{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/credential-abuse/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["AWS Security Token Service"],"_cs_severities":["medium"],"_cs_tags":["cloud","aws","cloudtrail","discovery","credential-abuse"],"_cs_type":"advisory","_cs_vendors":["Amazon"],"content_html":"\u003cp\u003eAdversaries frequently target AWS environments by leveraging stolen IAM credentials to conduct discovery and lateral movement. A common reconnaissance tactic is the use of the AWS Security Token Service (STS) \u003ccode\u003eGetCallerIdentity\u003c/code\u003e API, which provides details about the IAM user or role associated with the credentials currently in use. This operation requires no specific permissions and returns consistent information even if access to other resources is denied, making it a low-noise method for attackers to verify if their hijacked credentials are valid and to map their current environment context. This threat is particularly concerning because legitimate human users rarely need to call this API, as they are typically aware of the account context in which they are operating. Monitoring for the first-time usage of this API by specific identities provides a reliable signal for identifying credential abuse, provided that automated service accounts are appropriately tuned out of the detection logic.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful abuse of the \u003ccode\u003eGetCallerIdentity\u003c/code\u003e API indicates that an attacker has gained a functional foothold in an AWS account using compromised credentials. This discovery phase allows the attacker to confirm their access level before proceeding with more aggressive actions, such as resource enumeration, sensitive data exfiltration, or persistence establishment. If undetected, this initial access can lead to significant data breaches and unauthorized control over cloud infrastructure.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eDetection engineering teams should implement monitoring for the \u003ccode\u003eGetCallerIdentity\u003c/code\u003e event within AWS CloudTrail, specifically focusing on the first instance of an identity performing this call.\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eDeploy the provided detection logic to your SIEM to alert on anomalous \u003ccode\u003eGetCallerIdentity\u003c/code\u003e calls from non-service identities.\u003c/li\u003e\n\u003cli\u003eEstablish a baseline of known-good service accounts and automated tooling that legitimately use this API to reduce false positives.\u003c/li\u003e\n\u003cli\u003eIntegrate CloudTrail logs with security analytics platforms and tune alerts by excluding known \u003ccode\u003euser_agent.original\u003c/code\u003e strings associated with infrastructure-as-code tools like Terraform or Pulumi.\u003c/li\u003e\n\u003cli\u003eConduct periodic reviews of IAM permissions and enable multi-factor authentication (MFA) for all IAM users to mitigate the risk of credential compromise.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-24T09:47:07Z","date_published":"2026-08-24T09:47:07Z","id":"https://feed.craftedsignal.io/briefs/2026-08-aws-sts-getcalleridentity/","summary":"Adversaries with compromised credentials may abuse the AWS STS GetCallerIdentity API to verify access and identify the current account context, serving as a primary indicator of initial cloud reconnaissance.","title":"Detection of Unauthorized AWS STS GetCallerIdentity Discovery","url":"https://feed.craftedsignal.io/briefs/2026-08-aws-sts-getcalleridentity/"}],"language":"en","title":"CraftedSignal Threat Feed - Credential-Abuse","version":"https://jsonfeed.org/version/1.1"}