AWS Sign-In AWS-signin
4 operations, identified by eventName in the audit log.
| eventName | Description |
|---|---|
| _catch_all | Catch-all entry for AWS-signin rules that match the service but not a specific eventName. |
| ConsoleLogin | Records an authentication attempt to the AWS Management Console, including whether it succeeded or failed. |
| GetSigninToken | Retrieves a sign-in token used to grant console access to a federated user via the AWS federation endpoint. |
| PasswordRecoveryRequested | Records a request to initiate the root account password recovery process. |
_catch_all: AWS-signin (catch-all)
#Description
Catch-all entry for AWS-signin rules that match the service but not a specific eventName.
Fields #
| Name | Description |
|---|---|
eventName | The name of the API action that was called. |
eventSource | The AWS service endpoint that received the request (e.g. iam.amazonaws.com). |
eventType | CloudTrail event category: AwsApiCall, AwsConsoleSignIn, AwsConsoleAction, AwsServiceEvent, or AwsVpceEvents. |
userIdentity | The IAM entity that made the request (type, principalId, arn, accountId, sessionContext). |
sourceIPAddress | IP address of the caller, or the AWS service principal for service-initiated calls. |
awsRegion | AWS Region the request was made to. |
requestParameters | Parameters sent with the request. Shape is action-specific; null when none. |
responseElements | Response elements. Shape is action-specific; null for reads or when absent. |
errorCode | AWS service error code when the request failed. Absent on success. |
errorMessage | Description of the error when errorCode is present. |
ConsoleLogin
#Description
Records an authentication attempt to the AWS Management Console, including whether it succeeded or failed.
Fields #
| Name | Description |
|---|---|
eventName | The name of the API action that was called. |
eventSource | The AWS service endpoint that received the request (e.g. iam.amazonaws.com). |
eventType | CloudTrail event category: AwsApiCall, AwsConsoleSignIn, AwsConsoleAction, AwsServiceEvent, or AwsVpceEvents. |
userIdentity | The IAM entity that made the request (type, principalId, arn, accountId, sessionContext). |
sourceIPAddress | IP address of the caller, or the AWS service principal for service-initiated calls. |
awsRegion | AWS Region the request was made to. |
requestParameters | Parameters sent with the request. Shape is action-specific; null when none. |
responseElements | Response elements. Shape is action-specific; null for reads or when absent. |
errorCode | AWS service error code when the request failed. Absent on success. |
errorMessage | Description of the error when errorCode is present. |
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Provider_Name | eq | signin.amazonaws.com | 4 rules | elastic |
aws::eventName | eq | ConsoleLogin | 4 rules | kusto, panther, sigma, splunk |
aws::eventSource | eq | signin.amazonaws.com | 4 rules | panther, sigma |
security_result.action | eq | ALLOW | 4 rules | chronicle |
security_result.action | eq | BLOCK | 3 rules | chronicle |
EventType | eq | ConsoleLogin | 3 rules | elastic |
event.outcome | eq | success | 3 rules | elastic |
event.outcome | eq | failure | 1 rule | elastic |
aws::userIdentity.type | eq | Root | 2 rules | elastic, panther, sigma |
aws::userIdentity.type | eq | AssumedRole | 1 rule | elastic, kusto, panther, sigma |
responseElements.ConsoleLogin | eq | Failure | 2 rules | panther, sigma |
security_result.description | eq | Reason: Failed authentication | 2 rules | chronicle |
additionalEventData.MFAUsed | eq | Yes | 1 rule | panther, sigma, splunk |
user.id | contains | :i- | 1 rule | elastic |
Detection Rules #
View all rules referencing this event →Sigma #
Show 1 more (4 total)
Elastic #
Show 1 more (4 total)
YARA-L #
Show 3 more (6 total)
GetSigninToken
#Description
Retrieves a sign-in token used to grant console access to a federated user via the AWS federation endpoint.
Fields #
| Name | Description |
|---|---|
eventName | The name of the API action that was called. |
eventSource | The AWS service endpoint that received the request (e.g. iam.amazonaws.com). |
eventType | CloudTrail event category: AwsApiCall, AwsConsoleSignIn, AwsConsoleAction, AwsServiceEvent, or AwsVpceEvents. |
userIdentity | The IAM entity that made the request (type, principalId, arn, accountId, sessionContext). |
sourceIPAddress | IP address of the caller, or the AWS service principal for service-initiated calls. |
awsRegion | AWS Region the request was made to. |
requestParameters | Parameters sent with the request. Shape is action-specific; null when none. |
responseElements | Response elements. Shape is action-specific; null for reads or when absent. |
errorCode | AWS service error code when the request failed. Absent on success. |
errorMessage | Description of the error when errorCode is present. |
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Provider_Name | eq | signin.amazonaws.com | 2 rules | elastic |
aws::eventName | eq | GetSigninToken | 1 rule | panther, sigma |
aws::eventSource | eq | signin.amazonaws.com | 1 rule | panther, sigma |
aws::userIdentity.type | eq | AssumedRole | 1 rule | elastic, kusto, panther, sigma |
user.id | contains | :i- | 1 rule | elastic |
Detection Rules #
View all rules referencing this event →Sigma #
Elastic #
PasswordRecoveryRequested
#Description
Records a request to initiate the root account password recovery process.
Fields #
| Name | Description |
|---|---|
eventName | The name of the API action that was called. |
eventSource | The AWS service endpoint that received the request (e.g. iam.amazonaws.com). |
eventType | CloudTrail event category: AwsApiCall, AwsConsoleSignIn, AwsConsoleAction, AwsServiceEvent, or AwsVpceEvents. |
userIdentity | The IAM entity that made the request (type, principalId, arn, accountId, sessionContext). |
sourceIPAddress | IP address of the caller, or the AWS service principal for service-initiated calls. |
awsRegion | AWS Region the request was made to. |
requestParameters | Parameters sent with the request. Shape is action-specific; null when none. |
responseElements | Response elements. Shape is action-specific; null for reads or when absent. |
errorCode | AWS service error code when the request failed. Absent on success. |
errorMessage | Description of the error when errorCode is present. |
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Provider_Name | eq | signin.amazonaws.com | 1 rule | elastic |
Detection Rules #
View all rules referencing this event →Elastic #