Elastic low stable kql
AWS STS AssumeRole with New MFA Device
Identifies when a user has assumed a role using a new MFA device. Users can assume a role to obtain temporary credentials and access AWS resources using the AssumeRole API of AWS Security Token Service (STS). While a new MFA device is not always indicative of malicious behavior it should be verified as adversaries can use this technique for persistence and privilege escalation.
Detection Logic
data_stream.dataset:aws.cloudtrail
and event.provider:sts.amazonaws.com
and event.action:(AssumeRole or AssumeRoleWithSAML or AssumeRoleWithWebIdentity)
and event.outcome:success
and aws.cloudtrail.flattened.request_parameters.serialNumber:* False Positives
- ⚠ AWS administrators or automated processes might regularly assume roles for legitimate administrative purposes and to perform periodic tasks such as data backups, updates, or deployments.
Field Validations
Loading…
Comments (0)
Loading comments...