You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何查询已删除特定IAM用户的创建者?能否使用CloudTrail实现?

How to Find the Creator of a Deleted IAM User with AWS CloudTrail

Great question! AWS CloudTrail is exactly the tool you need to track down who created a deleted IAM user — even if the user is gone, the audit trail of their creation remains (as long as CloudTrail was enabled when the user was set up). Here's a straightforward breakdown of how to get that info:

Step 1: Navigate to CloudTrail Event History

  • Open the AWS CloudTrail console and head to the Event history section. This is where all tracked API actions are stored, including the CreateUser event that spawned your deleted IAM user.

Step 2: Filter for the Exact Creation Event

  • Use the console's filter tools to narrow down results:
    • Set the Event name filter to CreateUser (this is the specific API call for creating an IAM user).
    • Add a Resource name filter and enter the username of the deleted IAM user — even though the user no longer exists, the event will still reference their original username.
    • Optionally, set a Time range to match when you suspect the user was created (this cuts through noise from unrelated events).

Step 3: Extract the Creator's Details

  • Once you spot the matching CreateUser event, click into it to view the full event payload.
  • Look for the userIdentity section:
    • If the creator was an IAM user, you'll see their userName and ARN.
    • If it was the AWS root user, userIdentity.type will show Root alongside the root account's ARN.
    • If the user was created via an IAM role, userIdentity.type will be AssumedRole, and you'll get the role's ARN plus sessionContext data showing who assumed the role (e.g., another IAM user or an AWS service).

Alternative: Use the AWS CLI

If you prefer working from the command line, run this command to search for the creation event:

aws cloudtrail lookup-events \
  --lookup-attributes AttributeKey=EventName,AttributeValue=CreateUser \
  --lookup-attributes AttributeKey=ResourceName,AttributeValue=YOUR_DELETED_USERNAME \
  --start-time 2024-01-01T00:00:00Z \
  --end-time 2024-01-31T23:59:59Z

Replace YOUR_DELETED_USERNAME with the actual username and adjust the time range to fit your needs. The output will include the userIdentity field with the creator's details.

Important Things to Keep in Mind

  • CloudTrail Retention: By default, CloudTrail keeps events for 90 days. If you need access to older logs, ensure you've configured CloudTrail to deliver logs to an S3 bucket (where you can retain them indefinitely if required).
  • Event Availability: CloudTrail must have been enabled at the time the IAM user was created — if it wasn't, there won't be a record of the CreateUser event to retrieve.

内容的提问来源于stack exchange,提问作者Mohamed Salem

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.28 09:37:33