2026 Critical Cloud Control Plane Detection: AWS Snapshot/AMI Theft via External Account Sharing

This rule detects modifications to AWS EC2 Snapshot or AMI (Image) attributes that result in the resource becoming publicly accessible ('all') or shared with an unapproved AWS account ID. Such activities are often precursors to data exfiltration or unauthorized access to sensitive disk images.