AWS STS AssumeRole Misuse

 Original Source: [Sigma source]
Title: AWS STS AssumeRole Misuse
Status: test
Description:Identifies the suspicious use of AssumeRole. Attackers could move laterally and escalate privileges.
References:
  -https://github.com/elastic/detection-rules/pull/1214
  -https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRole.html
Author: Austin Songer @austinsonger
Date: 2021-07-24
modified:2022-10-09
Tags:
  • -'attack.lateral-movement'
  • -'attack.privilege-escalation'
  • -'attack.t1548'
  • -'attack.t1550'
  • -'attack.t1550.001'
Logsource:
  • product: aws
  • service: cloudtrail
Detection:
  selection:
    userIdentity.type: 'AssumedRole'
    userIdentity.sessionContext.sessionIssuer.type: 'Role'
  condition:selection
Falsepositives:
  -AssumeRole may be done by a system or network administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
  -AssumeRole from unfamiliar users or hosts should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
  -Automated processes that uses Terraform may lead to false positives.
Level: low