duo-labs / duo-labs/cloudmapper

Have find_admins look for any non-read-only IAM action

Open
#763 0 comments 0 reactions 0 assignees View on GitHub
audit
Dominant language
JavaScript
Stars
6.3k
Forks
836
PR merge metrics
No merged PRs in 30d

Description

I thought my find_admins command just looked for any IAM privileges that aren't Get, List, or Describe. This is not the case. I think the list of privs I am using could miss some things. Some privs such as `DeleteAccessKey` wouldn't be useful, but I still should do something smarter here than use this list I think. Also need to consider some things like `sts:AssumeRole` and possibly others? Need to think more on this.

https://github.com/duo-labs/cloudmapper/blob/main/shared/iam_audit.py#L161

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.