Skip to main content

Identity / IAM / Threats / DEV

Additional IAM Roles Creation

CCC.IAM.TH05

An adversary with access to a sufficiently privileged cloud account may create additional IAM roles to establish persistance or elevate their privileges.

Related Capabilities

IDTitleDescription
CCC.IAM.CP06IAM Roles / Service PrincipalsAbility to create, manage, list and delete IAM roles. IAM role is an identity for applications or services to access resources.
CCC.IAM.CP10Custom RolesAbility to create, manage, list and delete custom roles. Custom roles are user-defined roles that defines what actions are allowed.
CCC.IAM.CP15Role Assumption / DelegationAbility to temporarily assume another role or delegate access. Commonly used for user impersonation or temporary privilege elevation.

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1098.003Account Manipulation: Additional Cloud Roles