Most Popular Detection 2026: AWS IAM Privilege Escalation via Policy Manipulatio

This rule detects high-risk AWS API calls that are commonly associated with privilege escalation and persistence. It monitors for the creation of overly permissive IAM policies (wildcard permissions), the creation of new access keys for existing users, and suspicious AssumeRole operations.