feat(iam): add ECS Exec privilege escalation detection (ECS-006) (#10066)

This commit is contained in:
Andoni Alonso
2026-02-13 14:45:33 +01:00
committed by GitHub
parent 941f9b7e0b
commit 4f18bfc33c
2 changed files with 6 additions and 0 deletions
+1
View File
@@ -18,6 +18,7 @@ All notable changes to the **Prowler SDK** are documented in this file.
- OCI regions updater script and CI workflow [(#10020)](https://github.com/prowler-cloud/prowler/pull/10020)
- `image` provider for container image scanning with Trivy integration [(#9984)](https://github.com/prowler-cloud/prowler/pull/9984)
- CSA CCM 4.0 for the Alibaba Cloud provider [(#10061)](https://github.com/prowler-cloud/prowler/pull/10061)
- ECS Exec (ECS-006) privilege escalation detection via `ecs:ExecuteCommand` + `ecs:DescribeTasks` [(#10066)](https://github.com/prowler-cloud/prowler/pull/10066)
### 🔄 Changed
@@ -254,6 +254,11 @@ privilege_escalation_policies_combination = {
"iam:PassRole",
"ecs:RunTask",
},
# Prerequisite: Running ECS task with ECS Exec enabled and admin task role
"ECS+ExecuteCommand": {
"ecs:ExecuteCommand",
"ecs:DescribeTasks",
},
# SageMaker-based privilege escalation patterns
"PassRole+SageMakerCreateNotebookInstance": {
"iam:PassRole",