Skip to content

GetFederationToken

AWS

GetFederationToken

service: AWS - STS
techniques:

Event

Issues a federated-user session, not an assumed-role session. IAM-user requests use long-term credentials; durations range from 900 to 129,600 seconds (36 hours), defaulting to 43,200 seconds (12 hours). Root-issued sessions have a one-hour maximum. Inline or managed session policies constrain identity-policy grants; a wildcard policy cannot independently grant administrator access. Without session policies there are no identity-derived grants, though direct resource-policy grants to the session need separate evaluation.

Security Context

Legitimate identity brokers use this API. An adversary with usable long-term credentials could obtain temporary sessions for continued access (contextual T1078.004). Issuance is not token theft, so T1528 is not mapped. Do not assume rotating a source key is a complete containment action; investigate issued sessions and applicable denies. Nor should a session be described as irrevocable: permission changes and explicit denies can restrict access.

Log Source

AWS CloudTrail management event with eventSource: sts.amazonaws.com and eventName: GetFederationToken. Check errorCode and errorMessage before treating an attempt as successful; responseElements: null alone does not indicate failure. CloudTrail logs federation requests, but some malformed unauthenticated requests may not be recorded. Do not equate absence with absence of attempted abuse.

Key Fields

FieldInvestigation value
userIdentity.accessKeyIdLong-term calling key; distinguish from the temporary key in the response.
requestParameters.name, durationSecondsFederated-session name and requested lifetime.
requestParameters.policy, policyArnsRestrictive session policies; compare with caller grants and resource policies.
responseElements.federatedUser, credentialsSession identity, temporary-key identifier, and expiration for correlation.
eventTime, recipientAccountId, eventID, requestIDTimeline, account, and correlation identifiers.

What to Investigate

  1. Confirm the outcome and match the caller, target, and timing to an approved workflow. Review failed attempts separately.
  2. Verify the caller and broker workflow, including whether the long-term key was authorized and exposed.
  3. Evaluate effective access. These credentials cannot call IAM APIs through CLI/API and cannot call STS APIs except GetCallerIdentity; console access has different IAM behavior.
  4. Correlate downstream federated-user activity and GetSigninToken workflows where evidence exists. Check session expiration and containment through permission controls rather than assuming source-key rotation proves revocation.

Sample Event

Synthetic scenario. Draco requests a 12-hour session with a wildcard session policy. This is the default duration, not the IAM-user maximum; the sample does not show the user’s grants or any subsequent privileged action.

Exact CloudTrail nesting, field presence, redaction, and timestamp formatting remain unverified against captured logs. Credential/token placeholders and metadata placeholders are illustrative, not usable credentials or complete provider metadata.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "AKIADRAC0MALF0YEXAMP5",
"userName": "draco"
},
"eventTime": "2026-04-15T21:21:38Z",
"eventSource": "sts.amazonaws.com",
"eventName": "GetFederationToken",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"name": "draco-fed",
"policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Action\":\"*\",\"Resource\":\"*\"}]}",
"durationSeconds": 43200
},
"responseElements": {
"credentials": {
"accessKeyId": "ASIADRAC0FED0SESS00666",
"expiration": "Apr 16, 2026, 9:21:38 AM",
"sessionToken": "<encoded session token blob>"
},
"federatedUser": {
"arn": "arn:aws:sts::555123456789:federated-user/draco-fed",
"federatedUserId": "555123456789:draco-fed"
},
"packedPolicySize": 4
},
"requestID": "90000000-0000-4000-8000-000100111100",
"eventID": "90000000-0000-4000-8000-000100111101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sts.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Initial Access Persistence Privilege Escalation Stealth

Techniques:
  • T1078.004 — Cloud Accounts — Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of r...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.