AWS CloudTrail: Suspicious SAML Provider Updates and AssumeRoleWithSAML

Flags CloudTrail activity involving SAML provider updates plus SAML role assumptions in AWS, which can enable backdoor access.

FreeUnreviewedSigmamediumv1
title: "AWS CloudTrail: Suspicious SAML Provider Updates and AssumeRoleWithSAML"
id: adbeaab2-7b0e-45d6-8d9e-a550b7b50dde
status: test
description: This rule identifies CloudTrail events where an AWS SAML provider is updated (IAM UpdateSAMLProvider) and SAML-based role assumptions occur (STS AssumeRoleWithSAML). Such activity can indicate an attacker establishing or changing SAML authentication paths to regain access or escalate privileges through SAML role usage. It relies on AWS CloudTrail telemetry capturing the specific IAM and STS API calls and correlates them within the same alert context.
references:
  - https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateSAMLProvider.html
  - https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRoleWithSAML.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/aws/cloudtrail/aws_susp_saml_activity.yml
author: Austin Songer, Huntrule Team
date: 2021-09-22
modified: 2022-12-18
tags:
  - attack.initial-access
  - attack.lateral-movement
  - attack.persistence
  - attack.privilege-escalation
  - attack.stealth
  - attack.t1078
  - attack.t1548
  - attack.t1550
  - attack.t1550.001
logsource:
  product: aws
  service: cloudtrail
detection:
  selection_sts:
    eventSource: sts.amazonaws.com
    eventName: AssumeRoleWithSAML
  selection_iam:
    eventSource: iam.amazonaws.com
    eventName: UpdateSAMLProvider
  condition: 1 of selection_*
falsepositives:
  - Automated processes that uses Terraform may lead to false positives.
  - SAML Provider could be updated by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
  - SAML Provider being updated from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: medium
license: DRL-1.1
related:
  - id: f43f5d2f-3f2a-4cc8-b1af-81fde7dbaf0e
    type: derived

What it detects

This rule identifies CloudTrail events where an AWS SAML provider is updated (IAM UpdateSAMLProvider) and SAML-based role assumptions occur (STS AssumeRoleWithSAML). Such activity can indicate an attacker establishing or changing SAML authentication paths to regain access or escalate privileges through SAML role usage. It relies on AWS CloudTrail telemetry capturing the specific IAM and STS API calls and correlates them within the same alert context.

Known false positives

  • Automated processes that uses Terraform may lead to false positives.
  • SAML Provider could be updated by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
  • SAML Provider being updated from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.