[THREAT-197] AWS Credential Misuse Rules (STS, CloudTrail) - #2032
Conversation
Add 4 new detection rules for AWS STS abuse and credential misuse patterns
- AWS.STS.GetCallerIdentity.TruffleHog — Detects credential validation by TruffleHog scanning tool
- AWS.STS.GetSessionToken.Misuse — Detects IAM users calling GetSessionToken for temporary credential generation
- AWS.Console.GetSigninToken.Abuse — Detects potential abuse of console federation sign-in tokens
- AWS.CloudTrail.IMDSCredentialExfiltration — Detects IMDS credential usage outside expected EC2 services
PR SummaryMedium Risk Overview Updates the AWS documentation/indexes ( Reviewed by Cursor Bugbot for commit 8487171. Bugbot is set up for automated code reviews on this repo. Configure here. |
There was a problem hiding this comment.
Cursor Bugbot has reviewed your changes and found 2 potential issues.
❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.
Reviewed by Cursor Bugbot for commit 15b4944. Configure here.

Background
Add 4 new detection rules for AWS STS abuse and credential misuse patterns
Changes
Testing