Skip to content

feat: add Prowler detection coverage to ecs-006#11

Merged
sethsec merged 2 commits intoDataDog:mainfrom
andoniaf:add-prowler-ecs-006
Feb 23, 2026
Merged

feat: add Prowler detection coverage to ecs-006#11
sethsec merged 2 commits intoDataDog:mainfrom
andoniaf:add-prowler-ecs-006

Conversation

@andoniaf
Copy link
Contributor

Summary

  • Adds Prowler detection tool link to ecs-006 (ecs:ExecuteCommand + ecs:DescribeTasks)
  • Prowler PR #10066 added the ECS+ExecuteCommand privilege escalation pattern, which was the only path skipped in PR Add Prowler detection coverage to 64 attack paths #10
  • Links to the specific commit (4f18bfc) where the pattern was added at L258

Test plan

  • Schema validation passes (python scripts/validate-schema.py data/paths/ecs/ecs-006.yaml)

Prowler PR #10066 added the ECS+ExecuteCommand privilege escalation
pattern, enabling detection of this path. Links to the specific commit
where the pattern was added.
@sethsec sethsec merged commit f7170af into DataDog:main Feb 23, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants