Derivation rules

2,433 declarative match → where → emit rules (1,787 derived, 646 explicit). Filter by cloud, emitted edge, node type, or text.

65 rule(s) · page 1 of 2

A management-account principal that can assume OrganizationAccountAccessRole enters the member account as full admin.
aws CanEnterAccount derived
Cross-account issuance on a CA whose certs are trusted in the owner account enters that account.
aws CanEnterAccount derived
A cross-account principal that can start or modify a CodeBuild build gains a foothold in the project's account via the service role.
aws CanEnterAccount derived
cloudformation:CreateStackInstances / UpdateStackSet in the admin account deploys to target accounts, executing as the StackSet execution role there - a cross-account foothold.
aws CanEnterAccount derived
A principal with cloudfront:CreateDistribution can create new distributions pointing at any origin (S3 bucket, ALB, API Gateway, custom endpoint). If an S3 bucket has an overly-broad OAC policy grant (missing aws:SourceArn condition), the attacker can create a distribution to expose its contents publicly.
aws CanCreate derived
Principal with cloudtrail:LookupEvents can query 90 days of account-wide management-event history without S3 access, exposing IAM principal names, access-key IDs, resource ARNs, and error codes - useful for recon and lateral movement planning.
aws CanRead derived
Creating a managed account via Account Factory yields a new account pre-seeded with an admin role the creator can assume - creation is entry.
aws CanEnterAccount derived
A management-account principal that can assume AWSControlTowerExecution enters every enrolled member account as administrator.
aws CanEnterAccount derived
A Direct Connect Gateway-to-TransitGateway association spanning account boundaries establishes network-layer trust (on-prem has routed path into remote account's VPCs).
aws CrossAccountTrust explicit
DocumentDB cluster snapshot is shared for restore with a specific external AWS account via rds:DescribeDBClusterSnapshotAttributes (restore attribute contains account ID).
aws CrossAccountTrust explicit
A principal in the snapshot's restore-authorized account with rds:RestoreDBClusterFromSnapshot can restore a shared DocumentDB cluster snapshot to a new cluster, obtaining full read access to all original data without network access to the source cluster.
aws CanReadData derived
An EventBridge custom bus resource policy granting events:PutEvents to a principal in another account establishes cross-account publish trust; the external principal can inject events that trigger compute consumers in this account.
aws CrossAccountTrust derived
A snapshot is shared to an external AWS account via ec2:DescribeSnapshotAttribute.
aws CrossAccountTrust explicit
A principal with ecr:PutReplicationConfiguration can change the registry's replication destination settings, enabling supply-chain image interception and poisoning across all repositories in the account.
An EFS file system with no explicit file system policy (PolicyNotFound) is fully accessible to any same-account IAM principal that can network-reach the mount target.
aws ExposedToAccount derived
A Kinesis stream resource policy granting kinesis:PutRecord(s) to a principal in another account is cross-account publish trust, enabling that external principal to trigger the stream's Lambda consumer.
aws CrossAccountTrust derived
A Kinesis stream resource policy granting read actions (GetRecords/GetShardIterator/SubscribeToShard) to a foreign account enables that account to read the stream's records, supporting data exfiltration.
aws CrossAccountTrust derived
Cross-account decrypt that unlocks THIS account's credentials is an account foothold.
aws CanEnterAccount derived
An external principal permitted by the key policy/grant can use the key cross-account.
aws CanDecrypt derived
Cross-account principal that can run code in a function enters this account.
aws CanEnterAccount derived
An LF admin (or GRANT OPTION holder) granting Lake Formation SELECT / INSERT / DATA_LOCATION_ACCESS to a principal ARN in a foreign AWS account creates cross- account data-lake trust: the external principal can query this account's governed data via their own analytics services.
aws CrossAccountTrust derived
An MSK cluster resource-based policy granting kafka-cluster:WriteData or ReadData to a principal in another account is cross-account publish/consume trust; feeds messaging-chains rule 4 and can-control's CanEnterAccount derivation.
aws CrossAccountTrust derived
Neptune cluster snapshot with public restore attribute (restore=all) is immediately exfiltrable by any AWS account via RestoreDBClusterFromSnapshot.
aws CanExfiltrate derived
Neptune cluster snapshot is shared for restore with a specific external AWS account via neptune:DescribeDBClusterSnapshotAttributes (restore attribute contains account ID).
aws CrossAccountTrust explicit
Neptune cluster snapshot with public restore attribute (restore=all) is exposed to the internet via CrossAccountTrust to external Account.
aws ExposedToInternet derived
Neptune cluster snapshot is publicly restorable (restore attribute contains 'all') via neptune:DescribeDBClusterSnapshotAttributes, establishing a CrossAccountTrust.
aws CrossAccountTrust explicit
Domain access policy grants es:ESHttp* to a principal in a foreign AWS account, enabling cross-account data access without a role assumption.
aws CrossAccountTrust derived
quicksight:RegisterUser + quicksight:UpdateUser (role=ADMIN) lets an attacker promote themselves or others to QuickSight admin, gaining read access to all datasets, dashboards, and data source configurations.
aws CanGrantPermission derived
An attacker who can modify QuickSight's configuration (UpdateAccountSettings) and pass an IAM role to it gains execution as that role for all data queries.
aws CanExecuteAs derived
A shared subnet collapses the inter-account network boundary: consumer workloads launched into the shared subnet are on-link with owner-account resources, yielding on-subnet network reachability.
aws CanNetworkReach derived
A shared Transit Gateway enables the consumer VPC to reach owner-account resources attached to the TGW, derived from the CrossAccountTrust fact and confirmed TGW attachments.
aws CanNetworkReach derived
redshift:AuthorizeDataShare grants a consumer AWS account real-time read access to producer cluster objects, establishing cross-account live data trust.
aws CrossAccountTrust derived
redshift-serverless:PutResourcePolicy allows a principal to grant another AWS account live access to a Redshift Serverless namespace via resource policy.
aws CrossAccountTrust derived
A principal in account B provisioning a product from a portfolio shared by account A (servicecatalog:ProvisionProduct) causes resources to be deployed in account A as the account-A launch role. The receiving-account principal effectively gains a foothold in account A via the launch role's permissions.
aws CanEnterAccount derived
Cross-account read of a secret that is credentials for a local identity is a foothold in this account.
aws CanEnterAccount derived
A queue resource policy granting sqs:SendMessage to a principal in another account is cross-account publish trust; fed by messaging-chains rule 4 to derive CanEnterAccount.
aws CrossAccountTrust derived
A principal in account A that can execute commands on an instance in account B, which runs as a role in account B, gains a foothold in account B.
aws CanEnterAccount derived
move · open · esc close