2026 Critical Cloud Control Plane Detection: Rogue Federated Identity Provider T

Detects modifications to AWS IAM trust relationships, specifically the creation or update of SAML providers, OIDC providers, or the update of role trust policies containing wildcard principals. These actions are indicative of an attacker attempting to establish a durable, credential-less persistence mechanism via federated identity manipulation.