2026 Critical Cloud Control Plane Detection: PassRole Privilege Escalation Chain

Detects potential privilege escalation sequences in AWS where an identity uses 'iam:PassRole' in conjunction with resource-creation APIs (such as 'lambda:CreateFunction', 'ec2:RunInstances', or 'cloudformation:CreateStack'). This pattern is indicative of an attacker attempting to attach a higher-privileged role to a newly created resource under their control, allowing them to perform actions beyond their current scope.