2026 Critical Cloud Control Plane Detection: Cross-Account AssumeRole Chaining (Role-Chain Escalation)

Detects chained AWS STS AssumeRole/AssumeRoleWithSAML/AssumeRoleWithWebIdentity events where a principal assumes a role in a different account and then quickly performs another role assumption from that new context. This pattern, often referred to as 'role chaining' or 'role laundering', is frequently used to obfuscate identity tracking and facilitate lateral movement across AWS account boundaries.