Suspicious IMDS IAM Credential Retrieval From Container Workload

PremiumReviewedSigma · Medium · v1
Category
process_creation
Author
HuntRule
Published
2026-06-02
Updated
2026-08-28

ATT&CK techniques

Initial Access → Cred Access
  1. Recon

  2. Resource Dev

  3. Execution

  4. Discovery

  5. Lateral Movement

  6. Collection

  7. C2

  8. Exfiltration

  9. Impact

What it detects

This rule detects a command line that queries the EC2 Instance Metadata Service credentials path 169.254.169.254 latest meta-data iam security-credentials to retrieve IAM role credentials. In EKS clusters where IMDSv2 is not enforced, a compromised pod uses this request to steal the worker node role credentials and escalate beyond the pod identity. This matters because it lets container workloads impersonate the underlying node and reach broader AWS permissions.

Related detections9 linkedT1552.005 — drag to rearrange
Suspicious AWS EC2 Windows Password Retrieval via GetPasswordData
Possible Jamf Pro SSRF Exploitation via eduFeatureSettingsTest imageUrl (via webserver)
Possible WebSphere Portal SSRF via Proxy Servlet targeting Cloud Metadata (CVE-2021-27748) (via webserver)
Possible SSRF to AWS Metadata via Workspace One UEM BlobHandler CVE-2021-22054
Possible SSRF via Gatsby _gatsby File Proxy Endpoint
Possible SSRF to Cloud Metadata via Nuxt _ipx Image Proxy
Suspicious Cloud Instance Metadata Access from Command Line (via process_creation)
Suspicious Access to Cloud and Database Credential Files via Process
Possible Super SSRF via Jira Server nativemobile batch CVE-2022-26135
Suspicious IMDS IAM Credential Retrieval From Container Workload
Pivot detection · T1552.005 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.