{"repo":"salesforce/cloudsplaining","free":true,"listed":false,"github":"https://github.com/salesforce/cloudsplaining","clone":"git clone https://github.com/salesforce/cloudsplaining.git","description":"Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report.","language":"JavaScript","stars":2243,"topics":["aws","aws-iam","cloud","security","salesforce","aws-security","cloud-security","iam","hacktoberfest"],"license":"BSD-3-Clause","category":"security-tools","readme_excerpt":"Cloudsplaining -------------- Cloudsplaining is an AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized HTML report. Example report Documentation For full documentation, please visit the project on ReadTheDocs. Installation Cheatsheet Example report Overview Cloudsplaining identifies violations of least privilege in AWS IAM policies and generates a pretty HTML report. It can scan all the policies in your AWS account, across multiple AWS accounts, or it can scan a single policy file. It helps to identify IAM actions that do not leverage resource constraints. It also helps prioritize the remediation process by flagging IAM policies that present the following risks to the AWS account in question without restriction: Data Exfiltration ( s3:GetObject , ssm:GetParameter , secretsmanager:GetSecretValue ) Infrastructure Modification Resource Exposure (the ability to modify resource-based policies) Privilege Escalation (based on Pathfinding.cloud) Credentials Exposure Cloudsplaining also identifies IAM Roles that can be assumed by AWS Compute Services (such as EC2, ECS, EKS, or Lambda), as they can present greater risk than user-defined roles - especially if the AWS Compute service is on an instance that is directly or indirectly exposed to the internet. Flagging these roles is particularly useful to penetration testers (or attackers) under certain scenarios. For example, if an attacker obtains privileges to execute ssm:SendCo","default_branch":null,"files":null,"tree":[],"storefront":"/r/salesforce","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/salesforce/cloudsplaining/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}