Exploring AWS STS AssumeRoot
ID: 06fa96b4-bc24-525b-bf3c-f1f5197d30f4
STIX ID: report--06fa96b4-bc24-525b-bf3c-f1f5197d30f4
Feed Name: Elastic Security Labs
This article analyzes AWS STS’s new AssumeRoot API, demonstrating how an attacker with compromised admin-level IAM credentials could obtain temporary root credentials for a member account and create a root login profile (e.g., via IAMCreateRootUserPassword) using Terraform and Python. It provides Elastic SIEM hunting and detection approaches (CloudTrail-based ES|QL/KQL queries for unusual AssumeRoot and CreateLoginProfile activity) and offers hardening guidance, including strict least-privilege controls on AssumeRoot task policies, organization-wide CloudTrail visibility, MFA enforcement, and use of RCPs; while no in-the-wild abuse is reported, the piece highlights proactive detection and defense for this living-off-the-cloud technique.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
