aws-backup-recovery-point-restored-content

A recovery point can contain every secret present in the protected resource; AWS Backup has no generic content-read API, so inspection requires restoration into the source service.

awscritical service: aws:backup emits CanReadData

Where it sits

locationStartRestoreJob recovery point -> restored resource data
location kinddata_record
data kindscredential password api_key private_key customer_data source_code_secret
emits edgeCanReadData
serviceAWS Backup (aws:backup)

Collection recipe

access modeindirect_destination
operationStartRestoreJob then source-service read
response pathrestored resource content
encodingprotocol_native
params{"IamRoleArn": "\u003crestore-role\u003e", "Metadata": "\u003crestore-metadata\u003e", "RecoveryPointArn": "\u003crecovery-point-arn\u003e"}

Required permissions

backup:StartRestoreJob
iam:PassRole

References

move · open · esc close