Skip to content

GetAuthorizationToken

AWS

GetAuthorizationToken

service: AWS - ECR
techniques:

Event

Returns a base64-encoded registry authorization token valid for 12 hours. Its permissions follow the requesting IAM principal’s ECR access; it does not grant arbitrary pull or push rights. The registryIds parameter is deprecated. Token issuance is separate from registry authentication and image operations.

Security Context

Normal image builds and deployments request these tokens. Account abuse can use the same operation (contextual T1078.004), but issuance is not proof of unsecured credential discovery, metadata theft, or container escape. Establish repository permissions and actual image access separately.

Log Source

AWS CloudTrail management event with eventSource: ecr.amazonaws.com and eventName: GetAuthorizationToken. Check errorCode and errorMessage; a null response alone does not establish success or failure.

Key Fields

FieldInvestigation value
userIdentityCaller and credential provenance; the API does not retrieve instance metadata.
awsRegion, recipientAccountIdRegional/account context; not a list of repositories the token can access.
responseElementsMay be null in CloudTrail; do not expect a usable registry password in the event.
eventTime, recipientAccountId, eventID, requestIDTimeline and correlation identifiers.
sourceIPAddress, userAgentSupporting context, not a definitive attacker fingerprint.

What to Investigate

  1. Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
  2. Match issuance to a known build, deploy, or operator workflow and validate the caller’s origin.
  3. Review identity and repository policies and correlate subsequent image-read or upload API activity. Token issuance alone shows neither pull nor push.
  4. Correlate PutImage and changes to image digests where relevant; confirm consumer impact before claiming a backdoored deployment.

Sample Event

Synthetic scenario. Draco requests a registry token. The sample does not demonstrate a compromised container, stolen metadata credentials, arbitrary registry access, or image modification.

Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "AssumedRole",
"principalId": "AROAOCCAMYP1PEL1NE02:i-0123456789abcdef0",
"arn": "arn:aws:sts::555123456789:assumed-role/OccamyPipelineRole/i-0123456789abcdef0",
"accountId": "555123456789",
"accessKeyId": "ASIAOCCAMY1MDS5SESS01",
"sessionContext": {
"sessionIssuer": {
"type": "Role",
"principalId": "AROAOCCAMYP1PEL1NE02",
"arn": "arn:aws:iam::555123456789:role/OccamyPipelineRole",
"accountId": "555123456789",
"userName": "OccamyPipelineRole"
},
"attributes": {
"creationDate": "2026-04-15T21:09:14Z",
"mfaAuthenticated": "false"
},
"ec2RoleDelivery": "2.0"
}
},
"eventTime": "2026-04-15T21:13:02Z",
"eventSource": "ecr.amazonaws.com",
"eventName": "GetAuthorizationToken",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": null,
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000100111010",
"eventID": "90000000-0000-4000-8000-000100111011",
"readOnly": true,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "api.ecr.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Initial Access Persistence Privilege Escalation Stealth

Techniques:
  • T1078.004 — Cloud Accounts — Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of r...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.