logo

Control Tower Pivoting Using the Default Role

ID: f3a2bfb8-70ee-5788-aecc-63090761f378

STIX ID: report--f3a2bfb8-70ee-5788-aecc-63090761f378

Feed Name: TrustedSec blog

Threat Score
65/100

Date Published: 2025-03-19

Date Updated: 2026-05-01

...
...

This report analyzes a pivot technique in AWS Control Tower where an attacker with access to the Management account can assume the AWSControlTowerExecution role in Member accounts due to Control Tower's default trust relationship and permissive resource statements; it details how to test for this condition, how to detect sts:AssumeRole attempts, and recommends defenses (permissions boundaries, tightening policies and Permission Sets) and remediation steps (in-line deny policies), while noting limitations such as Control Tower drift and session-duration behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.