AWS Console sessions can be spawned using tools such as aws-vault to make certain actions much easier than using the AWS CLI. You need to have either sts:GetFederationToken or sts:AssumeRole permissions to generate the temporary credentials you will need.
Use of this technique generates suspicious CloudTrail logs and is not recommended if attempting to avoid detection. Use the -s flag to generate a link without automatically opening a new tab in your browser.
















