Detection catalogue
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
- detections
Loading detections…
Loading detections
Explore published rules with transparent provenance, licensing, and ATT&CK mappings.
Loading detections…
Detects successful attachment of AWS managed policies containing FullAccess permissions to users, roles, or groups, excluding admin-named policies. This action can rapidly expand privilege scope and should be reviewed as potential cloud privilege escalation.
Outside the enterprise matrix
Published to signed-in readers
The query as its source wrote it, its canonical form, and the content hash that pins this exact revision.