Analytics
Informational
✕
Multiple failed AWS assume role attempts
An AWS identity performed an unusual high number of failed assume role attempts.
- Module:
- Cortex Cloud
- Licensed by:
- Cloud Runtime Security (CRS)
- Data source:
- AWS Audit Log
ATT&CK tactics: Discovery (TA0007) Privilege Escalation (TA0004)
ATT&CK techniques: Valid Accounts: Cloud Accounts (T1078.004) Abuse Elevation Control Mechanism: Temporary Elevated Cloud Access (T1548.005) Account Discovery: Cloud Account (T1087.004)
Attacker's goals:
Identify accessible roles and move laterally or escalate privileges within a cloud environment.
Investigative actions:
Check if the attempting identity is aware of this activity and if its recent behavior appears suspicious. Evaluate if the source IP address or user agent associated with these attempts is known or suspicious. Verify if any successful assume role operations occurred from the same identity around the same time. Review any additional activity from the specific roles the identity assumed.
- Test period:
- 1 Hour
- Deduplication:
- 5 Days
1 variation:
- Suspicious multiple failed AWS assume role attempts Medium (parent: Informational)