Derivation rules

2,433 declarative match → where → emit rules (1,787 derived, 646 explicit). Filter by cloud, emitted edge, node type, or text.

2,433 rule(s) · page 1 of 49

Control of a parent administrative boundary inherits transitively to every descendant boundary and resource via Contains*.
Delete an Access Analyzer, removing all findings and disabling ongoing IAM access analysis for the zone of trust - a hard delete of a detective control that reduces detection fidelity without granting access (non-walkable edge).
aws CanDelete derived
List findings on an Access Analyzer to map which account resources are externally or publicly accessible and which external principals hold access grants - recon that identifies targets for further attack-path traversal.
aws CanRead derived
A management-account principal that can assume OrganizationAccountAccessRole enters the member account as full admin.
aws CanEnterAccount derived
An exportable ACM certificate exposes its private key to any principal that can export it.
aws ExposesCredential derived
An exported ACM private key authenticates as the certificate's DNS/TLS server identity.
aws CredentialsFor derived
Cross-account issuance on a CA whose certs are trusted in the owner account enters that account.
aws CanEnterAccount derived
Forging a cert to act as a more-privileged identity is privilege escalation.
aws CanEscalateTo derived
A CA-issued certificate authenticates as the downstream identity a trust consumer maps it to.
aws CredentialsFor derived
Forging a CA-trusted cert lets the principal act as the downstream identity.
aws CanImpersonate derived
Issue a certificate for an arbitrary subject/SAN signed by the CA's key.
aws CanSignAs derived
Rewrite the CA resource policy to grant self issuance, then sign as the CA.
aws CanSignAs derived
Issue a SubordinateCACertificate to create a new issuer chaining to the trusted CA.
aws CanSignAs derived
UpdateApp + iam:PassRole can replace an Amplify App's iamServiceRoleArn, changing the build execution identity.
aws CanAttachIdentity derived
UpdateBranch + iam:PassRole can replace an Amplify Branch's computeRoleArn, changing the SSR request-serving identity.
aws CanAttachIdentity derived
amplify:CreateApp + iam:PassRole creates a new Amplify App bound to a chosen service role.
aws CanCreateWorkloadAs derived
amplify:CreateWebHook creates an unauthenticated HTTP endpoint that triggers a branch build.
aws CanTrigger derived
An Amplify App build exposes the service role's session credentials to code running in the build.
aws ExposesCredential derived
amplify:UpdateApp with buildSpec field rewrites the app-level build commands for all branches.
aws CanModifyCode derived
amplify:UpdateBranch with buildSpec field rewrites build commands for a specific branch.
aws CanModifyCode derived
amplify:UpdateApp can change iamServiceRoleArn, env vars, and auto-build config.
amplify:UpdateBranch can change env vars, enableAutoBuild, computeRoleArn, and backend env.
move · open · esc close