2026 Critical Cloud Control Plane Detection: PassRole Privilege Escalation Chain to Lambda/EC2
Detects a privilege escalation sequence where a principal uses 'PassRole' to attach an IAM role to a newly created compute resource (Lambda, EC2, or CloudFormation stack), followed shortly by that compute resource performing privileged API calls. This behavior indicates a potential attempt to gain unauthorized elevated permissions by executing actions from an over-privileged service identity.
Cortex XDR

