One IAM Role to Rule Them All: The Cloud Security Blast Radius Nobody Designed
Cloud Breach Radar
0:00 / 0:00
One IAM Role to Rule Them All: The Cloud Security Blast Radius Nobody Designed
10 просмотров · 6 дней назад
Cloud Breach Radar
1 подписчик
10 просмотров · 6 дней назад
#cloudsecurity #CSPM #CNAPP
One IAM role trusted by everything is the biggest cloud security blast radius in your account. Here is how it grows and how to shrink it. In the 2019 Capital One breach a single web application firewall role could list and copy more than 700 S3 buckets, and 106 million records left with it. The firewall needed none of them. This video is about that role: the shared admin role every pipeline, cluster and vendor integration is trusted to assume.
Chapters:
00:00 The answer: one role, 700 buckets
00:47 How the shared role is born
01:36 How attackers reach it
02:33 The blast radius, measured
03:27 Control 1: split the role
04:18 Controls 2 and 3: shrink and detect
05:08 Count the principals
In this video you will learn:
How a shared admin role accumulates one Friday shortcut at a time
Why any foothold that can call sts:AssumeRole reaches the whole account
The numbers: under 5% of granted permissions used, 78% of orgs hold a 90-day-unused role
Control 1: one workload, one role, one trust policy, capped by a permissions boundary
Control 2: shrink with IAM Access Analyzer unused-access findings
Control 3: count AssumeRole sources per role and alert on the new one
For cloud engineers and security leads who know IAM basics but have never audited who can assume their widest role.
Sources
Capital One breach retrospective (Huntress): https://www.huntress.com/threat-library/da...
Datadog State of Cloud Security 2024: https://www.datadoghq.com/blog/cloud-secur...
Orca Security cloud least privilege guide (Orca 2025 and Microsoft permission statistics): https://orca.security/resources/blog/cloud...
AWS IAM Access Analyzer unused access: https://docs.aws.amazon.com/IAM/latest/Use...
AWS permissions boundaries: https://docs.aws.amazon.com/IAM/latest/Use...
MITRE ATT&CK T1078.004 Valid Accounts, Cloud Accounts: https://attack.mitre.org/techniques/T1078/...
Cloud Breach Radar is produced with Orca Security, the agentless cloud security platform that maps which identities can reach which data.
Count the principals that can reach your widest role this week. If it is more than one, you know where to start.
#cloudsecurity #CSPM #CNAPP #AWSsecurity #Azuresecurity #IAM #leastprivilege #AWSIAM