1200KM / detection
T1550.001 Application Access Token — Detection Rules
Detection workspace for T1550.001 Application Access Token: 4 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- AWS Console GetSigninToken Potential Abuse · test · medium · {"product":"aws","service":"cloudtrail"}
- AWS STS AssumeRole Misuse · test · low · {"product":"aws","service":"cloudtrail"}
- AWS STS GetSessionToken Misuse · test · low · {"product":"aws","service":"cloudtrail"}
- AWS Suspicious SAML Activity · test · medium · {"product":"aws","service":"cloudtrail"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0185 Behavioral Detection Strategy for Use Alternate Authentication Material: Application Access Token (T1550.001)
AN0526 Analytic 0526
Use of AWS STS or GCP IAM APIs to request temporary tokens or federation sessions inconsistent with normal account activity, including from unexpected principals or regions.
AN0527 Analytic 0527
OAuth or SAML access tokens reused across multiple sessions or clients without corresponding MFA or login activity.
AN0528 Analytic 0528
Application access tokens used to call APIs (e.g., Google Workspace, Salesforce) without interactive logins, often with unusual scopes or elevated permissions.
AN0529 Analytic 0529
OAuth token usage for Exchange Online or SharePoint API access without preceding login or from unauthorized clients.
AN0530 Analytic 0530
Compromised service account tokens mounted inside containers and reused for external API calls or lateral movement across services.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Connected anomaly research
Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.
Telemetry contracts · Maintained query examples · Validation and blind spots
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.