Derivation rules

2,433 declarative match → where → emit rules (1,787 derived, 646 explicit). Filter by cloud, emitted edge, node type, or text.

77 rule(s) · page 1 of 2

Delete an Access Analyzer, removing all findings and disabling ongoing IAM access analysis for the zone of trust - a hard delete of a detective control that reduces detection fidelity without granting access (non-walkable edge).
aws CanDelete derived
List findings on an Access Analyzer to map which account resources are externally or publicly accessible and which external principals hold access grants - recon that identifies targets for further attack-path traversal.
aws CanRead derived
Deleting the Detective behavior graph is a defense-evasion / cover-tracks primitive that reduces investigative coverage (ADMINISTRATOR ONLY). Emits CanModifyConfiguration on the SecurityService node.
A member account can remove itself from a Detective behavior graph (detective:DisassociateMembership). This is a self-removal action with reduced scope. Emits CONDITIONAL CanModifyConfiguration.
Forcibly removing a member account from a Detective behavior graph (detective:DeleteMembers) is a defense-evasion primitive (ADMINISTRATOR ONLY). Emits CanModifyConfiguration on the SecurityService node.
A principal with fms:DeleteNotificationChannel can permanently remove the SNS topic that receives FMS compliance notifications, creating an irreversible silent-running state for FMS enforcement.
aws CanDelete derived
A principal with fms:DeletePolicy can permanently delete an existing Firewall Manager policy, eliminating org-wide enforcement of WAF/Shield/Security Group/ Network Firewall/DNS Firewall controls across all in-scope member accounts. This is an irreversible destructive action with maximum blast radius.
aws CanDelete derived
A principal with fms:PutPolicy can overwrite an existing Firewall Manager policy with an empty or permissive rule set, or set RemediationEnabled=false, disabling org-wide enforcement of WAF/Shield/Security Group/Network Firewall/ DNS Firewall controls across all in-scope member accounts - a high-blast-radius defense-evasion / cover-tracks primitive. The policy object persists; enforcement is weakened but not destroyed.
A principal with fms:PutNotificationChannel can replace the SNS topic that receives FMS compliance notifications, redirecting or suppressing alerts about policy violations. This silences detective coverage without removing enforcement.
Delete the GuardDuty detector, permanently eliminating threat detection in the account/region.
aws CanDelete derived
Disable the GuardDuty detector via UpdateDetector(Enable=false), pausing all finding generation.
Sever a member account's GuardDuty aggregation link to the Organizations delegated administrator, creating a central-monitoring blind spot.
Principal holds effective IAM permission to create GuardDuty filters.
aws HasPermission explicit
Principal holds effective IAM permission to create GuardDuty trusted-IP sets.
aws HasPermission explicit
Principal holds effective IAM permission to delete GuardDuty detector.
aws HasPermission explicit
Principal holds effective IAM permission to disassociate from GuardDuty delegated administrator (member account action).
aws HasPermission explicit
Principal holds effective IAM permission to disassociate member accounts from GuardDuty (admin account action).
aws HasPermission explicit
Principal holds effective IAM permission to retrieve GuardDuty findings details.
aws HasPermission explicit
Principal holds effective IAM permission to list GuardDuty findings.
aws HasPermission explicit
Principal holds effective IAM permission to update GuardDuty detector (including Enable=false).
aws HasPermission explicit
Principal holds effective IAM permission to update GuardDuty filters.
aws HasPermission explicit
Principal holds effective IAM permission to update GuardDuty findings feedback (mark as FALSE_POSITIVE).
aws HasPermission explicit
Principal holds effective IAM permission to update GuardDuty trusted-IP sets.
aws HasPermission explicit
Principal holds effective IAM permission to update GuardDuty publishing destination.
aws HasPermission explicit
Read GuardDuty findings to enumerate detected threats - useful for an attacker to confirm whether their activity was detected.
aws CanRead derived
Create or update a GuardDuty filter to auto-archive (suppress) specific findings, enabling stealthy evasion while the detector appears operational.
Add attacker-controlled IPs to a GuardDuty trusted-IP set (IPSet), suppressing network-based findings for those addresses.
Mark GuardDuty findings as FALSE_POSITIVE to bypass SOAR automation, poison the ML model, and reduce SOC visibility.
Redirect GuardDuty findings export to an attacker-controlled S3 bucket, exfiltrating security telemetry and severing central SOC visibility.
Delegated-administrator account principal with inspector2:Disable can disable scanning for any/all organization member accounts simultaneously, stopping CVE detection across the entire AWS Organization from a single API call.
Principal with inspector2:Disable can stop vulnerability scanning in the account (or designated member accounts from delegated-admin), removing continuous CVE and network-exposure detection - a defense-evasion primitive.
Principal with inspector2:UpdateConfiguration can modify scan settings (e.g., Lambda deep scan, ECR scanning toggle), affecting detection depth but not service enablement.
Disabling Macie (macie2:DisableMacie) permanently disables the service, deletes all configurations and findings, and removes sensitive-data classification from the account - a weaken-defenses / cover-tracks / destructive primitive.
aws CanDelete derived
Reading Macie findings (macie2:GetFindings) reveals the precise S3 objects and locations where sensitive data - credentials, API keys, PII - was detected. This is a recon / targeting primitive.
aws CanRead derived
Pausing Macie (macie2:UpdateMacieSession with status=PAUSED) temporarily stops sensitive-data classification and finding generation from the account without deleting configurations or findings - a weaken-defenses / cover-tracks primitive.
Principal can disable Security Hub security controls, compliance standards, or the entire service (securityhub:UpdateStandardsControl / securityhub:BatchDisableStandards / securityhub:DisableSecurityHub), permanently preventing Security Hub from generating findings for those checks or disabling all detection - a persistent defense-evasion action that does not grant resource access.
Principal can fully disable AWS Security Hub (securityhub:DisableSecurityHub), eliminating all detection from GuardDuty, Inspector, Macie, Config, and IAM Access Analyzer integrations - the highest-impact defense-evasion primitive that does not grant resource access.
Principal can enumerate Security Hub findings (securityhub:GetFindings), yielding a detailed inventory of every resource with a known vulnerability or misconfiguration - useful recon for target selection in lateral movement.
aws CanRead derived
Principal can suppress Security Hub findings (securityhub:BatchUpdateFindings), setting workflow state to SUPPRESSED or RESOLVED to hide attacker activity from dashboards and automated response - a defense-evasion primitive that does not grant access to any resource.
Remove Shield Advanced DDoS protection from a resource (defense evasion, reduces DDoS coverage).
aws CanModify derived
Modify a customer-managed Rule Group to corrupt all Web ACLs that reference it (defense evasion with potentially multi-ACL blast radius).
aws CanModify derived
Permanently delete a customer-managed Rule Group, breaking all Web ACLs that reference it (requires prior removal of all associations).
aws CanDelete derived
Permanently delete a Web ACL, removing WAF protection from all previously associated resources (requires prior disassociation).
aws CanDelete derived
Disable WAF logging by deleting or disabling logging configuration, removing event coverage and aiding evasion.
aws CanModify derived
Discover WAF logging configuration (destination Firehose/S3/CloudWatch Logs), aiding recon into the logging pipeline.
aws CanRead derived
Replace a Web ACL with an attacker-controlled permissive one to weaken HTTP-layer filtering (requires owning a substitute Web ACL).
aws CanModify derived
Update or disassociate a Web ACL to weaken or remove HTTP-layer filtering from protected resources (defense evasion, not access grant).
aws CanModify derived
move · open · esc close