AWS IAM Privilege Escalation via Overly-Permissive Policy Attach
Detects modifications to AWS IAM policies (user or role policies) that grant AdministratorAccess, PowerUserAccess, or wildcard permissions (*). This is a common indicator of privilege escalation or persistence, where an attacker grants themselves or another identity broad administrative access within the AWS account.
Cortex XDR

