cloudforge v1.4.0 AWS public S3 · seed 17

brief

# Lab: `public_data_exposure`

b2b_saas / medium / `customer-data-lake` · prod

## Your job

Some data in this account may be reachable from the internet. Find the exposure. Not every public-looking bucket is a true positive.

For each path, name where it starts, what opens the way, and what the attacker reaches. That is not always data: it can be a role, a key, a secret, an image, a queue, a snapshot or a database.

## Resources

- `n17_c602/acct-main`: **Account** prod-account-c602
- `n35_c602/vpc-prod`: **VPC** prod-vpc-c602
- `n26_c602/s3-public-data`: **S3Bucket** customer-pii-c602
- `n29_c602/s3-locked-backups`: **S3Bucket** public-looking-backups-c602
- `n02_c602/app-data-lake`: **Application** customer-data-lake-c602
- `n44_c602/data-customer-pii`: **DataSet** customer-pii-records-c602
- `n25_c602/trail-main`: **LogTrail** main-trail-c602
- `n19_c602/role-batch-service`: **IAMRole** BatchServiceRole-c602
- `n15_c602/pol-batch-service`: **IAMPolicy** BatchServicePolicy-c602
- `n42_c602/role-reporting-read`: **IAMRole** ReportingReadRole-c602
- `n28_c602/pol-reporting-read-read`: **IAMPolicy** ReportingReadPolicy-c602
- `n46_c602/role-legacy-support`: **IAMRole** LegacySupportRole-c602
- `n38_c602/pol-legacy-support-read`: **IAMPolicy** LegacySupportReadPolicy-c602
- `n41_c602/s3-cdn-origin`: **S3Bucket** cdn-origin-media-c602
- `n45_c602/s3-ops-runbooks`: **S3Bucket** ops-runbooks-c602
- `n43_c602/trail-ops-runbooks`: **LogTrail** trail-ops-runbooks-c602
- `n08_c602/data-ops-runbooks`: **DataSet** runbook-library-c602
- `n01_c602/s3-ops-runbooks`: **S3Bucket** ops-runbooks-2-c602
- `n23_c602/trail-ops-runbooks`: **LogTrail** trail-ops-runbooks-2-c602
- `n40_c602/data-ops-runbooks`: **DataSet** runbook-library-2-c602
- `n39_c602/s3-partner-uploads`: **S3Bucket** partner-uploads-c602
- `n14_c602/trail-partner-uploads`: **LogTrail** trail-partner-uploads-c602
- `n03_c602/data-partner-uploads`: **DataSet** partner-upload-files-c602
- `n06_c602/ecr-analytics-worker`: **EcrRepository** repo-analytics-worker-c602
- `n07_c602/data-analytics-cache`: **DataSet** data-analytics-cache-c602
- `n18_c602/kms-internal-telemetry`: **KmsKey** kms-internal-telemetry-c602
- `n31_c602/s3-media-cache`: **S3Bucket** media-cache-c602
- `n24_c602/s3-build-artifacts`: **S3Bucket** build-artifacts-c602
- `n12_c602/sqs-audit-events`: **SqsQueue** audit-events-c602
- `n36_c602/role-metrics-collector`: **IAMRole** MetricsCollectorRole-c602
- `n20_c602/trail-security-secondary`: **LogTrail** trail-security-secondary-c602
- `n09_c602/data-analytics-cache`: **DataSet** data-analytics-cache-2-c602
- `n33_c602/role-cloud-watch-agent`: **IAMRole** CloudWatchAgentRole-c602
- `n22_c602/kms-storage-general`: **KmsKey** kms-storage-general-c602
- `n13_c602/trail-audit-operations`: **LogTrail** trail-audit-operations-c602
- `n11_c602/ecr-collector-agent`: **EcrRepository** repo-collector-agent-c602
- `n32_c602/trail-audit-operations`: **LogTrail** trail-audit-operations-2-c602
- `n16_c602/kms-app-configs`: **KmsKey** kms-app-configs-c602
- `n00_c602/data-telemetry-sink`: **DataSet** data-telemetry-sink-c602
- `n04_c602/trail-audit-operations`: **LogTrail** trail-audit-operations-3-c602
- `n21_c602/data-operational-metrics`: **DataSet** data-operational-metrics-c602
- `n27_c602/data-operational-metrics`: **DataSet** data-operational-metrics-2-c602
- `n34_c602/role-backup-runner`: **IAMRole** BackupRunnerRole-c602
- `n05_c602/sqs-audit-events`: **SqsQueue** audit-events-2-c602
- `n30_c602/ecr-utility-image`: **EcrRepository** repo-utility-image-c602
- `n10_c602/s3-media-cache`: **S3Bucket** media-cache-2-c602
- `n37_c602/sqs-notifications-stream`: **SqsQueue** notifications-stream-c602

## Relationships

- `n17_c602/acct-main` --exposed_to_internet--> `n26_c602/s3-public-data`
- `n26_c602/s3-public-data` --stores_sensitive_data--> `n44_c602/data-customer-pii`
- `n26_c602/s3-public-data` --belongs_to_app--> `n02_c602/app-data-lake`
- `n29_c602/s3-locked-backups` --belongs_to_app--> `n02_c602/app-data-lake`
- `n17_c602/acct-main` --exposed_to_internet--> `n29_c602/s3-locked-backups`
- `n19_c602/role-batch-service` --attached_policy--> `n15_c602/pol-batch-service`
- `n19_c602/role-batch-service` --can_read--> `n26_c602/s3-public-data`
- `n42_c602/role-reporting-read` --attached_policy--> `n28_c602/pol-reporting-read-read`
- `n46_c602/role-legacy-support` --attached_policy--> `n38_c602/pol-legacy-support-read`
- `n45_c602/s3-ops-runbooks` --logs_to--> `n43_c602/trail-ops-runbooks`
- `n45_c602/s3-ops-runbooks` --stores_sensitive_data--> `n08_c602/data-ops-runbooks`
- `n01_c602/s3-ops-runbooks` --logs_to--> `n23_c602/trail-ops-runbooks`
- `n01_c602/s3-ops-runbooks` --stores_sensitive_data--> `n40_c602/data-ops-runbooks`
- `n39_c602/s3-partner-uploads` --logs_to--> `n14_c602/trail-partner-uploads`
- `n39_c602/s3-partner-uploads` --stores_sensitive_data--> `n03_c602/data-partner-uploads`

how this works

This estate was prebaked. A unique copy composes on the server in about 20 ms from a scenario spec: 10,000 seeds per family, 15 families. No cloud account was touched; the graph is the source of truth.

The grade is one call to TypeSafe Jev: three yes/no questions (entry, hop, sink) and one depth score (0 to 3, fewer rungs on a short path), typed probabilities back. No grade yet on this page.