Elastic medium stable kql

AWS IAM Customer Managed Policy Version Created or Default Version Set

Identifies successful IAM API calls that create a new customer managed policy version or set the default version for an existing customer managed policy. Attackers with `iam:CreatePolicyVersion` or `iam:SetDefaultPolicyVersion` on a privileged policy can introduce a permissive policy document and activate it, escalating effective permissions without attaching a new policy. These APIs are high impact when the target policy is attached to powerful roles or users.

View Source

Detection Logic

event.dataset: "aws.cloudtrail"
    and event.provider: "iam.amazonaws.com"
    and event.action: ("CreatePolicyVersion" or "SetDefaultPolicyVersion")
    and event.outcome: "success"
    and not aws.cloudtrail.user_identity.type: "AWSService" 
    and not aws.cloudtrail.user_identity.arn:arn*/terraform 
    and not source.as.organization.name:(Amazon* or AMAZON* or "Google LLC" or "MongoDB, Inc.")
    and not source.address: ( "cloudformation.amazonaws.com" or "servicecatalog.amazonaws.com")
    and not user_agent.original: (*Terraform* or *Pulumi*)

False Positives

  • Infrastructure-as-code, CI/CD, and IAM administrators routinely publish new policy versions or roll back defaults. Validate the policy ARN, change tickets, and whether the policy document broadens permissions. Exclude automation roles or pipelines after review.

Field Validations

Loading…

Comments (0)

Loading comments...