Problem When a GitHub Actions job cannot assume an AWS role through OpenID Connect, the first instinct is often to inspect or widen the role's attached AWS permissions. That can target the wrong layer. sts:AssumeRoleWithWebIdentity is an identity-and-trust decision. AWS evaluates whether the incoming OIDC identity is allowed to obtain the role... Weiterlesen
Intelligence View
GitHub Actions OIDC AccessDenied May Be a Trust-Policy Problem, Not a Permission-Policy Problem
Problem When a GitHub Actions job cannot assume an AWS role through OpenID Connect, the first instinct is often to inspect or widen the role's attached AWS permissions. That can target the wrong layer. sts:AssumeRoleWithWebIdentity is…
SOC Incident Playbook: Vulnerability Remediation & Verification
title: Detect Exploitation - GitHub Actions OIDC AccessDenied May Be a Trust-Policy Problem, Not a Permission-Policy Problem
id: a7daa899-07a8-4e64-b1ba-1635bb2e7fde
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
- https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
category: network_connection
product: any
detection:
selection:
CommandLine|contains:
- 'exploit'
condition: selection
falsepositives:
- Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
- attack.initial_accessrule CTI_Threat_Indicator {
meta:
author = "iShareStuff CTI Automated Detection Engine"
date = "2026-09-24"
description = "YARA Signature for "
strings:
$str = "GitHub Actions OIDC AccessDeni" ascii wide
condition:
any of them
}
SOCIAL SHARE CARD GENERATOR