logo

Exploring AWS STS AssumeRoot

ID: 06fa96b4-bc24-525b-bf3c-f1f5197d30f4

STIX ID: report--06fa96b4-bc24-525b-bf3c-f1f5197d30f4

Feed Name: Elastic Security Labs

Date Published: 2024-12-09

Date Updated: 2026-04-27

...
...

This article analyzes AWS STS’s new AssumeRoot API, demonstrating how an attacker with compromised admin-level IAM credentials could obtain temporary root credentials for a member account and create a root login profile (e.g., via IAMCreateRootUserPassword) using Terraform and Python. It provides Elastic SIEM hunting and detection approaches (CloudTrail-based ES|QL/KQL queries for unusual AssumeRoot and CreateLoginProfile activity) and offers hardening guidance, including strict least-privilege controls on AssumeRoot task policies, organization-wide CloudTrail visibility, MFA enforcement, and use of RCPs; while no in-the-wild abuse is reported, the piece highlights proactive detection and defense for this living-off-the-cloud technique.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.