logo

AWS Console Session Traceability: How Attackers Obfuscate Identity Through the AWS Console

ID: 6e7d4bfe-5d7b-5085-80bf-9ee99b748243

STIX ID: report--6e7d4bfe-5d7b-5085-80bf-9ee99b748243

Feed Name: Wiz Blog

Date Published: 2024-08-22

Date Updated: 2026-05-01

...
...

This report introduces “Console Conceal,” a technique that exploits an AWS Console logging quirk to obscure the originating IAM user behind CloudTrail events after role assumption, complicating investigations when SourceIdentity is not enabled. It explains how attackers can manipulate role session names and use federated console sessions so actions are logged with different temporary access keys than those in the AssumeRole event, breaking straightforward attribution. The report recommends enabling AWS SourceIdentity to restore immutable traceability across role chains and provides a practical heuristic (principalId/session name, role name, and session creation time) to correlate console actions back to AssumeRole events when SourceIdentity is absent.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.