AWS sts:AssumeRoot followed by security tampering or destructive actions

Detects the rare 'AssumeRoot' event in AWS STS followed by high-impact administrative or destructive API calls within a one-hour window. This behavior often indicates an adversary attempting to gain elevated, privileged access to perform unauthorized actions such as disabling logging, deleting infrastructure, or modifying IAM policies.