2026 Critical Cloud Control Plane Detection: Anomalous sts:AssumeRole or GetFederationToken Producing Elevated Cross-Account Session
Detects the use of sts:AssumeRole or sts:GetFederationToken to request temporary security credentials in a different AWS account than the one initiating the request. This can indicate cross-account privilege escalation or lateral movement using identity federation or assumed roles.
Sigma

