AWS Identity Center Identity Provider Change — Detection Rule

Detects a change in the AWS Identity Center (FKA AWS SSO) identity provider. A change in identity provider allows an attacker to establish persistent access or escalate privileges via user impersonation.

Read the full analysis on IntelFusions