UpdateFunctionCode20150331v2
UpdateFunctionCode20150331v2
Event
Updates the deployment package or container image used by the unpublished $LATEST version. Publish can create a new published version; published versions themselves are immutable. Aliases pinned to another version do not automatically switch. For container images, Lambda resolves the supplied tag to a digest rather than automatically following later tag changes.
Security Context
Changing code used by an established trigger can support persistence (contextual T1546). Normal deployment uses the same API. The update alone does not execute the package or prove it contains a script or backdoor.
Log Source
CloudTrail management event with eventSource: lambda.amazonaws.com and eventName: UpdateFunctionCode20150331v2. The dated suffix is part of the CloudTrail event name; the API documentation uses the undated operation name. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.
Key Fields
Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.
| Field | Investigation value |
|---|---|
functionName, s3Bucket, s3Key, s3ObjectVersion, imageUri | Target and deployment artifact; recover the exact version/digest. |
publish | Whether a new version is requested; false leaves the change unpublished. |
userIdentity, eventTime, awsRegion, eventID (top level) | Caller/session, timeline, Region, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Verify artifact provenance and inspect the actual code through approved access.
- Check final lastUpdateStatus, versions, aliases, and trigger destinations. InProgress is not completion.
- Correlate invocations of the changed version with runtime logs and behavior.
Sample Event
Synthetic scenario. The request updates $LATEST from an S3 package with publish false. The response is still InProgress and does not establish execution.
Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:42:19Z", "eventSource": "lambda.amazonaws.com", "eventName": "UpdateFunctionCode20150331v2", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "functionName": "occamy-log-processor", "s3Bucket": "fantasticlogs-niffler-archive", "s3Key": "staging/lambda-deploys/occamy-log-processor.zip", "publish": false }, "responseElements": { "functionName": "occamy-log-processor", "functionArn": "arn:aws:lambda:us-east-1:555123456789:function:occamy-log-processor", "runtime": "python3.11", "role": "arn:aws:iam::555123456789:role/OccamyPipelineRole", "handler": "handler.lambda_handler", "codeSize": 4827193, "description": "OCCAMY ingest log processor", "timeout": 60, "memorySize": 512, "lastModified": "2026-04-15T21:42:19.512+0000", "version": "$LATEST", "tracingConfig": { "mode": "PassThrough" }, "revisionId": "90000000-0000-4000-8000-0001f0e0d0c0", "state": "Active", "lastUpdateStatus": "InProgress" }, "requestID": "90000000-0000-4000-8000-000111001010", "eventID": "90000000-0000-4000-8000-000111001011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "lambda.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence
- T1546 — Event Triggered Execution — Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events. Various operating systems have means to monitor and subscribe to events such as logons or other user activity such as running specific applications/binaries. Cl...