AWS STS temporary credentials were generated
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
5 Days
Required Data
AWS Audit Log
Detection Modules
Cloud
ATT&CK Tactic
Persistence (TA0003), Initial Access (TA0001), Credential Access (TA0006)
ATT&CK Technique
Valid Accounts: Cloud Accounts (T1078.004), Trusted Relationship (T1199), Forge Web Credentials (T1606)
Severity
Informational
Description
AWS STS temporary credentials were generated for an AWS identity.
Attacker's Goals
Gain access and persistence to AWS account.
Investigative actions
Check which operation executed with the new credentials.
Was this helpful?
