logo

The many ways to obtain credentials in AWS

ID: 50fe145e-7659-512b-99cb-389406c87631

STIX ID: report--50fe145e-7659-512b-99cb-389406c87631

Feed Name: Wiz Blog

Date Published: 2024-12-20

Date Updated: 2026-05-01

...
...

This article catalogs the many ways AWS services and the SDK credential chain provision and expose IAM role credentials—ranging from environment variables, credential files, IMDSv2 (IPv4/IPv6), ECS/EKS credential endpoints, EKS Pod Identity and IRSA, SSM Default Host Management and hybrid activation, IoT AssumeRoleWithCertificate, IAM Roles Anywhere (including PKCS#11), Cognito GetCredentialsForIdentity, and Datasync’s certificate-based access. It emphasizes that multiple IAM principals can be reachable from a single host and that defenders must understand these paths to detect and prevent attacker credential harvesting.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.