Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- detections
Loading detections…
Loading detections
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
Loading detections…
Identifies creation of IAM policies that grant broad AWS Glue permissions paired with IAM permissions, followed by policy attachment to a principal. This sequence can indicate unauthorized privilege expansion and should be reviewed for potential cloud account manipulation.
Published to signed-in readers
The query as its source wrote it, its canonical form, and the content hash that pins this exact revision.