2026 Critical Cloud Control Plane Detection: Access Key Created for a Privileged Account by a Non-Owner Principal
Detects 'CreateAccessKey' API calls in AWS CloudTrail where the principal making the request is different from the target IAM user. This pattern is commonly associated with persistence mechanisms where an attacker creates additional access keys on legitimate administrator accounts to maintain stealthy access.
Sigma

