Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[AWS] Add boundary support #508

Closed
Renizmy opened this issue Apr 8, 2024 · 5 comments
Closed

[AWS] Add boundary support #508

Renizmy opened this issue Apr 8, 2024 · 5 comments
Labels
kind/question Further information is requested

Comments

@Renizmy
Copy link

Renizmy commented Apr 8, 2024

Hello,
In corporate environments, it is common to have boundary policies implemented. It could be interesting to be able to import them to be more "realistic"

Link: https://docs.aws.amazon.com/IAM/latest/UserGuide/access_policies_boundaries.html

@christophetd
Copy link
Contributor

Thanks for the suggestion!

To make sure I understand this properly, are you suggesting that we add a new attack technique related to permissions boundaries, or something else?

@christophetd christophetd added the kind/question Further information is requested label Apr 8, 2024
@Renizmy
Copy link
Author

Renizmy commented Apr 12, 2024

Something else, for example this scenario needs to create a new role. In corporate environnement, a common scenario is to restrict the creation of new role by importing a boundary

The main idea is to add an optional parameter to be able to import a boundary for creating this type of resources

@christophetd
Copy link
Contributor

What do you mean by "import a boundary"?

@Renizmy
Copy link
Author

Renizmy commented Apr 12, 2024

@christophetd
Copy link
Contributor

The current pre-requisites for Stratus Red Team indicate that you should run it as admin, in a sandbox. Documenting each and every permission required for each technique might be a valuable item, I'm going to track this in #555

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
kind/question Further information is requested
Projects
None yet
Development

No branches or pull requests

2 participants