Skip to content

GetSessionToken

AWS

GetSessionToken

service: AWS - STS
techniques:

Event

Uses long-term IAM-user credentials to obtain a temporary user session. IAM-user duration ranges from 15 minutes to 36 hours, defaulting to 12 hours; root sessions are limited to one hour. This is an authentication operation requiring no permission grant for sts:GetSessionToken. It does not assume a role or grant permissions beyond the user’s access.

Security Context

MFA context may satisfy conditions on later requests; it is not an independent privilege grant. IAM API calls require MFA authentication information, and permitted STS calls are limited to AssumeRole and GetCallerIdentity. Legitimate automation and interactive work use this API. T1078.004 requires evidence of account abuse; issuance itself is not token theft.

Log Source

AWS CloudTrail management event with eventSource: sts.amazonaws.com and eventName: GetSessionToken. Check errorCode and errorMessage; a null response alone does not establish success or failure.

Key Fields

FieldInvestigation value
userIdentity.accessKeyIdLong-term calling key and owner.
requestParameters.serialNumber, durationSecondsMFA device and requested lifetime; a device name is not evidence of hardware type.
responseElementsMay not expose credentials in a log record; use available correlation fields and downstream user-session context.
eventTime, recipientAccountId, eventID, requestIDTimeline and correlation identifiers.
sourceIPAddress, userAgentSupporting context, not a definitive attacker fingerprint.

What to Investigate

  1. Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
  2. Verify the initiating user, credential provenance, and expected workflow. Absence of serialNumber alone is not proof of abuse.
  3. Review MFA validation and policy conditions on downstream requests; distinguish ordinary user-session credentials from role sessions.
  4. Correlate subsequent IAM and AssumeRole activity and applicable containment controls. Do not infer revocation of all temporary sessions from source-key rotation.

Sample Event

Synthetic scenario. Hermione requests 12 hours with a virtual-device ARN. Token-code material is omitted; the sample does not establish a YubiKey or a later privileged task.

Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDAHERM10NE000ADM1N",
"arn": "arn:aws:iam::555123456789:user/hermione",
"accountId": "555123456789",
"accessKeyId": "AKIAHERM10NEEXAMPLE1",
"userName": "hermione"
},
"eventTime": "2026-04-15T14:11:09Z",
"eventSource": "sts.amazonaws.com",
"eventName": "GetSessionToken",
"awsRegion": "us-east-1",
"sourceIPAddress": "198.51.100.42",
"userAgent": "aws-cli/2.15.30 Python/3.11.6 Linux/5.15.0-1052-aws exe/x86_64.ubuntu.22 prompt/off command/sts.get-session-token",
"requestParameters": {
"serialNumber": "arn:aws:iam::555123456789:mfa/hermione-totp",
"durationSeconds": 43200
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000101000110",
"eventID": "90000000-0000-4000-8000-000101000111",
"readOnly": true,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "sts.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Initial Access Persistence Privilege Escalation Stealth

Techniques:
  • T1078.004 — Cloud Accounts — Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of r...
Documentation reviewed: September 30, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.