AssumeRoleWithWebIdentity
AssumeRoleWithWebIdentity
Event
Uses a supported web-identity token, commonly an OIDC token, to obtain a role session without existing AWS credentials. Trust conditions, token validation, and role settings constrain the exchange. The default API session duration is one hour; requested durations range from 15 minutes to the role maximum, up to 12 hours. Optional session policies restrict role-policy permissions rather than adding grants.
Security Context
Normal SSO or workload federation generates this event. T1078.004 applies contextually to abuse of cloud identities; T1550.001 requires evidence of unauthorized use of authentication material. A successful exchange does not itself establish token theft, cross-account lateral movement, or the privileges implied by a role name.
Log Source
AWS CloudTrail management event with eventSource: sts.amazonaws.com and eventName: AssumeRoleWithWebIdentity. Check errorCode and errorMessage before treating an attempt as successful; responseElements: null alone does not indicate failure. CloudTrail logs federation requests, but some malformed unauthenticated requests may not be recorded. Do not equate absence with absence of attempted abuse.
Key Fields
| Field | Investigation value |
|---|---|
userIdentity | Federated identity and provider context; corroborate with identity-provider records. |
requestParameters.roleArn | Target role; inspect its event-time trust and permissions. |
responseElements.assumedRoleUser, credentials.accessKeyId | Role-session and temporary-key correlation identifiers, not proof of subsequent use. |
responseElements | Subject, audience, issuer/provider, and expiration when present; field availability varies. |
eventTime, recipientAccountId, eventID, requestID | Timeline, account, and correlation identifiers. |
What to Investigate
- Confirm the outcome and match the caller, target, and timing to an approved workflow. Review failed attempts separately.
- Correlate issuer, audience, and subject with the workload run. A subject naming a branch does not prove the trust policy was restricted to that branch.
- Review role trust at the event time, session policies, tags, and effective permissions. Compare requested duration with the actual expiration.
- Track downstream role-session API activity and recent trust-policy changes. Verify authorization and token provenance before labeling routine federation malicious.
Sample Event
Synthetic scenario. An illustrative GitHub Actions exchange returns an OccamyPipelineRole session for a main-branch subject. The trust policy, triggering commit, and workflow authorization require separate evidence.
Exact CloudTrail nesting, field presence, redaction, and timestamp formatting remain unverified against captured logs. Credential/token placeholders and metadata placeholders are illustrative, not usable credentials or complete provider metadata.
{ "eventVersion": "1.09", "userIdentity": { "type": "WebIdentityUser", "principalId": "token.actions.githubusercontent.com:sts.amazonaws.com:repo:fantasticlogs/occamy:ref:refs/heads/main", "userName": "repo:fantasticlogs/occamy:ref:refs/heads/main", "identityProvider": "arn:aws:iam::555123456789:oidc-provider/token.actions.githubusercontent.com" }, "eventTime": "2026-04-15T15:18:42Z", "eventSource": "sts.amazonaws.com", "eventName": "AssumeRoleWithWebIdentity", "awsRegion": "us-east-1", "sourceIPAddress": "198.51.100.200", "userAgent": "aws-actions-configure-aws-credentials/4.0.0 aws-sdk-nodejs/2.1525.0 linux/v20.10.0 callback", "requestParameters": { "roleArn": "arn:aws:iam::555123456789:role/OccamyPipelineRole", "roleSessionName": "GitHubActions-occamy-deploy-12345", "durationSeconds": 3600 }, "responseElements": { "credentials": { "accessKeyId": "ASIA0CCAMYP1PESESS01N", "sessionToken": "<encoded session token blob>", "expiration": "Apr 15, 2026, 4:18:42 PM" }, "subjectFromWebIdentityToken": "repo:fantasticlogs/occamy:ref:refs/heads/main", "assumedRoleUser": { "assumedRoleId": "AROAOCCAMYP1PEL1NE02:GitHubActions-occamy-deploy-12345", "arn": "arn:aws:sts::555123456789:assumed-role/OccamyPipelineRole/GitHubActions-occamy-deploy-12345" }, "provider": "arn:aws:iam::555123456789:oidc-provider/token.actions.githubusercontent.com", "audience": "sts.amazonaws.com" }, "additionalEventData": { "identityProviderConnectionVerificationMethod": "IAMTrustStore" }, "requestID": "90000000-0000-4000-8000-000001110000", "eventID": "90000000-0000-4000-8000-000001110001", "readOnly": true, "resources": [ { "accountId": "555123456789", "type": "AWS::IAM::Role", "ARN": "arn:aws:iam::555123456789:role/OccamyPipelineRole" } ], "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "sts.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Initial Access Privilege Escalation Lateral Movement Stealth
- T1078.004 — Cloud Accounts — Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of r...
- T1550.001 — Application Access Token — Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.