cloudforge v1.4.0 AWS IAM policy version · seed 43

brief

# Lab: `iam_privesc_policy_version`

b2b_saas / medium / `enterprise-payroll` · prod

## Your job

An internal developer identity has been provisioned with limited scope. Can it reach a role that administers the account, and how?

For each path, name where it starts, what opens the way, and what the attacker reaches. That is not always data: it can be a role, a key, a secret, an image, a queue, a snapshot or a database.

## Resources

- `n33_82c1/acct-main`: **Account** prod-account-82c1
- `n41_82c1/role-developer`: **IAMRole** DeveloperOperationsRole-82c1
- `n18_82c1/pol-dev-tools`: **IAMPolicy** PolicyLifecycleManagementPolicy-82c1
- `n27_82c1/role-app-operator`: **IAMRole** AppOperatorRole-82c1
- `n03_82c1/pol-target-app`: **IAMPolicy** AppOperatorDataPolicy-82c1
- `n07_82c1/s3-payroll-records`: **S3Bucket** payroll-records-prod-000000000000-82c1
- `n00_82c1/data-payroll-records`: **DataSet** payroll-financial-records-82c1
- `n08_82c1/role-migration-helper`: **IAMRole** MigrationHelperRole-82c1
- `n05_82c1/pol-migration-helper-read`: **IAMPolicy** MigrationHelperReadPolicy-82c1
- `n06_82c1/s3-open-data`: **S3Bucket** open-data-exports-82c1
- `n45_82c1/s3-open-data`: **S3Bucket** open-data-exports-2-82c1
- `n10_82c1/s3-ml-features`: **S3Bucket** ml-feature-store-82c1
- `n17_82c1/trail-ml-features`: **LogTrail** trail-ml-features-82c1
- `n02_82c1/data-ml-features`: **DataSet** feature-vectors-82c1
- `n21_82c1/s3-ops-runbooks`: **S3Bucket** ops-runbooks-82c1
- `n30_82c1/trail-ops-runbooks`: **LogTrail** trail-ops-runbooks-82c1
- `n28_82c1/data-ops-runbooks`: **DataSet** runbook-library-82c1
- `n13_82c1/role-datadog-monitoring`: **IAMRole** DatadogMonitoringRole-82c1
- `n26_82c1/data-operational-metrics`: **DataSet** data-operational-metrics-82c1
- `n04_82c1/trail-security-secondary`: **LogTrail** trail-security-secondary-82c1
- `n14_82c1/s3-build-artifacts`: **S3Bucket** build-artifacts-82c1
- `n24_82c1/role-datadog-monitoring`: **IAMRole** DatadogMonitoringRole-2-82c1
- `n39_82c1/ecr-analytics-worker`: **EcrRepository** repo-analytics-worker-82c1
- `n19_82c1/role-backup-runner`: **IAMRole** BackupRunnerRole-82c1
- `n32_82c1/ecr-base-runner`: **EcrRepository** repo-base-runner-82c1
- `n43_82c1/s3-backup-vault`: **S3Bucket** backup-vault-82c1
- `n40_82c1/ecr-utility-image`: **EcrRepository** repo-utility-image-82c1
- `n01_82c1/role-backup-runner`: **IAMRole** BackupRunnerRole-2-82c1
- `n34_82c1/ecr-collector-agent`: **EcrRepository** repo-collector-agent-82c1
- `n38_82c1/kms-internal-telemetry`: **KmsKey** kms-internal-telemetry-82c1
- `n35_82c1/ecr-collector-agent`: **EcrRepository** repo-collector-agent-2-82c1
- `n12_82c1/trail-audit-operations`: **LogTrail** trail-audit-operations-82c1
- `n15_82c1/ecr-analytics-worker`: **EcrRepository** repo-analytics-worker-2-82c1
- `n29_82c1/trail-security-secondary`: **LogTrail** trail-security-secondary-2-82c1
- `n36_82c1/role-cloud-watch-agent`: **IAMRole** CloudWatchAgentRole-82c1
- `n09_82c1/role-datadog-monitoring`: **IAMRole** DatadogMonitoringRole-3-82c1
- `n31_82c1/sqs-notifications-stream`: **SqsQueue** notifications-stream-82c1
- `n37_82c1/s3-build-artifacts`: **S3Bucket** build-artifacts-2-82c1
- `n44_82c1/trail-security-secondary`: **LogTrail** trail-security-secondary-3-82c1
- `n16_82c1/s3-backup-vault`: **S3Bucket** backup-vault-2-82c1
- `n22_82c1/trail-audit-operations`: **LogTrail** trail-audit-operations-2-82c1
- `n20_82c1/s3-build-artifacts`: **S3Bucket** build-artifacts-3-82c1
- `n42_82c1/role-prometheus-agent`: **IAMRole** PrometheusAgentRole-82c1
- `n25_82c1/sqs-audit-events`: **SqsQueue** audit-events-82c1
- `n11_82c1/s3-build-artifacts`: **S3Bucket** build-artifacts-4-82c1
- `n23_82c1/sqs-ingest-pipeline`: **SqsQueue** ingest-pipeline-82c1

## Relationships

- `n33_82c1/acct-main` --assumes--> `n41_82c1/role-developer`
- `n41_82c1/role-developer` --attached_policy--> `n18_82c1/pol-dev-tools`
- `n41_82c1/role-developer` --assumes--> `n27_82c1/role-app-operator`
- `n27_82c1/role-app-operator` --attached_policy--> `n03_82c1/pol-target-app`
- `n27_82c1/role-app-operator` --can_read--> `n07_82c1/s3-payroll-records`
- `n07_82c1/s3-payroll-records` --stores_sensitive_data--> `n00_82c1/data-payroll-records`
- `n08_82c1/role-migration-helper` --attached_policy--> `n05_82c1/pol-migration-helper-read`
- `n10_82c1/s3-ml-features` --logs_to--> `n17_82c1/trail-ml-features`
- `n10_82c1/s3-ml-features` --stores_sensitive_data--> `n02_82c1/data-ml-features`
- `n21_82c1/s3-ops-runbooks` --logs_to--> `n30_82c1/trail-ops-runbooks`
- `n21_82c1/s3-ops-runbooks` --stores_sensitive_data--> `n28_82c1/data-ops-runbooks`

how this works

This estate was prebaked. A unique copy composes on the server in about 20 ms from a scenario spec: 10,000 seeds per family, 15 families. No cloud account was touched; the graph is the source of truth.

The grade is one call to TypeSafe Jev: three yes/no questions (entry, hop, sink) and one depth score (0 to 3, fewer rungs on a short path), typed probabilities back. No grade yet on this page.