Skip to content

AssumeRoleWithSAML

AWS

AssumeRoleWithSAML

service: AWS - STS
techniques:

Event

Uses a SAML assertion from a trusted provider to obtain a role session; the caller does not need existing AWS credentials. Session duration is limited by the request, the role setting, and the assertion’s SessionNotOnOrAfter value. The default API session duration is one hour; requested durations range from 15 minutes to the role maximum, up to 12 hours. Optional session policies restrict role-policy permissions rather than adding grants.

Security Context

Normal SSO or workload federation generates this event. T1078.004 applies contextually to abuse of cloud identities; T1550.001 requires evidence of unauthorized use of authentication material. A successful exchange does not itself establish token theft, cross-account lateral movement, or the privileges implied by a role name.

Log Source

AWS CloudTrail management event with eventSource: sts.amazonaws.com and eventName: AssumeRoleWithSAML. Check errorCode and errorMessage before treating an attempt as successful; responseElements: null alone does not indicate failure. CloudTrail logs federation requests, but some malformed unauthenticated requests may not be recorded. Do not equate absence with absence of attempted abuse.

Key Fields

FieldInvestigation value
userIdentityFederated identity and provider context; corroborate with identity-provider records.
requestParameters.roleArnTarget role; inspect its event-time trust and permissions.
responseElements.assumedRoleUser, credentials.accessKeyIdRole-session and temporary-key correlation identifiers, not proof of subsequent use.
responseElementsSubject, audience, issuer/provider, and expiration when present; field availability varies.
eventTime, recipientAccountId, eventID, requestIDTimeline, account, and correlation identifiers.

What to Investigate

  1. Confirm the outcome and match the caller, target, and timing to an approved workflow. Review failed attempts separately.
  2. Correlate assertion identity and timing with IdP authentication logs. Hardware MFA and the end-user source address cannot be inferred from AWS Internal.
  3. Review role trust at the event time, session policies, tags, and effective permissions. Compare requested duration with the actual expiration.
  4. Track downstream role-session API activity and recent trust-policy changes. Verify authorization and token provenance before labeling routine federation malicious.

Sample Event

Synthetic scenario. An illustrative corporate SAML exchange returns a GraphornAdminRole session. AWS Internal is a sample source value, not a universal SAML network path or proof of hardware MFA.

Exact CloudTrail nesting, field presence, redaction, and timestamp formatting remain unverified against captured logs. Credential/token placeholders and metadata placeholders are illustrative, not usable credentials or complete provider metadata.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "SAMLUser",
"principalId": "Cdddddd0EXAMPLEsamlIDP=:hermione@fantasticlogs.cloud",
"userName": "hermione@fantasticlogs.cloud",
"identityProvider": "Cdddddd0EXAMPLEsamlIDP="
},
"eventTime": "2026-04-15T13:42:11Z",
"eventSource": "sts.amazonaws.com",
"eventName": "AssumeRoleWithSAML",
"awsRegion": "us-east-1",
"sourceIPAddress": "AWS Internal",
"userAgent": "aws-internal/3 aws-sdk-java/1.12.479 Linux/5.10.186-157.751.amzn2int.x86_64 OpenJDK_64-Bit_Server_VM/17.0.7+11 java/17.0.7 kotlin/1.3.72 vendor/Amazon.com_Inc. cfg/retry-mode/standard",
"requestParameters": {
"sAMLAssertionID": "_c0046cEXAMPLEb9d4b8eEXAMPLE2619aEXAMPLE",
"roleSessionName": "hermione@fantasticlogs.cloud",
"principalTags": {
"Department": "SecurityEngineering",
"Email": "hermione@fantasticlogs.cloud"
},
"transitiveTagKeys": [
"Department",
"Email"
],
"roleArn": "arn:aws:iam::555123456789:role/GraphornAdminRole",
"principalArn": "arn:aws:iam::555123456789:saml-provider/FantasticLogsOkta",
"durationSeconds": 3600
},
"responseElements": {
"credentials": {
"accessKeyId": "ASIAGRAPH0RNSESS1ON1",
"sessionToken": "<encoded session token blob>",
"expiration": "Apr 15, 2026, 2:42:11 PM"
},
"assumedRoleUser": {
"assumedRoleId": "AROAGRAPH0RNADM1NR01:hermione@fantasticlogs.cloud",
"arn": "arn:aws:sts::555123456789:assumed-role/GraphornAdminRole/hermione@fantasticlogs.cloud"
},
"packedPolicySize": 1,
"subject": "hermione@fantasticlogs.cloud",
"subjectType": "transient",
"issuer": "https://fantasticlogs.okta.com",
"audience": "https://signin.aws.amazon.com/saml",
"nameQualifier": "Cdddddd0EXAMPLEsamlIDP="
},
"requestID": "90000000-0000-4000-8000-000001101110",
"eventID": "90000000-0000-4000-8000-000001101111",
"readOnly": true,
"resources": [
{
"accountId": "555123456789",
"type": "AWS::IAM::Role",
"ARN": "arn:aws:iam::555123456789:role/GraphornAdminRole"
},
{
"accountId": "555123456789",
"type": "AWS::IAM::SAMLProvider",
"ARN": "arn:aws:iam::555123456789:saml-provider/FantasticLogsOkta"
}
],
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sts.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Initial Access Privilege Escalation Lateral Movement Stealth

Techniques:
  • T1078.004 — Cloud Accounts — Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of r...
  • T1550.001 — Application Access Token — Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.