Suspicious AWS IAM Role Creation With Cross-Account Trust Policy

PremiumReviewedSigma · Low · v1
Product
aws
Service
cloudtrail
Author
HuntRule
Published
2026-09-14
Updated
2026-09-14

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects an IAM CreateRole event whose assumeRolePolicyDocument establishes a trust relationship that allows another AWS account principal to assume the role. Adversaries create such backdoored roles so an attacker-controlled external account gains persistent access into the victim environment. This is important because cross-account trust relationships are a stealthy persistence mechanism that survives credential rotation.

Related detections9 linkedT1098.003 — drag to rearrange
Suspicious Azure Policy Definition or Assignment Modification
Suspicious MURKY PANDA Mail Permission Grant to Service Principal (via azure)
Malicious Assignment of a Privileged Azure AD Role (via auditlogs)
Suspicious Entra Cross-Tenant Access or External User Invitation via Azure Audit (via azure)
Suspicious Delegated Permission Grant to Entra Agent Access Scope via Azure Audit Logs
Suspicious IAM CreateLoginProfile For Root User via AWS AssumeRoot Abuse
Suspicious AWS IAM Privilege Escalation via AttachUserPolicy of Administrator Policy
Suspicious Member Added to Privileged Directory Role in Entra ID
Suspicious High-Privilege Microsoft Graph Application Role Grant via Azure Audit (via azure)
Suspicious AWS IAM Role Creation With Cross-Account Trust Policy
Pivot detection · T1098.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.