Detecting Anomalous API Calls by AssumedRole Entities in AWS
This analytic identifies potential unauthorized access or credential misuse by detecting API calls performed by AWS 'AssumedRole' entities that deviate from historical behavioral baselines.
This detection focuses on identifying suspicious activity within AWS environments by monitoring API calls executed by users with the 'AssumedRole' type. Attackers often compromise temporary security credentials to move laterally or persist within a cloud environment; these activities frequently involve executing API calls that the legitimate service role has never performed before. By utilizing historical baselines of user-command associations in AWS CloudTrail, this analytic triggers alerts when a role executes a command for the first time or after a significant period of inactivity. This is critical for defenders because it surfaces potentially malicious reconnaissance, privilege escalation, or exfiltration efforts that rely on abusing existing, yet previously underutilized, IAM roles.
Impact
Successful exploitation of compromised 'AssumedRole' identities can lead to full account takeover, unauthorized access to sensitive cloud resources, data exfiltration from S3 buckets, and the modification of security groups or IAM policies to maintain persistent backdoor access within the AWS infrastructure.
Recommendation
- Ingest AWS CloudTrail logs into your SIEM and enable the baseline correlation searches defined in the Splunk Security Content framework ('Previously Seen Cloud API Calls Per User Role - Initial' and 'Update').
- Configure the
cloud_api_calls_from_previously_unseen_user_roles_activity_windowmacro to align with your organization's risk appetite and operational cadence. - Use the detected
userandcommandartifacts to pivot into risk-based analysis, specifically reviewing historical risk events for the target entity to identify broader patterns of compromise. - Baseline 'AssumedRole' activity during initial deployment windows to minimize false positives associated with standard CI/CD pipelines or automated infrastructure configuration tools.
Immediate actions
Deploy baseline tracking searches for AWS CloudTrail API activity
Threat Hunt
Identify AssumedRole entities executing high-impact API calls for the first time
Data: AWS CloudTrail