2026 Critical Cloud Control Plane Detection: Identity or Session Token Manipulation to Mask Actor Identity
Detects AWS CloudTrail events where an actor performs identity or session token manipulation, specifically through the use of sts:GetFederationToken or sts:AssumeRole, or by modifying MFA configurations such as DeactivateMFADevice or CreateVirtualMFADevice on privileged accounts. This activity may indicate an attempt to gain persistent access, bypass security controls, or masquerade as a legitimate principal.
Sigma

