AWSCloudTrail - STS Token Suspicious Activity from Lambda

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Identifies STS token usage from Lambda that originates outside AWS IP ranges, which may indicate token hijacking via SSRF or credential theft.

Attribute Value
Type Hunting Query
Solution Amazon Web Services
ID 70a6e84f-6f3b-4ce1-83d6-ea6df9e7a9dd
Severity High
Tactics CredentialAccess, LateralMovement
Techniques T1528, T1550.001
Required Connectors AWS
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
AWSCloudTrail

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries · Back to Amazon Web Services