LoFP LoFP / aws federated account

TitleTags
attacks using a golden saml or saml assertion hijacks or forgeries are very difficult to detect as accessing cloud providers with these assertions looks exactly like normal access, however things such as source ip sourceipaddress user, and principal targeted at receiving cloud provider along with endpoint credential access and abuse detection searches can provide the necessary context to detect these attacks.
updating a saml provider or creating a new one may not necessarily be malicious however it needs to be closely monitored.