如何查询已删除特定IAM用户的创建者?能否使用CloudTrail实现?
How to Find the Creator of a Deleted IAM User with AWS CloudTrail
Great question! AWS CloudTrail is exactly the tool you need to track down who created a deleted IAM user — even if the user is gone, the audit trail of their creation remains (as long as CloudTrail was enabled when the user was set up). Here's a straightforward breakdown of how to get that info:
Step 1: Navigate to CloudTrail Event History
- Open the AWS CloudTrail console and head to the Event history section. This is where all tracked API actions are stored, including the
CreateUserevent that spawned your deleted IAM user.
Step 2: Filter for the Exact Creation Event
- Use the console's filter tools to narrow down results:
- Set the Event name filter to
CreateUser(this is the specific API call for creating an IAM user). - Add a Resource name filter and enter the username of the deleted IAM user — even though the user no longer exists, the event will still reference their original username.
- Optionally, set a Time range to match when you suspect the user was created (this cuts through noise from unrelated events).
- Set the Event name filter to
Step 3: Extract the Creator's Details
- Once you spot the matching
CreateUserevent, click into it to view the full event payload. - Look for the
userIdentitysection:- If the creator was an IAM user, you'll see their
userNameand ARN. - If it was the AWS root user,
userIdentity.typewill showRootalongside the root account's ARN. - If the user was created via an IAM role,
userIdentity.typewill beAssumedRole, and you'll get the role's ARN plussessionContextdata showing who assumed the role (e.g., another IAM user or an AWS service).
- If the creator was an IAM user, you'll see their
Alternative: Use the AWS CLI
If you prefer working from the command line, run this command to search for the creation event:
aws cloudtrail lookup-events \ --lookup-attributes AttributeKey=EventName,AttributeValue=CreateUser \ --lookup-attributes AttributeKey=ResourceName,AttributeValue=YOUR_DELETED_USERNAME \ --start-time 2024-01-01T00:00:00Z \ --end-time 2024-01-31T23:59:59Z
Replace YOUR_DELETED_USERNAME with the actual username and adjust the time range to fit your needs. The output will include the userIdentity field with the creator's details.
Important Things to Keep in Mind
- CloudTrail Retention: By default, CloudTrail keeps events for 90 days. If you need access to older logs, ensure you've configured CloudTrail to deliver logs to an S3 bucket (where you can retain them indefinitely if required).
- Event Availability: CloudTrail must have been enabled at the time the IAM user was created — if it wasn't, there won't be a record of the
CreateUserevent to retrieve.
内容的提问来源于stack exchange,提问作者Mohamed Salem
相关产品推荐
相关产品推荐

