AI Agent Privilege Escalation via Elevation Control Abuse

Detects unauthorized privilege escalation for AI agent identities within an orchestration platform. The rule triggers when an AI agent account receives an IAM role change, API scope grant, or tool permission update that lacks a corresponding human-approval audit event, or occurs shortly after the agent generates logs indicating potential prompt injection or anomalous behavior.