What is the FASTEST way for the security engineer to identify the federated user?

1 Comment

  1. Jessica
    Author

    I weigh that the answer is:
    Filter the AWS CloudTrail event history for the TerminateInstances event and identify the assumed IAM role. Review the AssumeRoleWithSAML event call in CloudTrail to identify the corresponding username.

Leave a Reply

Your email address will not be published. Required fields are marked *

eighteen + 9 =