AWS CloudTrail Detects STS GetCallerIdentity Calls with TruffleHog User-Agent

Identifies TruffleHog-labeled STS GetCallerIdentity calls in AWS CloudTrail, indicating possible AWS key validation or enumeration.

FreeReviewedSigma · Medium · v5
Product
aws
Service
cloudtrail
Author
Adan Alvarez @adanalvarez (SigmaHQ), DRL 1.1
Published
2025-10-12
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies AWS STS GetCallerIdentity API calls in CloudTrail where the event originates from sts.amazonaws.com and the userAgent contains "TruffleHog." It flags this behavior because TruffleHog can be used to enumerate and validate potentially exposed AWS credentials by confirming whether they authenticate successfully. Detection relies on CloudTrail fields for eventSource, eventName, and userAgent.

Related detections3 linkedT1087.004 — drag to rearrange
Malicious Directory Enumeration With Recon Tooling User Agent via Azure AD Graph
Kubernetes RBAC SelfSubjectRulesReview Permission Enumeration Attempt
Azure sign-in logs: Detect AzureHound discovery tool via default User-Agent
AWS CloudTrail Detects STS GetCallerIdentity Calls with TruffleHog User-Agent
Pivot detection · T1087.004 · 3 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.