Files
elastic-detection-rules/rules/integrations
Samirbous 3ca29eed6e [New] EKS Access Entry Granted Cluster Admin Policy (#6091)
* [New] EKS Access Entry Granted Cluster Admin Policy

Detects when the AmazonEKSClusterAdminPolicy or AmazonEKSAdminPolicy is associated with a principal via the EKS
Access Entries API. This grants full cluster-admin equivalent access to the specified IAM user or role.

* Update rules/integrations/aws/persistence_eks_access_entry_modified.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Update rules/integrations/aws/persistence_eks_access_entry_modified.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Update rules/integrations/aws/privilege_escalation_eks_access_entry_granted_cluster_admin_policy.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Update rules/integrations/aws/privilege_escalation_eks_access_entry_granted_cluster_admin_policy.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Update rules/integrations/aws/privilege_escalation_eks_access_entry_granted_cluster_admin_policy.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Update rules/integrations/aws/persistence_eks_access_entry_modified.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

---------

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

(cherry picked from commit e4994a5478)
2026-05-14 15:49:37 +00:00
..
2026-04-22 18:46:33 +00:00
2025-07-07 11:27:48 -04:00