Files
elastic-detection-rules/rules/integrations
Samirbous bc90efe086 [New] EKS Access Entry Granted Cluster Admin Policy (#6091)
* [New] EKS Access Entry Granted Cluster Admin Policy

Detects when the AmazonEKSClusterAdminPolicy or AmazonEKSAdminPolicy is associated with a principal via the EKS
Access Entries API. This grants full cluster-admin equivalent access to the specified IAM user or role.

* Update rules/integrations/aws/persistence_eks_access_entry_modified.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Update rules/integrations/aws/persistence_eks_access_entry_modified.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Update rules/integrations/aws/privilege_escalation_eks_access_entry_granted_cluster_admin_policy.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Update rules/integrations/aws/privilege_escalation_eks_access_entry_granted_cluster_admin_policy.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Update rules/integrations/aws/privilege_escalation_eks_access_entry_granted_cluster_admin_policy.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

* Update rules/integrations/aws/persistence_eks_access_entry_modified.toml

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

---------

Co-authored-by: Isai <59296946+imays11@users.noreply.github.com>

(cherry picked from commit e4994a5478)
2026-05-14 15:48:36 +00:00
..
2026-04-22 18:45:36 +00:00
2025-07-07 11:27:48 -04:00