2026 Critical Cloud Control Plane Detection: Backdoor IAM User or Role Created with Long-Lived Credentials and Broad Trust Policy

Detects potential persistence mechanisms in AWS by monitoring the creation of new IAM users or roles, the issuance of long-lived credentials (access keys or login profiles), or the creation of roles with permissive cross-account trust policies. This rule specifically excludes known legitimate automation roles to reduce noise.