AWS Identity Center Identity Provider Change

 Original Source: [Sigma source]
Title: AWS Identity Center Identity Provider Change
Status: test
Description:Detects a change in the AWS Identity Center (FKA AWS SSO) identity provider. A change in identity provider allows an attacker to establish persistent access or escalate privileges via user impersonation.
References:
  -https://docs.aws.amazon.com/singlesignon/latest/userguide/app-enablement.html
  -https://docs.aws.amazon.com/singlesignon/latest/userguide/sso-info-in-cloudtrail.html
  -https://docs.aws.amazon.com/service-authorization/latest/reference/list_awsiamidentitycentersuccessortoawssinglesign-on.html
Author: Michael McIntyre @wtfender
Date: 2023-09-27
modified:None
Tags:
  • -'attack.persistence'
  • -'attack.credential-access'
  • -'attack.defense-impairment'
  • -'attack.t1556'
Logsource:
  • product: aws
  • service: cloudtrail
Detection:
  selection:
    eventSource:
      -'sso-directory.amazonaws.com'
      -'sso.amazonaws.com'

    eventName:
      -'AssociateDirectory'
      -'DisableExternalIdPConfigurationForDirectory'
      -'DisassociateDirectory'
      -'EnableExternalIdPConfigurationForDirectory'

  condition:selection
Falsepositives:
  -Authorized changes to the AWS account's identity provider
Level: high