Skip to content

UpdateFunctionConfiguration20150331v2

AWS

UpdateFunctionConfiguration20150331v2

service: AWS - Lambda
techniques:

Event

Changes configuration such as the execution role, layers, runtime settings, and environment. Updates apply to the unpublished version; existing published versions retain their configuration. AWS omits Environment from CloudTrail request and response records, so this event cannot reveal its variable values.

Security Context

An unauthorized execution-role change may manipulate access (T1098). Passing a role requires appropriate iam:PassRole permission and the role must trust Lambda; actual access remains bounded by effective policies. A layer must be accessible and compatible, and its presence does not prove its code ran.

Log Source

CloudTrail management event with eventSource: lambda.amazonaws.com and eventName: UpdateFunctionConfiguration20150331v2. The dated suffix is part of the CloudTrail event name; the API documentation uses the undated operation name. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.

Key Fields

Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.

FieldInvestigation value
functionName, roleFunction and requested execution role.
layersRequested layer versions; names alone do not establish behavior.
userIdentity, eventTime, awsRegion, eventID (top level)Caller/session, timeline, Region, and correlation identifiers.

What to Investigate

  1. Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
  2. Compare prior configuration and deployment approval, including role trust and effective permissions.
  3. Inspect accessible layer artifacts and trusted configuration history. Do not expect environment values in CloudTrail or copy secrets into investigation notes.
  4. Confirm final update status and which invoked version uses the changed configuration.

Sample Event

Synthetic scenario. The request selects another execution role and an external layer. Environment fields are intentionally absent; the update remains InProgress.

Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T21:45:31Z",
"eventSource": "lambda.amazonaws.com",
"eventName": "UpdateFunctionConfiguration20150331v2",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"functionName": "occamy-log-processor",
"role": "arn:aws:iam::555123456789:role/GraphornAdminRole",
"layers": [
"arn:aws:lambda:us-east-1:555666661337:layer:adversary-implant:1"
]
},
"responseElements": {
"functionName": "occamy-log-processor",
"functionArn": "arn:aws:lambda:us-east-1:555123456789:function:occamy-log-processor",
"runtime": "python3.11",
"role": "arn:aws:iam::555123456789:role/GraphornAdminRole",
"handler": "handler.lambda_handler",
"codeSize": 4827193,
"timeout": 60,
"memorySize": 512,
"lastModified": "2026-04-15T21:45:31.108+0000",
"version": "$LATEST",
"layers": [
{
"arn": "arn:aws:lambda:us-east-1:555666661337:layer:adversary-implant:1",
"codeSize": 18271
}
],
"revisionId": "90000000-0000-4000-8000-000111001100",
"state": "Active",
"lastUpdateStatus": "InProgress"
},
"requestID": "90000000-0000-4000-8000-000111001100",
"eventID": "90000000-0000-4000-8000-000111001101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "lambda.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.