Identify and manage a collection of IAM privileges in policies that potentially increase security risk.
There are a collection of IAM privileges that are most-often seen in privilege escalation attacks or, in combination, provide more access than likely intended. Some are obvious, but many are subtle… especially for less experienced IAM administrators. This list also can change over time, as AWS changes their IAM model and adds new capabilities. Customers can even become exposed as AWS updates their managed policies, some of which have been granted excessive privileges while customer trust/believe they were scoped to least privilege.
This Op identifies these high risk privileges in IAM policies, and allows you to quarantine the associated user or role or remove the privilege from the policy.
Supported Issue Types:
A high risk privilege configuration was identified in an IAM policy
- The policy _name_ has _violating IAM privileges_ and is associated with _count_ users and roles.
- Quarantine the associated users and roles
- Remove the high-risk privileges
We spend a lot of time talking to cloud security professionals, basically trying to figure out the best ways to get their jobs done in largely uncharted territory. Cloud technology is evolving at an unprecedented [...]
In Quick and Dirty: Building an S3 guardrail with Config we highlighted one of the big problems with Config: you need to set it up in each region of each account. Your best bet to make [...]