AWS CloudTrail GetSigninToken Requests with Suspected Console User-Agent

Flags CloudTrail GetSigninToken sign-in token requests with non-matching console user-agent patterns.

FreeReviewedSigma · Medium · v5
Product
aws
Service
cloudtrail
Author
Chester Le Bron (@123Le_Bron) (SigmaHQ), DRL 1.1
Published
2024-02-26
Updated
2026-07-31

ATT&CK techniques

Defense Evasion → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Cred Access

  8. Discovery

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags AWS CloudTrail events where GetSigninToken is called against signin.amazonaws.com, excluding requests that match a specific Jersey-based user agent pattern. Attackers can use GetSigninToken to obtain temporary federated credentials that may help pivot from tooling to AWS console access while reducing reliance on MFA tied to an original identity. The detection relies on CloudTrail eventSource/eventName fields and the userAgent substring observed in the request.

Related detections9 linkedT1550.001 — drag to rearrange
Suspicious Kubernetes Service Account Token Generation via kubectl
Suspicious browsercore Execution from Anomalous Parent for PRT Cookie (via process_creation)
Suspicious AWS SSO Account Role Enumeration via ListAccountRoles (via cloudtrail)
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious Device Registration Following OAuth Token Theft
Suspicious EC2 Serial Console SSH Public Key Push (via cloudtrail)
Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
Suspicious Entra Agent Service Principal Sign-In With PowerShell User Agent via Sign-In Logs
Suspicious Entra ID Auth Broker Sign-In With Node.js User Agent via Tycoon 2FA
AWS CloudTrail GetSigninToken Requests with Suspected Console User-Agent
Pivot detection · T1550.001 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.