Role assumption

A role is assumable by whoever its trust policy allows. sts:AssumeRole returns temporary credentials for the role, and because trust policies are frequently written too broadly (a whole account as principal, a wildcard, or a third-party account with no external ID), role assumption is both a lateral-movement and an escalation primitive.

Assuming a role#

bash
aws sts assume-role \
  --role-arn arn:aws:iam::<acct>:role/<role> \
  --role-session-name s --query Credentials
# export AccessKeyId / SecretAccessKey / SessionToken and continue as the role

What folds in here#

  • Cross-account: trust policies that name another account (or root), letting any principal there assume in.
  • Confused deputy: third-party-vendor roles assumable without the external ID that was meant to scope them.

Finding assumable roles#

Read trust documents from the enumeration dump and look for Principal values broader than a single role ARN, and for sts:AssumeRole statements missing a Condition on sts:ExternalId.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more