mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-10-04 02:04:06 +00:00
feat(iam): add ECS Exec privilege escalation detection (ECS-006) (#10066)
This commit is contained in:
@@ -18,6 +18,7 @@ All notable changes to the **Prowler SDK** are documented in this file.
|
||||
- OCI regions updater script and CI workflow [(#10020)](https://github.com/prowler-cloud/prowler/pull/10020)
|
||||
- `image` provider for container image scanning with Trivy integration [(#9984)](https://github.com/prowler-cloud/prowler/pull/9984)
|
||||
- CSA CCM 4.0 for the Alibaba Cloud provider [(#10061)](https://github.com/prowler-cloud/prowler/pull/10061)
|
||||
- ECS Exec (ECS-006) privilege escalation detection via `ecs:ExecuteCommand` + `ecs:DescribeTasks` [(#10066)](https://github.com/prowler-cloud/prowler/pull/10066)
|
||||
|
||||
### 🔄 Changed
|
||||
|
||||
|
||||
@@ -254,6 +254,11 @@ privilege_escalation_policies_combination = {
|
||||
"iam:PassRole",
|
||||
"ecs:RunTask",
|
||||
},
|
||||
# Prerequisite: Running ECS task with ECS Exec enabled and admin task role
|
||||
"ECS+ExecuteCommand": {
|
||||
"ecs:ExecuteCommand",
|
||||
"ecs:DescribeTasks",
|
||||
},
|
||||
# SageMaker-based privilege escalation patterns
|
||||
"PassRole+SageMakerCreateNotebookInstance": {
|
||||
"iam:PassRole",
|
||||
|
||||
Reference in New Issue
Block a user