Every AWS API call needs a credential, so obtaining one is the first move and harvesting more is how an engagement widens. Credentials arrive as long-lived access keys, temporary STS session tokens (an access key, secret, session token, and expiry), and role credentials delivered through the instance metadata service. Each has different theft and reuse characteristics, and several AWS services hand back fresh credentials when read.
What folds in here#
- Access keys: long-term
AKIApairs in files, environment variables, CI config, and source history. - Instance metadata: role credentials from IMDS on EC2 and ECS, including the IMDSv2 token flow and SSRF retrieval.
- STS tokens: capturing and replaying short-lived session tokens.
- Secret stores: Secrets Manager, SSM Parameter Store, and KMS as credential sources.
- Credential brokers: services that mint credentials for other principals.
The IMDS pages are the AWS end of the web server-side request forgery technique, cross-referenced rather than duplicated.