Techniques
Sample rules
AWS STS AssumeRole Misuse
- source: sigma
- technicques:- t1548
- t1550
- t1550.001
 
Description
Identifies the suspicious use of AssumeRole. Attackers could move laterally and escalate privileges.
Detection logic
condition: selection
selection:
  userIdentity.sessionContext.sessionIssuer.type: Role
  userIdentity.type: AssumedRole
