Suspicious AWS GetFederationToken Console Access by JavaGhost (via cloudtrail)

PremiumReviewedSigma · Medium · v1
Product
aws
Service
cloudtrail
Author
HuntRule
Published
2026-05-30
Updated
2026-08-28

ATT&CK techniques

Initial Access → Lateral Movement

What it detects

This rule detects use of the STS GetFederationToken API, which JavaGhost abuses to mint federated console sign-in sessions from stolen long-term IAM credentials. Generating console access via federation lets the actor operate interactively in the AWS account while blending with legitimate application-token usage.

Related detections9 linkedT1550.001 — drag to rearrange
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
Suspicious AWS STS Session Token and Role Chaining Abuse via CloudTrail (via aws)
Suspicious AWS STS Role Chaining From Temporary Session Credentials (via cloudtrail)
AWS CloudTrail Alert for Suspicious SAML Role Assumption and SAML Provider Updates
AWS CloudTrail: Suspicious STS AssumeRole sessions from Role-issued principals
AWS CloudTrail: IAMUser STS GetSessionToken Use
Suspicious Kubernetes Service Account Token Generation via kubectl
Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365
Suspicious AWS GetFederationToken Console Access by JavaGhost (via cloudtrail)
Pivot detection · T1550.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.