UpdateAssumeRolePolicy
UpdateAssumeRolePolicy
Event
Updates the role trust policy with the submitted document. Treat this as replacement of the document, not necessarily an additive change. The role permissions policies are separate.
Security Context
An unauthorized trust change can enable an additional access path or remove safeguards. Approved federation and workload changes use the same operation. T1098 and T1484.002 are contextual mappings for account and trust manipulation. An account principal such as arn:aws:iam::555666661337:root delegates trust to that account; it is not restricted to its root user and does not automatically authorize every identity there. Cross-account callers also need permission to assume the role, and trust conditions and other applicable restrictions must be satisfied.
Log Source
AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: UpdateAssumeRolePolicy. Include IAM global-service events in collection. Check errorCode and errorMessage; responseElements: null alone does not establish failure.
Key Fields
Request fields below are under requestParameters unless another path is shown.
| Field | Investigation value |
|---|---|
userIdentity | Caller and session context; distinguish the caller from the target. |
roleName | Role whose trust is changing; the name does not establish its privilege level. |
policyDocument | Complete submitted trust document; compare with its predecessor. |
eventTime, recipientAccountId, eventID, requestID | Timeline, account, and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context; neither proves malicious intent. |
errorCode, errorMessage | Distinguish failed attempts from completed changes. |
What to Investigate
- Confirm the request outcome, calling identity, account, and approved change. A recorded attempt is not necessarily a completed change.
- Recover the previous trust policy and compare principals, actions, and conditions. Identify removed restrictions as well as added principals.
- Verify cross-account authorization and the role’s effective permissions, including session and organization constraints. Do not infer administrator access from the role name.
- Correlate successful AssumeRole and downstream role sessions. Assess persistence only where an independently usable principal can still authenticate and assume the role.
Sample Event
Synthetic scenario. Draco submits a trust document for GraphornAdminRole naming an external account. The old document is absent: this sample cannot prove that a principal was merely added or that every identity in that account gained access.
This is an illustrative CloudTrail-shaped record. Exact field presence, timestamp formatting, and policy-document serialization have not been verified against a captured event. Preserve raw records before decoding any nested policy documents.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:23:11Z", "eventSource": "iam.amazonaws.com", "eventName": "UpdateAssumeRolePolicy", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "roleName": "GraphornAdminRole", "policyDocument": "%7B%22Version%22%3A%222012-10-17%22%2C%22Statement%22%3A%5B%7B%22Effect%22%3A%22Allow%22%2C%22Principal%22%3A%7B%22AWS%22%3A%22arn%3Aaws%3Aiam%3A%3A555666661337%3Aroot%22%7D%2C%22Action%22%3A%22sts%3AAssumeRole%22%7D%5D%7D" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000111000010", "eventID": "90000000-0000-4000-8000-000111000011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation Defense Impairment
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
- T1484.002 — Trust Modification — Adversaries may add new domain trusts, modify the properties of existing domain trusts, or otherwise change the configuration of trust relationships between domains and tenants to evade defenses and/or elevate privileges.Trust details, such as whether or not user identities are federated, allow a...