Skip to content

GetSigninToken

AWS

GetSigninToken

service: AWS - SignIn
tactics:
techniques:

Event

The federation endpoint exchanges supported temporary AWS credentials for a token used in a console sign-in URL. Getting the token and completing ConsoleLogin are separate steps. The URL is valid for 15 minutes, distinct from the associated credential/session lifetime; this exchange does not grant new permissions.

Security Context

Unexpected federation activity warrants investigation, but ordinary identity brokers use this operation. Token issuance alone is neither token theft nor proof of lateral movement, so the previous T1528/T1550.001 mappings are removed.

Log Source

AWS CloudTrail management event with eventSource: signin.amazonaws.com and eventName: GetSigninToken. Verify collection across the relevant accounts and Regions. Inspect response and error fields; the event does not by itself prove downstream use. Sign-in event fields and Region placement can differ from ordinary API calls; do not rely on one assumed Region or identity wrapper.

Key Fields

FieldInvestigation value
userIdentity, sourceIPAddressRecorded identity/client context, not proof of malicious intent.
eventName, eventSource, awsRegionOperation and collection context; distinguish requested target Region when applicable.
requestParameters, responseElementsRequest scope and outcome, where present.
eventID, eventTime, errorCode, errorMessageTiming, correlation, and errors; inspect related completion/sign-in records.

What to Investigate

  1. Confirm the recorded outcome and compare actor, target, and timing with the approved workflow.
  2. Identify the temporary session and correlate the originating STS request or identity-broker activity.
  3. Correlate subsequent ConsoleLogin and API actions; protect any live sign-in token or URL as credential material.
  4. Review upstream authentication evidence separately: federation MFA fields do not reliably describe whether an identity provider required MFA.

Sample Event

Synthetic scenario. The sample follows the documented assumed-role event shape. It shows successful token issuance, not a returned token value, stolen credentials, or successful console login.

Exact field presence, payload nesting, identity/session details, and timestamp formatting remain unverified against captured logs. Names and illustrative identifiers do not prove intent or downstream activity.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "AssumedRole",
"principalId": "AROAEXAMPLE00000000001:draco-console",
"arn": "arn:aws:sts::555123456789:assumed-role/ConsoleFederation/draco-console",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0FED0SESS00666",
"sessionContext": {
"sessionIssuer": {
"type": "Role",
"principalId": "AROAEXAMPLE00000000001",
"arn": "arn:aws:iam::555123456789:role/ConsoleFederation",
"accountId": "555123456789",
"userName": "ConsoleFederation"
},
"webIdFederationData": {},
"attributes": {
"creationDate": "2026-04-15T21:21:38Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T21:24:05Z",
"eventSource": "signin.amazonaws.com",
"eventName": "GetSigninToken",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "Java/1.8.0_382",
"requestParameters": null,
"responseElements": {
"GetSigninToken": "Success",
"credentials": {
"accessKeyId": "ASIADRAC0FED0SESS00666"
}
},
"additionalEventData": {
"MobileVersion": "No",
"MFAUsed": "No"
},
"requestID": "90000000-0000-4000-8000-000101001000",
"eventID": "90000000-0000-4000-8000-000101001001",
"readOnly": false,
"eventType": "AwsConsoleSignIn",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "us-east-1.signin.aws.amazon.com"
}
}

Sources

Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.