CanModify

General modify capability (specialized by CanModifyCode/Configuration/Policy where meaningful). Produced by explicit normalization (modify permissions) and derived rules (config-modification attack paths like CloudTrail tampering, logging-service disablement).

resource_control CONTROL nature: both walkable weight 1
Identity  ── CanModify ──▸  *

Source types

Identity

Target types

*

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

natureboth

Rules that emit CanModify 24

Principal with cloudtrail:StopLogging can pause event recording on a trail, suppressing the audit record of all subsequent API activity until logging is resumed - a defense-evasion / cover-tracks primitive.
awsderived
Principal with cloudtrail:PutEventSelectors can exclude attacker-used API principals, actions, or data-event prefixes from capture, creating selective audit blindness while leaving the trail apparently running.
awsderived
Principal with cloudtrail:UpdateEventDataStore can disable ingestion (IngestionEnabled: false) on a CloudTrail Lake event data store, halting new audit-event collection while the store remains accessible - a reversible detection-suppression primitive.
awsderived
Principal with cloudtrail:DeregisterOrganizationDelegatedAdmin can remove the delegated admin role from an account, preventing it from managing organization trails and reducing the security team's ability to respond to and restore logging. This is a persistence / evasion amplifier in multi-account environments.
awsderived
quicksight:UpdateDataSource on a data source with stored credentials lets an attacker overwrite those credentials or change the endpoint, triggering credential exfiltration or database takeover.
awsderived
Update or disassociate a Web ACL to weaken or remove HTTP-layer filtering from protected resources (defense evasion, not access grant).
awsderived
Replace a Web ACL with an attacker-controlled permissive one to weaken HTTP-layer filtering (requires owning a substitute Web ACL).
awsderived
Modify a customer-managed Rule Group to corrupt all Web ACLs that reference it (defense evasion with potentially multi-ACL blast radius).
awsderived
Modify an IP Set to add attacker-controlled IPs to allow lists or remove blocking IPs (defense evasion with blast radius tied to referencing Web ACLs).
awsderived
Modify a Regex Pattern Set to remove blocking patterns or add permissive ones (defense evasion with blast radius tied to referencing Web ACLs).
awsderived
Disable WAF logging by deleting or disabling logging configuration, removing event coverage and aiding evasion.
awsderived
Remove Shield Advanced DDoS protection from a resource (defense evasion, reduces DDoS coverage).
awsderived
Start a stopped ADF trigger to realize CONDITIONAL(trigger_exists) execution edges.
azurederived
Write the Defender pricing tier for a subscription (Microsoft.Security/pricings/write); setting any plan to 'Free' disables threat-detection for that resource type subscription-wide. This blinds Defender without altering any resource access controls.
azurederived
Create or modify a Defender for Cloud alert suppression rule (Microsoft.Security/ alertsSuppressionRules/write); suppressed alert types are auto-dismissed before analysts see them, reducing SOC visibility into the suppressed attack patterns.
azurederived
Write Defender for Cloud security contacts (Microsoft.Security/securityContacts/write); removing or replacing email/phone recipients silences external alert notification delivery out-of-band from the Azure portal, reducing off-portal incident-response triggers.
azurederived
Write auto-provisioning settings (Microsoft.Security/autoProvisioningSettings/write); disabling auto-provisioning prevents automatic deployment of the Log Analytics agent and Microsoft Defender for Endpoint on newly created or reimaged VMs and Arc-connected machines, leaving them unmonitored by Defender for Cloud.
azurederived
Write workspace settings (Microsoft.Security/workspaceSettings/write); redirecting the Defender data pipeline to a different or non-existent workspace severs log collection and alert generation subscription-wide.
azurederived
A customer principal with Microsoft.ManagedServices/registrationAssignments/write can create/modify Lighthouse registrationAssignments - enable cross-tenant access.
azurederived
secretmanager.versions.add writes a new payload version that downstream consumers will read.
gcpderived
disks/write allows changing networkAccessPolicy (e.g. from AllowPrivate to AllowAll), which upgrades CONDITIONAL(network_reachability) SAS-export edges to ACTIVE.
azureexplicit
snapshots/write allows setting publicNetworkAccess and networkAccessPolicy on a snapshot, enabling cross-subscription SAS download.
azureexplicit
move · open · esc close