Skip to main content

CCC.IAM.TH06: IAM Policies Modification

Threat ID:CCC.IAM.TH06
Title:IAM Policies Modification
Description:

An adversary with access to a sufficiently privileged cloud account may modify IAM policies to establish persistance or elevate their privileges.

Related Capabilities

IDTitleDescription
CCC.IAM.F02IAM UsersAbility to create, manage, list and delete IAM users. IAM user represents a single person or application.
CCC.IAM.F06IAM Roles / Service PrincipalsAbility to create, manage, list and delete IAM roles. IAM role is an identity for applications or services to access resources.
CCC.IAM.F10Custom RolesAbility to create, manage, list and delete custom roles. Custom roles are user-defined roles that defines what actions are allowed.

External Mappings

Reference IDEntry IDStrengthRemarks
MITRE-ATT&CK
T1098.003
0
Account Manipulation: Additional Cloud Roles
MITRE-ATT&CK
T1556.009
0
Modify Authentication Process: Conditional Access Policies

Controls

IDTitleObjectiveControl FamilyThreat MappingsGuideline MappingsAssessment Requirements
CCC.IAM.C02Restrict IAM Policies ModificationEnsure that only designated administrative accounts have the ability to create, modify, or attach policies that define permissions for other identities. Identity and Access Management
1
5
2