Techniques
Sample rules
AWS STS AssumeRole Misuse
- source: sigma
- technicques:
- t1548
- t1550
- t1550.001
Description
Identifies the suspicious use of AssumeRole. Attackers could move laterally and escalate privileges.
Detection logic
condition: selection
selection:
userIdentity.sessionContext.sessionIssuer.type: Role
userIdentity.type: AssumedRole