Skip to content
Threat Feed

Product

AWS Security Token Service

7 briefs RSS
medium advisory

Detection of Unauthorized AWS STS GetCallerIdentity Discovery

Adversaries with compromised credentials may abuse the AWS STS GetCallerIdentity API to verify access and identify the current account context, serving as a primary indicator of initial cloud reconnaissance.

AWS Security Token Service cloud aws cloudtrail discovery credential-abuse
1r 2t
high advisory

Suspicious AWS IAM API Calls via Temporary Session Tokens

This detection rule identifies suspicious AWS IAM API operations performed using temporary session credentials (access keys starting with ASIA) that are not sourced from console logins, indicating potential credential theft, session hijacking, or abuse of privileged temporary credentials by an attacker for persistence, privilege escalation, or defense evasion within the AWS environment.

AWS IAM +3 cloud aws persistence privilege-escalation defense-evasion
1r 2t
high advisory

AWS STS GetFederationToken Abuse for Persistence and Defense Evasion

Adversaries may exploit the AWS Security Token Service (STS) GetFederationToken API call to obtain temporary security credentials, enabling persistence and bypassing IAM API call limitations by gaining console access, with these temporary tokens remaining active for up to 36 hours, even if the initial compromised identity is deleted, and used to create console sign-in tokens.

AWS Security Token Service cloud aws defense-evasion persistence threat-detection
1r 2t
medium advisory

AWS STS AssumeRoot by Rare User and Member Account

The rule detects when the STS AssumeRoot action is performed by a rare user in AWS, potentially indicating privilege escalation.

AWS Security Token Service aws privilege-escalation cloud
2r 3t
medium advisory

AWS STS GetFederationToken Request for Defense Evasion and Persistence

Detection of the first AWS Security Token Service (STS) GetFederationToken request by a user, which adversaries can abuse to obtain temporary credentials for persistence and to bypass IAM API call limitations by gaining console access.

AWS Security Token Service aws cloud defense-evasion persistence
2r 2t
low threat

AWS STS AssumeRole with New MFA Device

This rule identifies when a user has assumed a role using a new MFA device in AWS, which can be indicative of persistence and privilege escalation attempts by threat actors.

exploited AWS Security Token Service +1 aws cloudtrail sts assume_role mfa persistence privilege_escalation lateral_movement
2r 4t
medium advisory

AWS STS Role Chaining for Privilege Escalation and Persistence

AWS STS role chaining, where one assumed role is used to assume another, can lead to privilege escalation or persistence by refreshing session tokens, triggering alerts on the first observed role assumption based on CloudTrail logs.

AWS Security Token Service +1 aws sts role-chaining privilege-escalation persistence
2r 3t