# Lab: `iam_privesc_policy_version` b2b_saas / medium / `enterprise-payroll` · prod ## Your job An internal developer identity has been provisioned with limited scope. Can it reach a role that administers the account, and how? For each path, name where it starts, what opens the way, and what the attacker reaches. That is not always data: it can be a role, a key, a secret, an image, a queue, a snapshot or a database. ## Resources - `n33_82c1/acct-main`: **Account** prod-account-82c1 - `n41_82c1/role-developer`: **IAMRole** DeveloperOperationsRole-82c1 - `n18_82c1/pol-dev-tools`: **IAMPolicy** PolicyLifecycleManagementPolicy-82c1 - `n27_82c1/role-app-operator`: **IAMRole** AppOperatorRole-82c1 - `n03_82c1/pol-target-app`: **IAMPolicy** AppOperatorDataPolicy-82c1 - `n07_82c1/s3-payroll-records`: **S3Bucket** payroll-records-prod-000000000000-82c1 - `n00_82c1/data-payroll-records`: **DataSet** payroll-financial-records-82c1 - `n08_82c1/role-migration-helper`: **IAMRole** MigrationHelperRole-82c1 - `n05_82c1/pol-migration-helper-read`: **IAMPolicy** MigrationHelperReadPolicy-82c1 - `n06_82c1/s3-open-data`: **S3Bucket** open-data-exports-82c1 - `n45_82c1/s3-open-data`: **S3Bucket** open-data-exports-2-82c1 - `n10_82c1/s3-ml-features`: **S3Bucket** ml-feature-store-82c1 - `n17_82c1/trail-ml-features`: **LogTrail** trail-ml-features-82c1 - `n02_82c1/data-ml-features`: **DataSet** feature-vectors-82c1 - `n21_82c1/s3-ops-runbooks`: **S3Bucket** ops-runbooks-82c1 - `n30_82c1/trail-ops-runbooks`: **LogTrail** trail-ops-runbooks-82c1 - `n28_82c1/data-ops-runbooks`: **DataSet** runbook-library-82c1 - `n13_82c1/role-datadog-monitoring`: **IAMRole** DatadogMonitoringRole-82c1 - `n26_82c1/data-operational-metrics`: **DataSet** data-operational-metrics-82c1 - `n04_82c1/trail-security-secondary`: **LogTrail** trail-security-secondary-82c1 - `n14_82c1/s3-build-artifacts`: **S3Bucket** build-artifacts-82c1 - `n24_82c1/role-datadog-monitoring`: **IAMRole** DatadogMonitoringRole-2-82c1 - `n39_82c1/ecr-analytics-worker`: **EcrRepository** repo-analytics-worker-82c1 - `n19_82c1/role-backup-runner`: **IAMRole** BackupRunnerRole-82c1 - `n32_82c1/ecr-base-runner`: **EcrRepository** repo-base-runner-82c1 - `n43_82c1/s3-backup-vault`: **S3Bucket** backup-vault-82c1 - `n40_82c1/ecr-utility-image`: **EcrRepository** repo-utility-image-82c1 - `n01_82c1/role-backup-runner`: **IAMRole** BackupRunnerRole-2-82c1 - `n34_82c1/ecr-collector-agent`: **EcrRepository** repo-collector-agent-82c1 - `n38_82c1/kms-internal-telemetry`: **KmsKey** kms-internal-telemetry-82c1 - `n35_82c1/ecr-collector-agent`: **EcrRepository** repo-collector-agent-2-82c1 - `n12_82c1/trail-audit-operations`: **LogTrail** trail-audit-operations-82c1 - `n15_82c1/ecr-analytics-worker`: **EcrRepository** repo-analytics-worker-2-82c1 - `n29_82c1/trail-security-secondary`: **LogTrail** trail-security-secondary-2-82c1 - `n36_82c1/role-cloud-watch-agent`: **IAMRole** CloudWatchAgentRole-82c1 - `n09_82c1/role-datadog-monitoring`: **IAMRole** DatadogMonitoringRole-3-82c1 - `n31_82c1/sqs-notifications-stream`: **SqsQueue** notifications-stream-82c1 - `n37_82c1/s3-build-artifacts`: **S3Bucket** build-artifacts-2-82c1 - `n44_82c1/trail-security-secondary`: **LogTrail** trail-security-secondary-3-82c1 - `n16_82c1/s3-backup-vault`: **S3Bucket** backup-vault-2-82c1 - `n22_82c1/trail-audit-operations`: **LogTrail** trail-audit-operations-2-82c1 - `n20_82c1/s3-build-artifacts`: **S3Bucket** build-artifacts-3-82c1 - `n42_82c1/role-prometheus-agent`: **IAMRole** PrometheusAgentRole-82c1 - `n25_82c1/sqs-audit-events`: **SqsQueue** audit-events-82c1 - `n11_82c1/s3-build-artifacts`: **S3Bucket** build-artifacts-4-82c1 - `n23_82c1/sqs-ingest-pipeline`: **SqsQueue** ingest-pipeline-82c1 ## Relationships - `n33_82c1/acct-main` --assumes--> `n41_82c1/role-developer` - `n41_82c1/role-developer` --attached_policy--> `n18_82c1/pol-dev-tools` - `n41_82c1/role-developer` --assumes--> `n27_82c1/role-app-operator` - `n27_82c1/role-app-operator` --attached_policy--> `n03_82c1/pol-target-app` - `n27_82c1/role-app-operator` --can_read--> `n07_82c1/s3-payroll-records` - `n07_82c1/s3-payroll-records` --stores_sensitive_data--> `n00_82c1/data-payroll-records` - `n08_82c1/role-migration-helper` --attached_policy--> `n05_82c1/pol-migration-helper-read` - `n10_82c1/s3-ml-features` --logs_to--> `n17_82c1/trail-ml-features` - `n10_82c1/s3-ml-features` --stores_sensitive_data--> `n02_82c1/data-ml-features` - `n21_82c1/s3-ops-runbooks` --logs_to--> `n30_82c1/trail-ops-runbooks` - `n21_82c1/s3-ops-runbooks` --stores_sensitive_data--> `n28_82c1/data-ops-runbooks`
This estate was prebaked. A unique copy composes on the server in about 20 ms from a scenario spec: 10,000 seeds per family, 15 families. No cloud account was touched; the graph is the source of truth.
The grade is one call to TypeSafe Jev: three yes/no questions (entry, hop, sink) and one depth score (0 to 3, fewer rungs on a short path), typed probabilities back. No grade yet on this page.
cloudforge on GitHub