Suspicious IAM CreateLoginProfile For Root User via AWS AssumeRoot Abuse

PremiumReviewedSigma · High · v1
Product
aws
Service
cloudtrail
Author
HuntRule
Published
2026-05-20
Updated
2026-08-28

ATT&CK techniques

Initial Access → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Execution

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule detects an IAM CreateLoginProfile event that establishes console access for the root user which follows abuse of STS AssumeRoot to plant durable access in a member account. Adversaries create a root login profile to convert temporary root credentials into persistent account takeover.

Related detections9 linkedT1078.004 — drag to rearrange
Malicious Assignment of a Privileged Azure AD Role (via auditlogs)
Possible Credential Stuffing Blocked by Conditional Access in Microsoft 365
Suspicious SES Account Sending Enablement and Identity Verification via CloudTrail
Possible Stolen AWS Credential Validation via STS GetCallerIdentity
Suspicious AWS Federated Console Login From Programmatic Credentials
Suspicious M365 Legacy Authentication via BAV2ROPC Client via m365
Suspicious Entra Cross-Tenant Access or External User Invitation via Azure Audit (via azure)
Suspicious STS AssumeRole With Exfil Session Name via CloudTrail (via cloudtrail)
Suspicious AWS Console Login Without MFA
Suspicious IAM CreateLoginProfile For Root User via AWS AssumeRoot Abuse
Pivot detection · T1078.004 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.