Title:
AWS STS AssumeRole Misuse
Status:
test
Description:Identifies the suspicious use of AssumeRole. Attackers could move laterally and escalate privileges.
References:
-https://github.com/elastic/detection-rules/pull/1214
-https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRole.html
Author: Austin Songer @austinsonger
Date: 2021-07-24
modified:2022-10-09
Tags:
- -'attack.lateral-movement'
- -'attack.privilege-escalation'
- -'attack.t1548'
- -'attack.t1550'
- -'attack.t1550.001'
Logsource:
- product: aws
- service: cloudtrail
Detection:
selection:
userIdentity.type:
'AssumedRole'
userIdentity.sessionContext.sessionIssuer.type:
'Role'
condition:
selection
Falsepositives:
-AssumeRole may be done by a system or network administrator. Verify whether the user identity, user agent, and/or hostname should be making changes in your environment.
-AssumeRole from unfamiliar users or hosts should be investigated. If known behavior is causing false positives, it can be exempted from the rule.
-Automated processes that uses Terraform may lead to false positives.
Level:
low