AN1105
Analytic 1105
IaaS
Multiple AWS CloudTrail events indicating temporary privilege escalation via PassRole and AssumeRole targeting newly created services or non-interactive infrastructure.
AWS:CloudTrail
PassRole
[targetRoleName]
Define which roles are allowed to be assumed or passed; restrict highly privileged roles.
[TimeWindow]
Time range between PassRole and AssumeRole events to link the privilege chain.
[invokingService]
Restrict which services are authorized to invoke role passing (e.g., Lambda, EC2).
AN1106
Analytic 1106
Identity Provider
Token creation or access delegation where a user impersonates a higher-privileged service account or performs domain-wide delegation actions, such as GCP's serviceAccountTokenCreator or Workspace impersonation.
gcp:iam
PrincipalEmail with serviceAccountTokenCreator impersonating new identity
gcp:workspaceaudit
Token Generation via Domain Delegation
[userEmailFilter]
Tune based on legitimate service accounts allowed to impersonate user accounts.
[delegatedScope]
Limit delegated access to specific scopes relevant to business functions.
AN1107
Analytic 1107
Office Suite
Detection of ApplicationImpersonation role assignment or delegated mailbox access to service principals or rarely used users, especially outside of normal hours or geographic norms.
m365:unified
Add-MailboxPermission or Set-ManagementRoleAssignment
m365:signinlogs
Unusual sign-in from service principal to user mailbox
[TargetMailbox]
Mailbox of interest where impersonation or access delegation occurs.
[UserAgent]
Tune based on expected application or script-based mailbox access.
[GeoLocation]
Restrict based on corporate geography or travel expectations.