{"id":"T1021.007","name":"Cloud Services","url":"https://attack.mitre.org/techniques/T1021/007","tactics":["lateral-movement"],"platforms":["IaaS","Identity Provider","Office Suite","SaaS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0008","stix_id":"x-mitre-detection-strategy--f6e514c0-120a-4ab1-ae3d-aa2de14e4324","name":"Behavioral Detection of Remote Cloud Logins via Valid Accounts","url":"https://attack.mitre.org/detectionstrategies/DET0008","analytics":[{"id":"AN0017","stix_id":"x-mitre-analytic--7d4732f8-989c-4425-81c4-aa3e1bcb8d0e","name":"Analytic 0017","description":"Cloud login from atypical geolocation or user-agent string, followed by resource enumeration or infrastructure manipulation using cloud CLI/API","url":"https://attack.mitre.org/detectionstrategies/DET0008#AN0017","platforms":["IaaS"],"log_source_references":[{"name":"AWS:CloudTrail","channel":"ConsoleLogin, AssumeRole, ListResources","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"aws-cloudtrail"},{"name":"gcp:audit","channel":"None","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"gcp-audit"}],"mutable_elements":[{"field":"IPGeoRiskScore","description":"Tunable scoring system for evaluating geo-divergent or TOR-origin logins"},{"field":"UserAgentFingerprint","description":"Flag rare CLI tools or browser-based sessions"},{"field":"SessionDuration","description":"Threshold for how long between login and API access"},{"field":"CloudResourceScope","description":"Limit monitoring to high-value resource groups or sensitive tenants"}],"live":true,"detection_strategies":["DET0008"],"techniques":["T1021.007"]},{"id":"AN0018","stix_id":"x-mitre-analytic--ecb9db5c-55ef-48df-8ccb-f57db8c32a08","name":"Analytic 0018","description":"Federated login using SSO or OAuth grant to cloud control plane, followed by directory or permissions enumeration","url":"https://attack.mitre.org/detectionstrategies/DET0008#AN0018","platforms":["Identity Provider"],"log_source_references":[{"name":"Okta:SystemLog","channel":"user.authentication.sso, app.oauth.grant","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"okta-systemlog"}],"mutable_elements":[{"field":"SSOApplicationScope","description":"Tune based on applications federated to high-priv cloud assets"},{"field":"ClientIDScope","description":"Filter based on expected OIDC clients used for login"},{"field":"LoginVelocity","description":"Track multiple geographic logins within short windows"}],"live":true,"detection_strategies":["DET0008"],"techniques":["T1021.007"]},{"id":"AN0019","stix_id":"x-mitre-analytic--c85d0aea-06c4-4b0f-8552-0d0873394ffa","name":"Analytic 0019","description":"Login to M365 or Google Workspace from CLI tools or unexpected source IPs, followed by mailbox or document access","url":"https://attack.mitre.org/detectionstrategies/DET0008#AN0019","platforms":["Office Suite"],"log_source_references":[{"name":"m365:unified","channel":"FileAccessed, MailboxAccessed","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"m365-unified"},{"name":"m365:unified","channel":"UserLoggedIn","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"m365-unified"}],"mutable_elements":[{"field":"DevicePlatformMismatch","description":"Raise alerts on login from CLI when user typically uses web-only"},{"field":"SensitiveDocumentAccessPattern","description":"Track access to documents labeled as internal/confidential"},{"field":"AccessFrequencyThreshold","description":"Tune for high-volume document reads post login"}],"live":true,"detection_strategies":["DET0008"],"techniques":["T1021.007"]},{"id":"AN0020","stix_id":"x-mitre-analytic--fb23f9ee-cdc8-46be-8f40-3631afbaff5a","name":"Analytic 0020","description":"Remote access to third-party SaaS with OAuth or API tokens post-initial compromise, followed by sensitive data access or configuration changes","url":"https://attack.mitre.org/detectionstrategies/DET0008#AN0020","platforms":["SaaS"],"log_source_references":[{"name":"saas:auth","channel":"LoginSuccess, APIKeyUse, AdminAction","data_component":"DC0067","data_component_name":"Logon Session Creation","log_source_slug":"saas-auth"}],"mutable_elements":[{"field":"OAuthTokenAge","description":"Older tokens issued before password change may indicate compromise"},{"field":"AppScope","description":"Restrict detection to high-value or regulated SaaS apps"}],"live":true,"detection_strategies":["DET0008"],"techniques":["T1021.007"]}],"live":true,"version":"1.0","techniques":["T1021.007"]}],"sigma_rules":[{"id":"f8103686-e3e8-46f3-be72-65f7fcb4aa53","title":"AWS Console GetSigninToken Potential Abuse","author":"Chester Le Bron (@123Le_Bron)","status":"test","level":"medium","date":"2024-02-26","modified":null,"description":"Detects potentially suspicious events involving \"GetSigninToken\".\nAn adversary using the \"aws_consoler\" tool can leverage this console API to create temporary federated credential that help obfuscate which AWS credential is compromised (the original access key) and enables the adversary to pivot from the AWS CLI to console sessions without the need for MFA using the new access key issued in this request.\n","references":["https://github.com/NetSPI/aws_consoler","https://www.crowdstrike.com/blog/analysis-of-intrusion-campaign-targeting-telecom-and-bpo-companies/"],"logsource":{"product":"aws","service":"cloudtrail"},"tags":["attack.lateral-movement","attack.t1021.007","attack.t1550.001"],"path":"rules/cloud/aws/cloudtrail/aws_console_getsignintoken.yml","techniques":["T1021.007","T1550.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}