Most Popular Detection 2026: AWS IAM Privilege Escalation via Suspicious Role Assumption

Detects potential AWS IAM privilege escalation attempts by identifying suspicious modifications to IAM policies, roles, or trust relationships, as well as unauthorized role assumption events. This rule monitors for activities such as attaching high-privilege policies (e.g., AdministratorAccess), creating new policy versions, and modifying trust policies to allow unexpected principals, which are common indicators of post-compromise activity designed to expand access within an AWS environment.