CanModifyTrust
Source can rewrite who may assume/impersonate the target - self-grant assumption.
Identity
── CanModifyTrust ──▸
Role, TrustPolicy, ServiceAccount, MachineIdentity
Source types
IdentityTarget types
States
ACTIVE
CONDITIONAL
POTENTIAL
BLOCKED
UNKNOWN
Derivation
| nature | explicit |
|---|
Per-cloud
| cloud | permissions / triggers | note |
|---|---|---|
| aws |
iam:UpdateAssumeRolePolicy
|
|
| gcp |
iam.serviceAccounts.setIamPolicy
|
|
| azure |
update federated credentials / SP owner
|
Rules that emit CanModifyTrust 22
awsderived
Registering an attacker-controlled CA as a trust anchor lets the attacker mint certs that federate into any role trusting the Roles Anywhere service principal.
awsderived
Creating/updating a Roles Anywhere profile that lists a privileged role (with iam:PassRole) maps the attacker's cert to that role.
awsderived
A principal who can write B2C custom policy XML can inject a Technical Profile trusting an attacker-controlled OIDC/SAML IdP.
azurederived
The B2C IEF Keyset Administrator can replace the signing keyset used by custom policies, enabling token forgery for all relying party applications.
azurederived
azurederived
A customer principal with Microsoft.ManagedServices/registrationDefinitions/write can modify Lighthouse trust anchors (authorizations list, managing tenant).
azurederived
A service principal holding Application.ReadWrite.All or Directory.ReadWrite.All can modify the trust configuration of any app registration by adding a federated identity credential (OIDC trust), allowing an attacker-controlled external issuer to obtain tokens as that app without a static secret.
azurederived
Workspace super-admin can authorize any service account for Domain-Wide Delegation (adding its OAuth2 client ID to the delegated clients list with chosen scopes), creating a new tenant-wide impersonation primitive.
gcpderived
gcpderived
Creating or updating a WIF pool provider lets a principal add/loosen the trust to an attacker-controlled external IdP.
gcpderived
setIamPolicy on a ServiceAccount lets a principal add/loosen the workloadIdentityUser binding that maps an external WIF subject to the SA.
gcpderived
awsexplicit
awsexplicit
awsexplicit
awsexplicit
awsexplicit
awsexplicit
awsexplicit
awsexplicit
awsexplicit
opsworks:UpdateStack + iam:PassRole on the new service role swaps the identity OpsWorks operates as.
awsexplicit