Identify and manage a collection of IAM privileges in policies that potentially increase security risk.
There are a collection of IAM privileges that are most-often seen in privilege escalation attacks or, in combination, provide more access than likely intended. Some are obvious, but many are subtle… especially for less experienced IAM administrators. This list also can change over time, as AWS changes their IAM model and adds new capabilities. Customers can even become exposed as AWS updates their managed policies, some of which have been granted excessive privileges while customer trust/believe they were scoped to least privilege.
This Op identifies these high risk privileges in IAM policies, and allows you to quarantine the associated user or role or remove the privilege from the policy.