2026 Critical Cloud Control Plane Detection: AWS Malicious Access Key Creation for IAM User

Detects the creation of new AWS IAM access keys where the actor initiating the request is distinct from the target user associated with the key. This behavior often indicates an adversary attempting to establish persistent access to a compromised account by creating additional, long-lived credentials.