2026 Critical Cloud Control Plane Detection: Inline IAM Policy Attachment Granting Wildcard Administrative Permissions
Detects the modification or attachment of IAM policies to users or roles that contain wildcard 'Allow' permissions for all actions and resources. This behavior is indicative of privilege escalation where an identity is granted full administrative control over the AWS account.
Sigma

