Derivation rules

2,433 declarative match → where → emit rules (1,787 derived, 646 explicit). Filter by cloud, emitted edge, node type, or text.

65 rule(s) · page 2 of 2

A consumer reads a RAM-shared SecureString whose creds grant the owning account.
aws CanEnterAccount derived
A consumer-account VPC with a confirmed (state==available) attachment to an owner-account Transit Gateway has L3 network reachability to subnets in the owner account (subject to TGW route table routing and L4 security group evaluation). This is a network-layer foothold (CanNetworkReach), not control-plane account entry (CanEnterAccount).
aws CanNetworkReach derived
A VPC peering connection whose requester and accepter VPCs belong to different AWS accounts represents cross-account network trust. The peering connection record in the accepting account's AWS account constitutes the cross-account authorization artifact, enabling principals in the peer account to reach resources in this account if SG/routing permits.
aws CrossAccountTrust derived
A VPC endpoint policy (gateway or interface) granting access to principals in another AWS account enables cross-account access to the backing PaaS service via the endpoint path. The endpoint policy resource is the trust artifact (modeled as ResourcePolicy source).
aws CrossAccountTrust derived
A PrivateLink producer endpoint with an explicit permission granting access to a foreign account principal is exposed to cross-account consumption. This is a structural fact representing the intended cross-account data-plane exposure.
aws ExposedToAccount derived
A VPC Lattice service network or service with authType NONE is accessible to any client in any associated VPC without IAM authentication - account-scoped exposure (or broader if the network is RAM-shared).
aws ExposedToAccount derived
A consumer account principal with CreateServiceNetworkVpcAssociation on a RAM-shared service network can associate their VPC, gaining cross-account private reachability to owner-account services.
aws CanNetworkReach derived
listKeys/action returns ADLS Gen2 account keys, bypassing all RBAC and ACLs.
azure CanReadCredential derived
An Automation Account sandbox job exposes its bound MI's token to any code it runs via the IMDS endpoint.
azure ExposesCredential derived
Code executing in an Automation Account sandbox can retrieve a bearer token for the bound MI from IMDS.
azure CanRetrieveToken derived
listKeys/action returns storage account keys, bypassing all Azure RBAC and network controls for all sub-services (when SharedKey auth is enabled).
azure CanReadCredential derived
Assuming/federating into a role in another account = entering it.
aws CanEnterAccount derived
Federating into a Role homed in an AWS account gives the federated principal a foothold in that account.
CanEnterAccount derived
A messaging resource policy that grants publish/subscribe to a principal in another account is cross-account trust (Pub/Sub topic IAM across projects emits CrossProjectTrust); feeds can-control's CanEnter* roll-up.
move · open · esc close