Suspicious AWS Federated Console Login From Programmatic Credentials

PremiumReviewedSigma · Medium · v1
Product
aws
Service
cloudtrail
Author
HuntRule
Published
2026-08-04
Updated
2026-08-28

ATT&CK techniques

Initial Access → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Execution

  4. Cred Access

  5. Discovery

  6. Collection

  7. C2

  8. Exfiltration

  9. Impact

What it detects

This rule detects an AWS Management Console sign-in performed by a federated user identity which indicates a session created from long-term or temporary programmatic credentials rather than an IAM user or SSO login. Wiz shows attackers exchange stolen keys for a federated console session to obfuscate their real identity and break session traceability. This matters because it lets an adversary operate interactively in the console while evading the account owner attribution normally provided by ConsoleLogin.

Related detections9 linkedT1550.001 — drag to rearrange
Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
Suspicious AWS STS Session Token and Role Chaining Abuse via CloudTrail (via aws)
Suspicious AWS GetFederationToken Console Access by JavaGhost (via cloudtrail)
Suspicious AWS STS Role Chaining From Temporary Session Credentials (via cloudtrail)
Suspicious Kubernetes Service Account Token Generation via kubectl
Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365
Suspicious browsercore Execution from Anomalous Parent for PRT Cookie (via process_creation)
Suspicious AWS SSO Account Role Enumeration via ListAccountRoles (via cloudtrail)
Suspicious SES Account Sending Enablement and Identity Verification via CloudTrail
Suspicious AWS Federated Console Login From Programmatic Credentials
Pivot detection · T1550.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.