AWS CloudTrail: Suspicious STS AssumeRole sessions from Role-issued principals

Alert on CloudTrail AssumeRole events initiated from an already assumed role session.

FreeReviewedSigma · Low · v5
Product
aws
Service
cloudtrail
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-07-24
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Lateral Movement

What it detects

This rule flags CloudTrail events where the caller’s identity is an assumed role session and the session issuer is of type Role. Such activity can indicate attackers using AWS STS AssumeRole to obtain new credentials, enabling lateral movement and privilege changes within the AWS environment. The detection relies on CloudTrail userIdentity and sessionContext fields that describe the assumed role and its role issuer.

Related detections9 linkedT1550.001 — drag to rearrange
AWS CloudTrail Alert for Suspicious SAML Role Assumption and SAML Provider Updates
AWS CloudTrail: IAMUser STS GetSessionToken Use
Suspicious AWS GetFederationToken Console Access by JavaGhost (via cloudtrail)
Malicious GCP Service Account Backdoor via serviceAccountTokenCreator Grant
Suspicious GCP Service Account Impersonation via GenerateAccessToken
Malicious Azure Elevate Access to User Access Administrator
Suspicious AWS Role Assumption via Cognito Web Identity
Suspicious Kubernetes Service Account Token Generation via kubectl
Suspicious browsercore Execution from Anomalous Parent for PRT Cookie (via process_creation)
AWS CloudTrail: Suspicious STS AssumeRole sessions from Role-issued principals
Pivot detection · T1550.001 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.