From 4f18bfc33cd2709ef3535e7c3ee0ad7ad72e8aa2 Mon Sep 17 00:00:00 2001 From: Andoni Alonso <14891798+andoniaf@users.noreply.github.com> Date: Fri, 13 Feb 2026 14:45:33 +0100 Subject: [PATCH] feat(iam): add ECS Exec privilege escalation detection (ECS-006) (#10066) --- prowler/CHANGELOG.md | 1 + .../providers/aws/services/iam/lib/privilege_escalation.py | 5 +++++ 2 files changed, 6 insertions(+) diff --git a/prowler/CHANGELOG.md b/prowler/CHANGELOG.md index 4d9abc30ed..4338fbf033 100644 --- a/prowler/CHANGELOG.md +++ b/prowler/CHANGELOG.md @@ -18,6 +18,7 @@ All notable changes to the **Prowler SDK** are documented in this file. - OCI regions updater script and CI workflow [(#10020)](https://github.com/prowler-cloud/prowler/pull/10020) - `image` provider for container image scanning with Trivy integration [(#9984)](https://github.com/prowler-cloud/prowler/pull/9984) - CSA CCM 4.0 for the Alibaba Cloud provider [(#10061)](https://github.com/prowler-cloud/prowler/pull/10061) +- ECS Exec (ECS-006) privilege escalation detection via `ecs:ExecuteCommand` + `ecs:DescribeTasks` [(#10066)](https://github.com/prowler-cloud/prowler/pull/10066) ### 🔄 Changed diff --git a/prowler/providers/aws/services/iam/lib/privilege_escalation.py b/prowler/providers/aws/services/iam/lib/privilege_escalation.py index 99d3e4dad9..9fded2d5c9 100644 --- a/prowler/providers/aws/services/iam/lib/privilege_escalation.py +++ b/prowler/providers/aws/services/iam/lib/privilege_escalation.py @@ -254,6 +254,11 @@ privilege_escalation_policies_combination = { "iam:PassRole", "ecs:RunTask", }, + # Prerequisite: Running ECS task with ECS Exec enabled and admin task role + "ECS+ExecuteCommand": { + "ecs:ExecuteCommand", + "ecs:DescribeTasks", + }, # SageMaker-based privilege escalation patterns "PassRole+SageMakerCreateNotebookInstance": { "iam:PassRole",