and session context; distinguish the caller from the target.
policyArnPolicy whose operative version is changing.
versionIdSelected existing version; its document is absent from this request.
eventTime, recipientAccountId, eventID, requestIDTimeline, account, and correlation identifiers.
sourceIPAddress, userAgentSupporting context; neither proves malicious intent.
errorCode, errorMessageDistinguish failed attempts from completed changes.

What to Investigate

  1. Confirm the request outcome, calling identity, account, and approved change. A recorded attempt is not necessarily a completed change.
  2. Recover the previously default and selected version documents, using history if a version was subsequently deleted. Compare complete statements.
  3. Enumerate permission attachments and boundary uses, including group members at the time. Evaluate the change against all applicable controls.
  4. Correlate CreatePolicyVersion and subsequent API activity. Confirm propagation and actual use; the request alone does not show prior default, recipients, or successful escalation.

Sample Event

Synthetic scenario. Draco selects v1 of OccamyPipelinePolicy. The sample does not establish that v3 was previously active, that v1 allowed S3 access, or that any service roles used the policy.

This is an illustrative CloudTrail-shaped record. Exact field presence, timestamp formatting, and policy-document serialization have not been verified against a captured event. Preserve raw records before decoding any nested policy documents.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:31:09Z",
"eventSource": "iam.amazonaws.com",
"eventName": "SetDefaultPolicyVersion",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"policyArn": "arn:aws:iam::555123456789:policy/OccamyPipelinePolicy",
"versionId": "v1"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000110101100",
"eventID": "90000000-0000-4000-8000-000110101101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation Persistence

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.