GetSessionToken
GetSessionToken
Event
Uses long-term IAM-user credentials to obtain a temporary user session. IAM-user duration ranges from 15 minutes to 36 hours, defaulting to 12 hours; root sessions are limited to one hour. This is an authentication operation requiring no permission grant for sts:GetSessionToken. It does not assume a role or grant permissions beyond the user’s access.
Security Context
MFA context may satisfy conditions on later requests; it is not an independent privilege grant. IAM API calls require MFA authentication information, and permitted STS calls are limited to AssumeRole and GetCallerIdentity. Legitimate automation and interactive work use this API. T1078.004 requires evidence of account abuse; issuance itself is not token theft.
Log Source
AWS CloudTrail management event with eventSource: sts.amazonaws.com and eventName: GetSessionToken. Check errorCode and errorMessage; a null response alone does not establish success or failure.
Key Fields
| Field | Investigation value |
|---|---|
userIdentity.accessKeyId | Long-term calling key and owner. |
requestParameters.serialNumber, durationSeconds | MFA device and requested lifetime; a device name is not evidence of hardware type. |
responseElements | May not expose credentials in a log record; use available correlation fields and downstream user-session context. |
eventTime, recipientAccountId, eventID, requestID | Timeline and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context, not a definitive attacker fingerprint. |
What to Investigate
- Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
- Verify the initiating user, credential provenance, and expected workflow. Absence of serialNumber alone is not proof of abuse.
- Review MFA validation and policy conditions on downstream requests; distinguish ordinary user-session credentials from role sessions.
- Correlate subsequent IAM and AssumeRole activity and applicable containment controls. Do not infer revocation of all temporary sessions from source-key rotation.
Sample Event
Synthetic scenario. Hermione requests 12 hours with a virtual-device ARN. Token-code material is omitted; the sample does not establish a YubiKey or a later privileged task.
Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDAHERM10NE000ADM1N", "arn": "arn:aws:iam::555123456789:user/hermione", "accountId": "555123456789", "accessKeyId": "AKIAHERM10NEEXAMPLE1", "userName": "hermione" }, "eventTime": "2026-04-15T14:11:09Z", "eventSource": "sts.amazonaws.com", "eventName": "GetSessionToken", "awsRegion": "us-east-1", "sourceIPAddress": "198.51.100.42", "userAgent": "aws-cli/2.15.30 Python/3.11.6 Linux/5.15.0-1052-aws exe/x86_64.ubuntu.22 prompt/off command/sts.get-session-token", "requestParameters": { "serialNumber": "arn:aws:iam::555123456789:mfa/hermione-totp", "durationSeconds": 43200 }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000101000110", "eventID": "90000000-0000-4000-8000-000101000111", "readOnly": true, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "sts.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Initial Access Persistence Privilege Escalation Stealth
- T1078.004 — Cloud Accounts — Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of r...