Elastic medium stable kql
AWS IAM Customer Managed Policy Version Created or Default Version Set
Identifies successful IAM API calls that create a new customer managed policy version or set the default version for an existing customer managed policy. Attackers with `iam:CreatePolicyVersion` or `iam:SetDefaultPolicyVersion` on a privileged policy can introduce a permissive policy document and activate it, escalating effective permissions without attaching a new policy. These APIs are high impact when the target policy is attached to powerful roles or users.
Detection Logic
event.dataset: "aws.cloudtrail"
and event.provider: "iam.amazonaws.com"
and event.action: ("CreatePolicyVersion" or "SetDefaultPolicyVersion")
and event.outcome: "success"
and not aws.cloudtrail.user_identity.type: "AWSService"
and not aws.cloudtrail.user_identity.arn:arn*/terraform
and not source.as.organization.name:(Amazon* or AMAZON* or "Google LLC" or "MongoDB, Inc.")
and not source.address: ( "cloudformation.amazonaws.com" or "servicecatalog.amazonaws.com")
and not user_agent.original: (*Terraform* or *Pulumi*) False Positives
- ⚠ Infrastructure-as-code, CI/CD, and IAM administrators routinely publish new policy versions or roll back defaults. Validate the policy ARN, change tickets, and whether the policy document broadens permissions. Exclude automation roles or pipelines after review.
Field Validations
Loading…
Comments (0)
Loading comments...