Skip to main content

Identity / IAM / Threats / DEV

IAM Policies Modification

CCC.IAM.TH06

An adversary with access to a sufficiently privileged cloud account may modify IAM policies to establish persistance or elevate their privileges.

Related Capabilities

IDTitleDescription
CCC.IAM.CP02IAM UsersAbility to create, manage, list and delete IAM users. IAM user represents a single person or application.
CCC.IAM.CP06IAM Roles / Service PrincipalsAbility to create, manage, list and delete IAM roles. IAM role is an identity for applications or services to access resources.
CCC.IAM.CP10Custom RolesAbility to create, manage, list and delete custom roles. Custom roles are user-defined roles that defines what actions are allowed.

Related Controls

IDTitleDescription
CCC.IAM.CN02Restrict IAM Policies ModificationEnsure that only designated administrative accounts have the ability to create, modify, or attach policies that define permissions for other identities.

External Mappings

FrameworkIDRemarks
MITRE-ATT&CKT1098.003Account Manipulation: Additional Cloud Roles
MITRE-ATT&CKT1556.009Modify Authentication Process: Conditional Access Policies