Suspicious AWS SAML Provider Enumeration for Federation Recon (via cloudtrail)

PremiumReviewedSigma · Medium · v1
Product
aws
Service
cloudtrail
Author
HuntRule
Published
2026-06-10
Updated
2026-08-28

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects enumeration of configured SAML identity providers through the IAM ListSAMLProviders call, a discovery step Muddled Libra performs to understand federation and plan cross tenant identity abuse. Because this API is rarely called in day to day operations, its use by an interactive or unfamiliar principal points to adversary reconnaissance of the trust configuration.

Related detections3 linkedT1580 — drag to rearrange
Suspicious SES Account Sending Enablement and Identity Verification via CloudTrail
Suspicious Boto3 Kali Linux User Agent in AWS CloudTrail Reconnaissance (via cloudtrail)
AWS CloudTrail: Potential S3 Bucket Enumeration via ListBuckets by Non-AssumedRole
Suspicious AWS SAML Provider Enumeration for Federation Recon (via cloudtrail)
Pivot detection · T1580 · 3 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.