Перейти к содержимому

One IAM Role to Rule Them All: The Cloud Security Blast Radius Nobody Designed

Cloud Breach Radar

0:00 / 0:00

One IAM Role to Rule Them All: The Cloud Security Blast Radius Nobody Designed

10 просмотров · 6 дней назад
Cloud Breach Radar
1 подписчик
10 просмотров · 6 дней назад
#cloudsecurity #CSPM #CNAPP One IAM role trusted by everything is the biggest cloud security blast radius in your account. Here is how it grows and how to shrink it. In the 2019 Capital One breach a single web application firewall role could list and copy more than 700 S3 buckets, and 106 million records left with it. The firewall needed none of them. This video is about that role: the shared admin role every pipeline, cluster and vendor integration is trusted to assume. Chapters: 00:00 The answer: one role, 700 buckets 00:47 How the shared role is born 01:36 How attackers reach it 02:33 The blast radius, measured 03:27 Control 1: split the role 04:18 Controls 2 and 3: shrink and detect 05:08 Count the principals In this video you will learn: How a shared admin role accumulates one Friday shortcut at a time Why any foothold that can call sts:AssumeRole reaches the whole account The numbers: under 5% of granted permissions used, 78% of orgs hold a 90-day-unused role Control 1: one workload, one role, one trust policy, capped by a permissions boundary Control 2: shrink with IAM Access Analyzer unused-access findings Control 3: count AssumeRole sources per role and alert on the new one For cloud engineers and security leads who know IAM basics but have never audited who can assume their widest role. Sources Capital One breach retrospective (Huntress): https://www.huntress.com/threat-library/da... Datadog State of Cloud Security 2024: https://www.datadoghq.com/blog/cloud-secur... Orca Security cloud least privilege guide (Orca 2025 and Microsoft permission statistics): https://orca.security/resources/blog/cloud... AWS IAM Access Analyzer unused access: https://docs.aws.amazon.com/IAM/latest/Use... AWS permissions boundaries: https://docs.aws.amazon.com/IAM/latest/Use... MITRE ATT&CK T1078.004 Valid Accounts, Cloud Accounts: https://attack.mitre.org/techniques/T1078/... Cloud Breach Radar is produced with Orca Security, the agentless cloud security platform that maps which identities can reach which data. Count the principals that can reach your widest role this week. If it is more than one, you know where to start. #cloudsecurity #CSPM #CNAPP #AWSsecurity #Azuresecurity #IAM #leastprivilege #AWSIAM