AWS GetFederationToken Followed by Console Login via Federation Exchange
Description
Detects the three-event chain produced by tools like aws_consoler that convert exfiltrated long-term IAM access keys into browser-accessible AWS console sessions: GetFederationToken obtains temporary credentials, GetSigninToken exchanges them for a federation sign-in token via the AWS federation endpoint, and ConsoleLogin confirms the resulting console session was opened — all from the same source IP within two minutes. This sequence is a high-confidence indicator of credential abuse using stolen IAM access keys.
Query · eql
sequence by source.ip with maxspan=2m [any where event.provider == "sts.amazonaws.com" and event.action == "GetFederationToken" and event.outcome == "success"] [any where event.provider == "signin.amazonaws.com" and event.action == "GetSigninToken" and event.outcome == "success"] [any where event.provider == "signin.amazonaws.com" and event.action == "ConsoleLogin" and event.outcome == "success"]
Investigation fields
Pivot points the source recommends for triage.
@timestampaws.cloudtrail.user_identity.arnaws.cloudtrail.user_identity.typeaws.cloudtrail.user_identity.access_key_iduser.nameevent.providerevent.actionevent.outcomesource.ipsource.as.organization.namecloud.regioncloud.account.id
Implementation guide
The AWS integration must be ingesting management events into logs-aws.cloudtrail-*. STS and sign-in management events are logged by default.
Known false positives
- Legacy federation broker applications that call GetFederationToken and immediately redirect users to a console session from the same host may trigger this rule. Validate the source IP against known application server infrastructure and confirm the federation architecture is documented.
Analyst notes
Investigating AWS GetFederationToken Followed by Console Login via Federation Exchange
This rule detects the aws_consoler attack chain: an adversary exfiltrates a long-term IAM access key (AKIA* prefix), runs aws_consoler or equivalent tooling, which calls GetFederationToken to obtain temporary credentials and then exchanges them at the AWS federation endpoint (https://signin.amazonaws.com/federation) for a signed console URL. Opening that URL triggers a ConsoleLogin event from the same source IP, completing the sequence.
The source IP correlation distinguishes this pattern from coincidental federation activity: both the API call and the browser-based console login originate from the same attacker machine in automated tooling scenarios.
Possible investigation steps
- Identify the IAM user from
aws.cloudtrail.user_identity.arnin the first event and confirm whether this user and access key are expected to callGetFederationToken. - Review
source.ipagainst known infrastructure. A call from an unexpected geography or cloud provider IP range is a strong indicator of exfiltrated key abuse. - Query CloudTrail for all API calls made during the resulting console session (user identity type
FederatedUser) in the window following theConsoleLogin. - Check GitHub, GitLab, CI/CD pipelines, and
.envfiles for exposure of the access key. - Determine whether any sensitive resources were accessed or modified during the console session.
Response and remediation
- Immediately deactivate the long-term access key used in the
GetFederationTokencall. - Revoke all active sessions for the IAM user.
- Review all actions taken during the federated console session and assess blast radius.
- Rotate all credentials associated with the IAM user.
- Migrate any legitimate federation use cases to IAM Identity Center or AssumeRoleWithWebIdentity.