{"repo":"securisec/cliam","free":true,"listed":false,"github":"https://github.com/securisec/cliam","clone":"git clone https://github.com/securisec/cliam.git","description":"Cloud agnostic IAM permissions enumerator","language":"Go","stars":163,"topics":["aws","cloud","firebase","gcp","golang"],"license":"GPL-3.0","category":"cli-tools","readme_excerpt":"cliam Multi cloud iam permissions enumeration tool. Currently covers: - [x] AWS - [x] GCP - [x] Azure - [] Oracle 🚧 WIP Description Cliam is a simple cloud permissions identifier. There are two main components to the CLI. Most of the enumerated permissions are list, describe or get permissions. - enumerate which can be used to enumerate specific permissions (recommended) - Some service providers have service groups that can check for permissions for a specific subset of services/resources. Installation Download the latest release. DEV tags are current, but not stable. In order to build the binary locally, cd into the cli directory and run make dev Usage Cliam works with credentials obtained from the services well known envars or from passing the commonly required flags from the cli. It is highly recommond that command completions are set as most of the enumerate options have to be specific. To generate completions, use cliam completion [shell] and set according to your shells completion directory. AWS Uses the AWS rest api to make a signed request using the passed in credentials. This greatly adds speed, but makes it a bit more challenging to keep up with adding new permissions. The issue of scale is that AWS uses 3 - 4 variety of requests at the service level Supports obtaining credentials from AWS profile, flags, or default AWS environment variables like AWS ACCESS KEY ID , AWS SECRET ACCESS KEY and optionally AWS SESSION TOKEN . Known resources Cliam for AWS also supports","default_branch":null,"files":null,"tree":[],"storefront":"/r/securisec","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/securisec/cliam/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}