Skip to content

[THREAT-197] AWS Credential Misuse Rules (STS, CloudTrail) - #2032

Merged
arielkr256 merged 5 commits into
developfrom
aws-sts-rules
Apr 20, 2026
Merged

arielkr256 merged 5 commits into
developfrom
aws-sts-rules

Conversation

@alessandrarizzo

Copy link
Copy Markdown
Contributor

Background

Add 4 new detection rules for AWS STS abuse and credential misuse patterns

Changes

- AWS.STS.GetCallerIdentity.TruffleHog — Detects credential validation by TruffleHog scanning tool
- AWS.STS.GetSessionToken.Misuse — Detects IAM users calling GetSessionToken for temporary credential generation
- AWS.Console.GetSigninToken.Abuse — Detects potential abuse of console federation sign-in tokens
- AWS.CloudTrail.IMDSCredentialExfiltration — Detects IMDS credential usage outside expected EC2 services

Testing

Add 4 new detection rules for AWS STS abuse and credential misuse patterns
    - AWS.STS.GetCallerIdentity.TruffleHog — Detects credential validation by TruffleHog scanning tool
    - AWS.STS.GetSessionToken.Misuse — Detects IAM users calling GetSessionToken for temporary credential generation
    - AWS.Console.GetSigninToken.Abuse — Detects potential abuse of console federation sign-in tokens
    - AWS.CloudTrail.IMDSCredentialExfiltration — Detects IMDS credential usage outside expected EC2 services
@alessandrarizzo
alessandrarizzo requested a review from a team as a code owner April 17, 2026 16:38
@alessandrarizzo alessandrarizzo added the rules Real-time log data detections label Apr 17, 2026
@cursor

cursor Bot commented Apr 17, 2026 •

Copy link
Copy Markdown

PR Summary

Medium Risk
Adds four new experimental CloudTrail detections that may materially change alert volume and require tuning (notably the high-severity IMDS exfiltration rule), but does not modify existing rule logic or core platform code.

Overview
Adds four new experimental AWS CloudTrail detection rules for credential-misuse patterns: suspicious GetSigninToken console federation requests (excluding known SSO user agents), IMDS-derived instance credentials used from public IPs/outside expected internal services, GetCallerIdentity calls with TruffleHog user agents, and GetSessionToken calls initiated by IAM users.

Updates the AWS documentation/indexes (alpha-index.md, aws.md) and detection-coverage.json to include these new rules, along with rule metadata, runbooks, and test fixtures in the corresponding YAMLs.

Reviewed by Cursor Bugbot for commit 8487171. Bugbot is set up for automated code reviews on this repo. Configure here.

Comment thread rules/aws_cloudtrail_rules/aws_imds_credential_exfiltration.py Outdated
Comment thread rules/aws_cloudtrail_rules/aws_imds_credential_exfiltration.py Outdated

@cursor cursor Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Cursor Bugbot has reviewed your changes and found 2 potential issues.

Fix All in Cursor

❌ Bugbot Autofix is OFF. To automatically fix reported issues with cloud agents, enable autofix in the Cursor dashboard.

Reviewed by Cursor Bugbot for commit 15b4944. Configure here.

Comment thread rules/aws_cloudtrail_rules/aws_imds_credential_exfiltration.py Outdated
Comment thread rules/aws_cloudtrail_rules/aws_imds_credential_exfiltration.py
@arielkr256
arielkr256 added this pull request to the merge queue Apr 20, 2026
Merged via the queue into develop with commit ec10094 Apr 20, 2026
18 checks passed
@arielkr256
arielkr256 deleted the aws-sts-rules branch April 20, 2026 16:57
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

rules Real-time log data detections

3 participants