AWS AssumeRole
Returns temporary security credentials for assuming an IAM role. Allows an entity (user, service, or account) to act with the role's permissions.
The adversary is trying to get into your network.
Initial Access consists of techniques that use various entry vectors to gain their initial foothold within a network. Techniques used to gain a foothold include targeted spearphishing and exploiting weaknesses on public-facing web servers. Footholds gained through initial access may allow for continued access, like valid accounts and use of external remote services, or may be limited-use due to changing passwords.
In cloud environments, initial access often involves compromised credentials, misconfigured identity providers, or exploiting exposed cloud services. Adversaries may leverage stolen API keys, abuse federated authentication (SAML/OIDC), or exploit publicly accessible storage buckets and serverless endpoints to establish their first foothold.
View Initial Access on MITRE ATT&CK →Explore this tactic in the map.
Returns temporary security credentials for assuming an IAM role. Allows an entity (user, service, or account) to act with the role's permissions.
Exchanges a validated SAML assertion for temporary IAM role credentials.
Exchanges a web-identity token for temporary IAM role credentials.
Records a sign-in attempt to the AWS Management Console, capturing success or failure status and whether MFA was used.
Requests a temporary authentication token for private Amazon ECR registries.
Issues temporary federated-user credentials using long-term IAM-user credentials.
Issues temporary credentials for an IAM user, optionally with MFA context.