Skip to content

UpdateDevEndpoint

AWS

UpdateDevEndpoint

service: AWS - Glue
techniques:

Event

Updates an existing development endpoint, including adding/removing SSH public keys and supported argument/library changes. This API does not change its execution role. A submitted update does not prove a new connection or that a library was loaded.

Security Context

Unauthorized SSH-key addition can manipulate access (T1098). Approved key rotation uses the same operation. Using the key requires its matching private key, a reachable ready endpoint, and applicable access controls; role permissions bound subsequent AWS access.

Log Source

CloudTrail management event with eventSource: glue.amazonaws.com and eventName: UpdateDevEndpoint. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.

Key Fields

Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.

FieldInvestigation value
endpointNameExisting endpoint and its configured role/network.
addPublicKeys, deletePublicKeys, publicKeyKey additions, removals, or replacement; compare fingerprints.
customLibraries, updateEtlLibraries, addArguments, deleteArgumentsOther requested changes where present.
userIdentity, eventTime, awsRegion, eventID (top level)Caller/session, timeline, Region, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Compare prior and new keys against approved owners and rotation records.
  3. Verify update completion, endpoint readiness, and network access without attempting a connection.
  4. Correlate subsequent connections and role activity; absence of a response body is not proof of failure.

Sample Event

Synthetic scenario. The request adds an illustrative RSA public key. It does not demonstrate a login, library execution, or changed role.

Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T21:32:08Z",
"eventSource": "glue.amazonaws.com",
"eventName": "UpdateDevEndpoint",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"endpointName": "demiguise-glue-dev",
"addPublicKeys": [
"ssh-rsa AAAAB3NzaC1yc2EAAAADAQABAAABAQC7jKZjbz9i7H+GAYLq2AyQN2G5axXRa6g+cvoXwHE7xxfK8VdIZG9TYIfBq82PsmKqLOWDuU3sOIwpMv5HdJZNvUARdgJC12URH+5JeLYlQ61mISA7SU2CdUVe8CPiR9YezvH71+u4LIVZqg4yID4rvhfdlwc1lB7aphrLGYjNoqw7Q0lyudCip2j0x7/9LDHZ2AY5l7KEYEsVTGAEtnHCet5RRV9S7OUyw2FsL6EVwep2P19nFbur25LmepVHslHLXJJzmlmYBscs//Fn/Hrbf91XxZ9MWE6KoWpsk5IKFqpa1jGNG67dyoe4lEA/gCIVo4RiYBMfD9NWHf7GX2lb synthetic-review-example"
]
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000111000110",
"eventID": "90000000-0000-4000-8000-000111000111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "glue.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.