Mods
AWS

IAM Role: AWS/Shield/Admin

PermissionGrant
iam:PassRoleAdmin
shield:AssociateDRTLogBucketAdmin
shield:AssociateDRTRoleAdmin
shield:CreateProtectionAdmin
shield:CreateSubscriptionAdmin
shield:DeleteProtectionAdmin
shield:DeleteSubscriptionAdmin
shield:DisassociateDRTLogBucketAdmin
shield:DisassociateDRTRoleAdmin
shield:UpdateEmergencyContactSettingsAdmin
shield:UpdateSubscriptionAdmin
iam:GetRoleMetadata
iam:ListAttachedRolePoliciesMetadata
s3:GetBucketPolicyMetadata
shield:DescribeAttackMetadata
shield:DescribeDRTAccessMetadata
shield:DescribeEmergencyContactSettingsMetadata
shield:DescribeProtectionMetadata
shield:DescribeSubscriptionMetadata
shield:GetSubscriptionStateMetadata
shield:ListAttacksMetadata
shield:ListProtectionsMetadata