3 ms·
Years ago I wrote a program to let various services run their course, query Cloudtrail for successful calls madero different AWS services, and attempt to find a
by devonkim 6y ago
Years ago I wrote a program to let various services run their course, query Cloudtrail for successful calls madero different AWS services, and attempt to find a minimal set of IAM permissions (not applicable for S3 at the time). The idea was to run an exhaustive test suite with expected allowed actions only and deny anything else. I believe AWS has a similar tool now for IAM but it’s not a problem that’ll be resolved satisfactorily for everyone given the combinatorics of IAM possible. Lateral movement in IAM roles and credentials is tough and even today not every action that IMO should be flagged is reported (IAM role assumption failures across accounts is silent when I checked early last year).
- kmcquade 6y agoDid you open source it? If not, you definitely should.
- devonkim 6y agoProbably can’t be open sourced given IP under contracts but I could try to re-write it. There’s some new services in IAM that could be leveraged to make it more accurate and cheaper to use, too.
- jsperx 6y agoThank you for putting this idea in my head! I’ve been trying to get better at expressing infrastructure as code, and one of the big blockers has been how adding new services to e.g. Terraform is tough when you don’t know all their permissions they need (see also https://github.com/hashicorp/terraform/issues/2834 https://github.com/hashicorp/terraform/issues/2834 for example). Using a test AWS environment to stage and then checking CloudTrail to see what was actually called would be a step forward. Having software to extract it would be even better.
- paulz_ 6y agoSomeone has actually been working on a project like this. While not 100% complete it's the best working one I know of. Can definitely relate to the problem being described here, especially when writing IAM policies for terraform deployments. https://github.com/flosell/trailscraper https://github.com/flosell/trailscraper
- AnHonestComment 6y agoAWS actually has a research team applying formal methods to IAM because doing it by hand is impossible. https://aws.amazon.com/iam/features/analyze-access/ https://aws.amazon.com/iam/features/analyze-access/