Skip to content

ConsoleLogin

AWS

ConsoleLogin

service: AWS - SignIn
techniques:

Event

ConsoleLogin records an AWS Management Console sign-in attempt. Inspect responseElements.ConsoleLogin for success or failure; this event is a sign-in record, not a resource-changing API call. AWS sign-in examples.

Security Context

A successful sign-in from an unusual context can be a starting point for investigating account compromise. A failed attempt does not establish that the caller obtained access.

Legitimate uses: routine interactive administration, approved emergency access, and sign-ins from new corporate egress addresses. An unfamiliar IP or absent MFA indication needs identity and workflow context.

Mapping rationale: unauthorized use of a valid cloud account can support initial access or activity that blends into normal administration. Confirm the authentication outcome and subsequent behavior before applying that interpretation.

Log Source

Search CloudTrail for eventSource: signin.amazonaws.com, eventName: ConsoleLogin, and eventType: AwsConsoleSignIn. The recorded Region depends on user type and sign-in endpoint, so do not search only one Region based on the resources the user later accessed. Federated examples also have different field shapes; this page’s sample illustrates an IAM user. AWS sign-in logging.

Key Fields

FieldInvestigation use
responseElements.ConsoleLoginDetermine whether this attempt succeeded or failed.
userIdentity.type and userIdentity.arnEstablish the identity type and account context where available.
additionalEventData.MFAUsedAssess the MFA indication for this sign-in flow; do not generalize one flow’s fields to every identity system.
sourceIPAddress and userAgentCompare origin and client with expected access patterns.
eventTime and awsRegionCorrelate attempts and identify the regional record.

What to Investigate

  1. Separate failures from successes and compare nearby attempts for the same identity. Check whether a success followed an unusual burst of failures.
  2. Confirm the identity and expected sign-in path with account owners or identity records. Do not infer a physical location solely from an IP address.
  3. Correlate later management activity by identity and time, using additional session evidence when available. Look for CreateAccessKey, permission changes, or StopLogging.
  4. Document the limits of the correlation: a matching user and time window alone do not uniquely identify one console session, and this record does not show everything the user did afterward.

Sample Event

Synthetic scenario — successful IAM user sign-in. Hermione signs in with an MFA indication. Success and MFAUsed: Yes describe this attempt; they do not independently prove that the activity was authorized.

{
"eventVersion": "1.08",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDAHERM10NE000ADM1N",
"arn": "arn:aws:iam::555123456789:user/hermione",
"accountId": "555123456789",
"userName": "hermione"
},
"eventTime": "2026-04-15T13:42:11Z",
"eventSource": "signin.amazonaws.com",
"eventName": "ConsoleLogin",
"awsRegion": "us-east-1",
"sourceIPAddress": "198.51.100.42",
"userAgent": "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36",
"requestParameters": null,
"responseElements": {
"ConsoleLogin": "Success"
},
"additionalEventData": {
"LoginTo": "https://console.aws.amazon.com/console/home?hashArgs=%23&isauthcode=true&state=hashArgsFromTB_us-east-1_examplee9aba7f8",
"MobileVersion": "No",
"MFAIdentifier": "arn:aws:iam::555123456789:mfa/hermione-yubikey",
"MFAUsed": "Yes"
},
"eventID": "90000000-0000-4000-8000-000000000110",
"readOnly": false,
"eventType": "AwsConsoleSignIn",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "us-east-1.signin.aws.amazon.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Initial Access Stealth

Techniques:
  • T1078.004 — Cloud Accounts — Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of r...
Documentation reviewed: September 28, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.