elastic
medium
kql
AWS EKS Access Entry Modified
Detects successful Amazon EKS Access Entries API operations that create, update, attach, detach, or delete authentication
mappings between IAM principals and the cluster. Changes to access entries alter who can authenticate to Kubernetes and
what Kubernetes-level permissions they receive, without requiring edits to in-cluster RBAC objects. Unexpected callers
or timing may indicate persistence or privilege abuse. Common automation identities (service-linked roles, eksctl,
Terraform, CloudFormatio