GetAuthorizationToken
GetAuthorizationToken
Event
Returns a base64-encoded registry authorization token valid for 12 hours. Its permissions follow the requesting IAM principal’s ECR access; it does not grant arbitrary pull or push rights. The registryIds parameter is deprecated. Token issuance is separate from registry authentication and image operations.
Security Context
Normal image builds and deployments request these tokens. Account abuse can use the same operation (contextual T1078.004), but issuance is not proof of unsecured credential discovery, metadata theft, or container escape. Establish repository permissions and actual image access separately.
Log Source
AWS CloudTrail management event with eventSource: ecr.amazonaws.com and eventName: GetAuthorizationToken. Check errorCode and errorMessage; a null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
userIdentity | Caller and credential provenance; the API does not retrieve instance metadata. |
awsRegion, recipientAccountId | Regional/account context; not a list of repositories the token can access. |
responseElements | May be null in CloudTrail; do not expect a usable registry password in the event. |
eventTime, recipientAccountId, eventID, requestID | Timeline and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context, not a definitive attacker fingerprint. |
What to Investigate
- Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
- Match issuance to a known build, deploy, or operator workflow and validate the caller’s origin.
- Review identity and repository policies and correlate subsequent image-read or upload API activity. Token issuance alone shows neither pull nor push.
- Correlate PutImage and changes to image digests where relevant; confirm consumer impact before claiming a backdoored deployment.
Sample Event
Synthetic scenario. Draco requests a registry token. The sample does not demonstrate a compromised container, stolen metadata credentials, arbitrary registry access, or image modification.
Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "AssumedRole", "principalId": "AROAOCCAMYP1PEL1NE02:i-0123456789abcdef0", "arn": "arn:aws:sts::555123456789:assumed-role/OccamyPipelineRole/i-0123456789abcdef0", "accountId": "555123456789", "accessKeyId": "ASIAOCCAMY1MDS5SESS01", "sessionContext": { "sessionIssuer": { "type": "Role", "principalId": "AROAOCCAMYP1PEL1NE02", "arn": "arn:aws:iam::555123456789:role/OccamyPipelineRole", "accountId": "555123456789", "userName": "OccamyPipelineRole" }, "attributes": { "creationDate": "2026-04-15T21:09:14Z", "mfaAuthenticated": "false" }, "ec2RoleDelivery": "2.0" } }, "eventTime": "2026-04-15T21:13:02Z", "eventSource": "ecr.amazonaws.com", "eventName": "GetAuthorizationToken", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": null, "responseElements": null, "requestID": "90000000-0000-4000-8000-000100111010", "eventID": "90000000-0000-4000-8000-000100111011", "readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "api.ecr.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Initial Access Persistence Privilege Escalation Stealth
- T1078.004 — Cloud Accounts — Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of r...