AWS IAM Privilege Escalation or CloudTrail Logging Tampering

Detects high-risk AWS API calls indicative of privilege escalation within IAM (e.g., policy attachments, credential creation) or activities aimed at tampering with or disabling CloudTrail logging, which is often a precursor to or indication of unauthorized activity to evade detection.