Home / Companies / Crowdstrike / Blog / Post Details
Content Deep Dive

How Adversaries Can Persist with AWS User Federation

Blog post from Crowdstrike

Post Details
Company
Date Published
Author
Vaishnav Murthy - Joel Eng
Word Count
3,950
Company Posts That Month
10
Language
English
Hacker News Points
-
Post removed?
No
Summary

CrowdStrike has identified a sophisticated technique employed by threat actors to maintain persistence within AWS environments using federated sessions. This method involves exploiting the AWS Security Token Service (STS) to create temporary credentials that outlast the revocation of original IAM user credentials. By using the sts:GetFederationToken API call, attackers can generate federated sessions that inherit permissions from compromised IAM users, allowing them to perform actions even after the base user's API keys are deactivated. The federated sessions persist until they expire, unless the permissions of the base IAM user are explicitly overridden or reduced. CrowdStrike recommends using an explicit deny-all IAM policy or a Service Control Policy (SCP) to effectively revoke the permissions of such federated sessions. This persistence technique highlights the need for organizations to adopt best practices such as minimizing the use of long-lived credentials and applying robust policy controls to prevent unauthorized access and privilege escalation within cloud environments.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
AI Agents 2 33 18 6 -41%
Zero Trust 2 386 66 16 +264%
AI Coding Assistant 1 67 20 7 -40%
AI Guardrails 1 29 22 7 -57%
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.