Suspicious AWS SSO Token Creation and Role Credential Retrieval (via cloudtrail)

PremiumReviewedSigma · Medium · v1
Product
aws
Service
cloudtrail
Author
HuntRule
Published
2026-05-10
Updated
2026-08-28

ATT&CK techniques

Defense Evasion → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Discovery

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule detects the AWS SSO CreateToken and GetRoleCredentials calls against sso.amazonaws.com, the API sequence Red Canary described adversaries using to replay cached SSO tokens stolen from the .aws sso cache. When these calls originate from multiple IP addresses in a short window they indicate an actor exchanging a stolen access token for STS role credentials.

Related detections9 linkedT1550.001 — drag to rearrange
Malicious PRT Token Forging via AADInternals (via ps_script)
Suspicious Entra Device Code Authentication with Office Client and Automated User Agent
Malicious OAuth Application Granted Full Mailbox and EWS Permissions (via m365)
Suspicious Kubernetes Service Account Token Generation via kubectl
Suspicious browsercore Execution from Anomalous Parent for PRT Cookie (via process_creation)
Suspicious GAM OAuth Token Enumeration via Process Creation
Suspicious AWS SSO Account Role Enumeration via ListAccountRoles (via cloudtrail)
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious Device Registration Following OAuth Token Theft
Suspicious AWS SSO Token Creation and Role Credential Retrieval (via cloudtrail)
Pivot detection · T1550.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.