elastic
medium
kql
AWS IAM Permission Boundary or Guardrail Policy Deleted by Unusual Identity
Detects the first time an AWS identity successfully deletes an IAM managed policy whose ARN contains
guardrail-related keywords (for example Boundary, Deny, Restrict, Guard, SCP, Guardrail). Adversaries who have
obtained elevated IAM privileges may delete policies to remove restrictive permissions boundaries,
eliminate deny-based guardrails, or clean up after a privilege escalation operation. Infrastructure-as-code tools (Terraform, CloudFormation, Pulumi, and Ansible) are excluded because polic