2026 Critical Cloud Control Plane Detection: Suspicious IAM Trust Policy Modification Enabling Cross-Account Access
Detects modifications to IAM role trust policies (UpdateAssumeRolePolicy) or the creation of new roles (CreateRole) where the Principal is configured with a wildcard or generic open access. This configuration enables any AWS account to assume the role, representing a significant risk for privilege escalation and persistence establishment by attackers.
Sigma

