AWS AssumeRole
Returns temporary security credentials for assuming an IAM role. Allows an entity (user, service, or account) to act with the role's permissions.
The adversary is trying to move through your environment.
Lateral Movement consists of techniques that adversaries use to enter and control remote systems on a network. Following through on their primary objective often requires exploring the network to find their target, then pivoting through multiple systems and accounts to gain access to it. Adversaries might install their own remote access tools to accomplish Lateral Movement or use legitimate credentials with native network and operating system tools, which may be stealthier.
In cloud environments, lateral movement involves assuming roles across accounts, accessing shared resources, using SSH keys injected via metadata services, or pivoting through VPC peering connections. Adversaries may also move between cloud services (e.g., from a compromised EC2 instance to S3 or RDS) using the permissions of the compromised identity.
View Lateral Movement on MITRE ATT&CK →Explore this tactic in the map.
Returns temporary security credentials for assuming an IAM role. Allows an entity (user, service, or account) to act with the role's permissions.
Exchanges a validated SAML assertion for temporary IAM role credentials.
Exchanges a web-identity token for temporary IAM role credentials.
Enables EC2 Serial Console access for the account in the current Region.
Records a connection to a VM’s interactive serial console.
Requests a connection to an Azure VM serial console.
Reconnects to a disconnected SSM Session Manager session.
Publishes an SSH key for a 60-second EC2 serial-console connection window.
Publishes a temporary SSH key through EC2 Instance Connect.
Starts an SSM Session Manager session.