AWS introduced EC2 Instance Metadata Service Version 2 (IMDSv2) to reduce theft of instance metadata and IAM role credentials through server-side request forgery (SSRF), open web application firewalls, reverse proxies, and network-device misconfigurations. IMDSv2 requires a session-oriented HTTP PUT request to obtain a secret token before metadata access; organizations can enforce IMDSv2-only access or disable IMDS, while AWS provides usage metrics, CloudTrail logging, updated SDKs and CLIs, and the ec2:RoleDelivery IAM context key to support migration from IMDSv1.
IMDS hardening addresses only one of several credential-access routes available after AWS compute compromise. Attackers may also obtain credentials from hard-coded application secrets, environment variables, local credential files, container credential endpoints, EKS identity mechanisms, and services such as Systems Manager, IoT, IAM Roles Anywhere, Cognito, and DataSync. Security teams should enforce IMDSv2 where applicable and monitor these additional credential stores, endpoints, tokens, and certificates because a single EC2 workload can expose multiple IAM principals.

Map this exposure pattern across your cloud, code, and identities.
1 event from the most recent confirmed update back to the earliest known activity.
AWS made IMDSv2 available for Amazon EC2, adding PUT-based session-token authentication and protections intended to reduce credential exposure through SSRF flaws and misconfigured proxies or network devices. The rollout included IMDSv2-capable SDKs and CLIs, IMDSv1-usage monitoring, and IAM context-key support for distinguishing credential delivery versions.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See where this exposure pattern shows up across your cloud, code, supply chain, and non-human identities.
2 references tracked. Mallory keeps watching after this page renders.
wiz.io
Open sourceaws.amazon.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.