For the complete documentation index, see llms.txt. This page is also available as Markdown.

Multiple failed AWS assume role attempts

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

1 Hour

Deduplication Period

5 Days

Required Data

AWS Audit Log

Detection Modules

Cloud

ATT&CK Tactic

Discovery (TA0007), Privilege Escalation (TA0004)

ATT&CK Technique

Valid Accounts: Cloud Accounts (T1078.004), Abuse Elevation Control Mechanism: Temporary Elevated Cloud Access (T1548.005), Account Discovery: Cloud Account (T1087.004)

Severity

Informational

Description

An AWS identity performed an unusual high number of failed assume role attempts.

Attacker's Goals

Identify accessible roles and move laterally or escalate privileges within a cloud environment.

Investigative actions

  • Check if the attempting identity is aware of this activity and if its recent behavior appears suspicious.

  • Evaluate if the source IP address or user agent associated with these attempts is known or suspicious.

  • Verify if any successful assume role operations occurred from the same identity around the same time.

  • Review any additional activity from the specific roles the identity assumed.

Variations

Suspicious multiple failed AWS assume role attempts

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007), Privilege Escalation (TA0004)

ATT&CK Technique

Valid Accounts: Cloud Accounts (T1078.004), Abuse Elevation Control Mechanism: Temporary Elevated Cloud Access (T1548.005), Account Discovery: Cloud Account (T1087.004)

Severity

Medium

Description

An AWS identity performed an unusual high number of failed assume role attempts.

Attacker's Goals

Identify accessible roles and move laterally or escalate privileges within a cloud environment.

Investigative actions

  • Check if the attempting identity is aware of this activity and if its recent behavior appears suspicious.

  • Evaluate if the source IP address or user agent associated with these attempts is known or suspicious.

  • Verify if any successful assume role operations occurred from the same identity around the same time.

  • Review any additional activity from the specific roles the identity assumed.

Was this helpful?