mirror of
https://github.com/elastic/detection-rules
synced 2026-06-08 14:00:08 +00:00
3ca29eed6e
* [New] EKS Access Entry Granted Cluster Admin Policy
Detects when the AmazonEKSClusterAdminPolicy or AmazonEKSAdminPolicy is associated with a principal via the EKS
Access Entries API. This grants full cluster-admin equivalent access to the specified IAM user or role.
* Update rules/integrations/aws/persistence_eks_access_entry_modified.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
* Update rules/integrations/aws/persistence_eks_access_entry_modified.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
* Update rules/integrations/aws/privilege_escalation_eks_access_entry_granted_cluster_admin_policy.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
* Update rules/integrations/aws/privilege_escalation_eks_access_entry_granted_cluster_admin_policy.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
* Update rules/integrations/aws/privilege_escalation_eks_access_entry_granted_cluster_admin_policy.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
* Update rules/integrations/aws/persistence_eks_access_entry_modified.toml
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
---------
Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>
(cherry picked from commit e4994a5478)