To be fair to the folks at Capital One, the mitigation leverages a feature that wasn't released until well after they were compromised.
https://aws.amazon.com/blogs/security/defense-in-depth-open-...
I would also suggest taking a look at the various articles around AWS IAM privilege escalation:
https://rhinosecuritylabs.com/aws/aws-privilege-escalation-m...
https://know.bishopfox.com/research/privilege-escalation-in-... (just shared on HN recently)