UpdateFunctionConfiguration20150331v2
UpdateFunctionConfiguration20150331v2
Event
Changes configuration such as the execution role, layers, runtime settings, and environment. Updates apply to the unpublished version; existing published versions retain their configuration. AWS omits Environment from CloudTrail request and response records, so this event cannot reveal its variable values.
Security Context
An unauthorized execution-role change may manipulate access (T1098). Passing a role requires appropriate iam:PassRole permission and the role must trust Lambda; actual access remains bounded by effective policies. A layer must be accessible and compatible, and its presence does not prove its code ran.
Log Source
CloudTrail management event with eventSource: lambda.amazonaws.com and eventName: UpdateFunctionConfiguration20150331v2. The dated suffix is part of the CloudTrail event name; the API documentation uses the undated operation name. Inspect errorCode/errorMessage and follow-up state. A missing or null response body does not alone establish success or failure.
Key Fields
Fields below refer to requestParameters unless otherwise noted. Exact CloudTrail serialization should be checked against the original record.
| Field | Investigation value |
|---|---|
functionName, role | Function and requested execution role. |
layers | Requested layer versions; names alone do not establish behavior. |
userIdentity, eventTime, awsRegion, eventID (top level) | Caller/session, timeline, Region, and correlation identifiers. |
What to Investigate
- Confirm the recorded outcome and compare caller, target, and timing with the approved workflow.
- Compare prior configuration and deployment approval, including role trust and effective permissions.
- Inspect accessible layer artifacts and trusted configuration history. Do not expect environment values in CloudTrail or copy secrets into investigation notes.
- Confirm final update status and which invoked version uses the changed configuration.
Sample Event
Synthetic scenario. The request selects another execution role and an external layer. Environment fields are intentionally absent; the update remains InProgress.
Exact CloudTrail field presence, response nesting, redaction, and timestamp formatting remain unverified against captured logs. Illustrative names do not establish intent or downstream behavior.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T18:51:02Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T21:45:31Z", "eventSource": "lambda.amazonaws.com", "eventName": "UpdateFunctionConfiguration20150331v2", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "functionName": "occamy-log-processor", "role": "arn:aws:iam::555123456789:role/GraphornAdminRole", "layers": [ "arn:aws:lambda:us-east-1:555666661337:layer:adversary-implant:1" ] }, "responseElements": { "functionName": "occamy-log-processor", "functionArn": "arn:aws:lambda:us-east-1:555123456789:function:occamy-log-processor", "runtime": "python3.11", "role": "arn:aws:iam::555123456789:role/GraphornAdminRole", "handler": "handler.lambda_handler", "codeSize": 4827193, "timeout": 60, "memorySize": 512, "lastModified": "2026-04-15T21:45:31.108+0000", "version": "$LATEST", "layers": [ { "arn": "arn:aws:lambda:us-east-1:555666661337:layer:adversary-implant:1", "codeSize": 18271 } ], "revisionId": "90000000-0000-4000-8000-000111001100", "state": "Active", "lastUpdateStatus": "InProgress" }, "requestID": "90000000-0000-4000-8000-000111001100", "eventID": "90000000-0000-4000-8000-000111001101", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "lambda.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...