GetFederationToken
GetFederationToken
Event
Issues a federated-user session, not an assumed-role session. IAM-user requests use long-term credentials; durations range from 900 to 129,600 seconds (36 hours), defaulting to 43,200 seconds (12 hours). Root-issued sessions have a one-hour maximum. Inline or managed session policies constrain identity-policy grants; a wildcard policy cannot independently grant administrator access. Without session policies there are no identity-derived grants, though direct resource-policy grants to the session need separate evaluation.
Security Context
Legitimate identity brokers use this API. An adversary with usable long-term credentials could obtain temporary sessions for continued access (contextual T1078.004). Issuance is not token theft, so T1528 is not mapped. Do not assume rotating a source key is a complete containment action; investigate issued sessions and applicable denies. Nor should a session be described as irrevocable: permission changes and explicit denies can restrict access.
Log Source
AWS CloudTrail management event with eventSource: sts.amazonaws.com and eventName: GetFederationToken. Check errorCode and errorMessage before treating an attempt as successful; responseElements: null alone does not indicate failure. CloudTrail logs federation requests, but some malformed unauthenticated requests may not be recorded. Do not equate absence with absence of attempted abuse.
Key Fields
| Field | Investigation value |
|---|---|
userIdentity.accessKeyId | Long-term calling key; distinguish from the temporary key in the response. |
requestParameters.name, durationSeconds | Federated-session name and requested lifetime. |
requestParameters.policy, policyArns | Restrictive session policies; compare with caller grants and resource policies. |
responseElements.federatedUser, credentials | Session identity, temporary-key identifier, and expiration for correlation. |
eventTime, recipientAccountId, eventID, requestID | Timeline, account, and correlation identifiers. |
What to Investigate
- Confirm the outcome and match the caller, target, and timing to an approved workflow. Review failed attempts separately.
- Verify the caller and broker workflow, including whether the long-term key was authorized and exposed.
- Evaluate effective access. These credentials cannot call IAM APIs through CLI/API and cannot call STS APIs except GetCallerIdentity; console access has different IAM behavior.
- Correlate downstream federated-user activity and GetSigninToken workflows where evidence exists. Check session expiration and containment through permission controls rather than assuming source-key rotation proves revocation.
Sample Event
Synthetic scenario. Draco requests a 12-hour session with a wildcard session policy. This is the default duration, not the IAM-user maximum; the sample does not show the user’s grants or any subsequent privileged action.
Exact CloudTrail nesting, field presence, redaction, and timestamp formatting remain unverified against captured logs. Credential/token placeholders and metadata placeholders are illustrative, not usable credentials or complete provider metadata.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "AKIADRAC0MALF0YEXAMP5", "userName": "draco" }, "eventTime": "2026-04-15T21:21:38Z", "eventSource": "sts.amazonaws.com", "eventName": "GetFederationToken", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "name": "draco-fed", "policy": "{\"Version\":\"2012-10-17\",\"Statement\":[{\"Effect\":\"Allow\",\"Action\":\"*\",\"Resource\":\"*\"}]}", "durationSeconds": 43200 }, "responseElements": { "credentials": { "accessKeyId": "ASIADRAC0FED0SESS00666", "expiration": "Apr 16, 2026, 9:21:38 AM", "sessionToken": "<encoded session token blob>" }, "federatedUser": { "arn": "arn:aws:sts::555123456789:federated-user/draco-fed", "federatedUserId": "555123456789:draco-fed" }, "packedPolicySize": 4 }, "requestID": "90000000-0000-4000-8000-000100111100", "eventID": "90000000-0000-4000-8000-000100111101", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "sts.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Initial Access Persistence Privilege Escalation Stealth
- T1078.004 — Cloud Accounts — Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of r...