Amazon Web Services Beta
How: read-only AWS API queries, using a role in your account that this
platform assumes. There is no AWS credential of yours to store: the session the
role yields expires in an hour.
Needs: a role carrying AWS’s own SecurityAudit
managed policy, whose trust policy names this platform and requires an external
ID. The external ID is generated per connection and is not optional —
without it, a role that trusts us could be assumed on behalf of anyone who learns
its ARN.
Reads: EC2 instances and their security groups, S3 bucket access
settings, IAM roles, users and policy attachments, RDS instance settings, and the
existence of secrets.
Finds: management ports open to any address, instances with public
addresses, instance metadata service v1 still permitted where a role is attached,
publicly accessible buckets and databases, users holding account-wide policies,
console users without MFA, long-lived access keys, roles assumable from outside
the account, and an internet-facing instance carrying a role that holds
account-wide privilege.
Cannot determine: what is inside a bucket, a secret or a key —
the policy requested grants no permission to read the contents of anything, which
is deliberate. Nor anything in a region you did not select for collection: those
are reported as unassessed rather than clean, because a region nobody read is
invisible, not empty.
Into the graph: accounts, instances, buckets, databases and roles
become nodes, and the escalation route becomes edges. That last one is the point:
Internet → an instance with SSH open → the role its instance profile
carries → AdministratorAccess across the account is a path, and neither
half of it is visible on its own. Where IMDSv1 is still permitted the first step
gets cheaper still, because a server-side request forgery reaches the credentials
without code execution at all.