AWS CloudTrail: IAMUser STS GetSessionToken Use

Alerts on CloudTrail STS GetSessionToken calls made by IAM users, indicating potential temporary credential misuse.

FreeReviewedSigma · Low · v5
Product
aws
Service
cloudtrail
Author
Austin Songer @austinsonger (SigmaHQ), DRL 1.1
Published
2021-07-24
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Lateral Movement

What it detects

This rule flags CloudTrail events where an IAM user calls the STS GetSessionToken API. Attackers can use session tokens to obtain temporary credentials that may enable lateral movement or privilege escalation. It relies on telemetry from AWS CloudTrail, specifically matching eventSource sts.amazonaws.com, eventName GetSessionToken, and userIdentity.type equal to IAMUser.

Related detections9 linkedT1550.001 — drag to rearrange
AWS CloudTrail Alert for Suspicious SAML Role Assumption and SAML Provider Updates
AWS CloudTrail: Suspicious STS AssumeRole sessions from Role-issued principals
Suspicious AWS GetFederationToken Console Access by JavaGhost (via cloudtrail)
Malicious GCP Service Account Backdoor via serviceAccountTokenCreator Grant
Suspicious GCP Service Account Impersonation via GenerateAccessToken
Malicious Azure Elevate Access to User Access Administrator
Suspicious AWS Role Assumption via Cognito Web Identity
Suspicious Kubernetes Service Account Token Generation via kubectl
Suspicious browsercore Execution from Anomalous Parent for PRT Cookie (via process_creation)
AWS CloudTrail: IAMUser STS GetSessionToken Use
Pivot detection · T1550.001 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.