-
Notifications
You must be signed in to change notification settings - Fork 216
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[AWS] Add boundary support #508
Comments
Thanks for the suggestion! To make sure I understand this properly, are you suggesting that we add a new attack technique related to permissions boundaries, or something else? |
Something else, for example this scenario needs to create a new role. In corporate environnement, a common scenario is to restrict the creation of new role by importing a boundary The main idea is to add an optional parameter to be able to import a boundary for creating this type of resources |
What do you mean by "import a boundary"? |
The current pre-requisites for Stratus Red Team indicate that you should run it as admin, in a sandbox. Documenting each and every permission required for each technique might be a valuable item, I'm going to track this in #555 |
Hello,
In corporate environments, it is common to have boundary policies implemented. It could be interesting to be able to import them to be more "realistic"
Link: https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_boundaries.html
The text was updated successfully, but these errors were encountered: