2026 Critical Cloud Control Plane Detection: AWS CloudShell Abuse for Command Execution and File Staging

Detects the initialization of an AWS CloudShell session followed by file transfer operations (PutFile or GetFile). This behavior may indicate an attacker using CloudShell to stage, exfiltrate, or move tools within the cloud environment, potentially bypassing endpoint detection by operating within the cloud service infrastructure.