AWS Console Session Traceability: How Attackers Obfuscate Identity Through the AWS Console
ID: 6e7d4bfe-5d7b-5085-80bf-9ee99b748243
STIX ID: report--6e7d4bfe-5d7b-5085-80bf-9ee99b748243
Feed Name: Wiz Blog
This report introduces “Console Conceal,” a technique that exploits an AWS Console logging quirk to obscure the originating IAM user behind CloudTrail events after role assumption, complicating investigations when SourceIdentity is not enabled. It explains how attackers can manipulate role session names and use federated console sessions so actions are logged with different temporary access keys than those in the AssumeRole event, breaking straightforward attribution. The report recommends enabling AWS SourceIdentity to restore immutable traceability across role chains and provides a practical heuristic (principalId/session name, role name, and session creation time) to correlate console actions back to AssumeRole events when SourceIdentity is absent.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
