Isai
b6847c7a48
[New Rule] AWS STS Role Chaining ( #4209 )
...
* [New Rule] AWS STS Role Chaining
Identifies role chaining activity. Role chaining is when you use one assumed role to assume a second role through the AWS CLI or API.
While this a recognized functionality in AWS, role chaining can be abused for privilege escalation if the subsequent assumed role provides additional privileges.
Role chaining can also be used as a persistence mechanism as each AssumeRole action results in a refreshed session token with a 1 hour maximum duration.
This rule looks for role chaining activity happening within a single account, to eliminate false positives produced by common cross-account behavior.
* adding metadata query fields
* removing index field
2024-10-30 12:18:04 -04:00
..
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-08-01 00:30:02 -04:00
2024-05-23 00:45:10 +05:30
2024-07-24 11:19:56 -04:00
2024-07-24 11:19:56 -04:00
2024-07-24 11:19:56 -04:00
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-06-28 20:42:36 -04:00
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-07-24 11:19:56 -04:00
2024-07-18 18:28:19 -04:00
2024-08-21 20:17:10 -04:00
2024-07-24 11:19:56 -04:00
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-10-09 21:08:38 -04:00
2024-09-24 09:32:12 -04:00
2024-10-09 21:08:38 -04:00
2024-07-24 11:19:56 -04:00
2024-07-31 16:55:49 -04:00
2024-05-23 00:45:10 +05:30
2024-10-09 15:25:36 -04:00
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-07-11 13:02:10 -04:00
2024-07-24 11:19:56 -04:00
2024-07-18 22:52:39 -04:00
2024-05-23 00:45:10 +05:30
2024-10-09 21:08:38 -04:00
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-07-11 13:02:10 -04:00
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-07-11 13:02:10 -04:00
2024-10-09 21:08:38 -04:00
2024-10-09 21:08:38 -04:00
2024-08-02 13:36:11 -03:00
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-10-09 21:08:38 -04:00
2024-05-23 00:45:10 +05:30
2024-07-24 11:19:56 -04:00
2024-07-31 15:52:59 -04:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2024-06-19 10:04:41 -04:00
2021-07-21 15:24:56 -06:00
2024-07-31 15:44:02 -04:00
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-07-24 11:19:56 -04:00
2024-07-24 11:19:56 -04:00
2024-10-09 21:08:38 -04:00
2024-07-24 11:19:56 -04:00
2024-05-23 00:45:10 +05:30
2024-07-11 13:02:10 -04:00
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-07-11 13:02:10 -04:00
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-07-24 11:19:56 -04:00
2024-10-09 21:08:38 -04:00
2024-10-09 21:08:38 -04:00
2024-10-09 21:08:38 -04:00
2024-08-20 11:53:46 -04:00
2024-05-23 00:45:10 +05:30
2024-05-23 00:45:10 +05:30
2024-10-30 12:18:04 -04:00
2024-08-20 11:53:46 -04:00
2024-05-23 00:45:10 +05:30