Hacking-the-Cloud / hackingthe.cloud

An encyclopedia for offensive and defensive security knowledge in cloud native technologies.
https://hackingthe.cloud
Other
1.72k stars 216 forks source link

Obfuscated Admin Policy #419

Open Frichetten opened 2 months ago

Frichetten commented 2 months ago

Some actors spam the AdministratorAccess Policy which is poor OpSec. They should instead (if they have the permissions), obfuscate their permissions with a policy that permits this. I'm thinking *, ?, the whole nine yards.

Frichetten commented 2 weeks ago

Permiso has some really good content on this in a blog post. Need to reference it and their tool. https://permiso.io/blog/introducing-sky-scalpel-open-source-tool