AWS CloudTrail: Suspicious SAML Provider Updates and AssumeRoleWithSAML
Flags CloudTrail activity involving SAML provider updates plus SAML role assumptions in AWS, which can enable backdoor access.
FreeUnreviewedSigmamediumv1
aws-cloudtrail-suspicious-saml-provider-updates-and-assumerolewithsaml-f43f5d2f
title: "AWS CloudTrail: Suspicious SAML Provider Updates and AssumeRoleWithSAML"
id: adbeaab2-7b0e-45d6-8d9e-a550b7b50dde
status: test
description: This rule identifies CloudTrail events where an AWS SAML provider is updated (IAM UpdateSAMLProvider) and SAML-based role assumptions occur (STS AssumeRoleWithSAML). Such activity can indicate an attacker establishing or changing SAML authentication paths to regain access or escalate privileges through SAML role usage. It relies on AWS CloudTrail telemetry capturing the specific IAM and STS API calls and correlates them within the same alert context.
references:
- https://docs.aws.amazon.com/IAM/latest/APIReference/API_UpdateSAMLProvider.html
- https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRoleWithSAML.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/cloud/aws/cloudtrail/aws_susp_saml_activity.yml
author: Austin Songer, Huntrule Team
date: 2021-09-22
modified: 2022-12-18
tags:
- attack.initial-access
- attack.lateral-movement
- attack.persistence
- attack.privilege-escalation
- attack.stealth
- attack.t1078
- attack.t1548
- attack.t1550
- attack.t1550.001
logsource:
product: aws
service: cloudtrail
detection:
selection_sts:
eventSource: sts.amazonaws.com
eventName: AssumeRoleWithSAML
selection_iam:
eventSource: iam.amazonaws.com
eventName: UpdateSAMLProvider
condition: 1 of selection_*
falsepositives:
- Automated processes that uses Terraform may lead to false positives.
- SAML Provider could be updated by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
- SAML Provider being updated from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
level: medium
license: DRL-1.1
related:
- id: f43f5d2f-3f2a-4cc8-b1af-81fde7dbaf0e
type: derived
What it detects
This rule identifies CloudTrail events where an AWS SAML provider is updated (IAM UpdateSAMLProvider) and SAML-based role assumptions occur (STS AssumeRoleWithSAML). Such activity can indicate an attacker establishing or changing SAML authentication paths to regain access or escalate privileges through SAML role usage. It relies on AWS CloudTrail telemetry capturing the specific IAM and STS API calls and correlates them within the same alert context.
Known false positives
- Automated processes that uses Terraform may lead to false positives.
- SAML Provider could be updated by a system administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
- SAML Provider being updated from unfamiliar users should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.