Elastic low stable kql

AWS Sign-In Token Created

Captures requests to the AWS federation endpoint (signin.amazonaws.com) for GetSigninToken. This API exchanges existing temporary AWS credentials (e.g., from STS GetFederationToken or AssumeRole) for a short-lived sign-in token that is embedded in a one-click URL to the AWS Management Console. It is commonly used by custom federation tools and automation to pivot from programmatic access to a browser session. This is a building block rule meant to be used for correlation with other rules to detect suspicious activity.

View Source

Detection Logic

event.dataset: "aws.cloudtrail" and 
    event.provider: "signin.amazonaws.com" and 
    event.action : "GetSigninToken" and 
    event.outcome: "success"

False Positives

  • Legitimate federation workflows, admin portals, SSO helpers, CI/CD jobs, or internal scripts that create one-click console links, commonly invoke GetSigninToken and may generate frequent benign events.

Field Validations

Loading…

Comments (0)

Loading comments...