CanRead

Read configuration/metadata of a resource (recon; low base value). Produced by explicit normalization (configuration-read IAM permissions) and by derived rules (recon primitives like reading Macie findings to identify sensitive-data targets).

resource_control CONTROL nature: both walkable weight 2
Identity  ── CanRead ──▸  *

Source types

Identity

Target types

*

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

natureboth

Rules that emit CanRead 31

List findings on an Access Analyzer to map which account resources are externally or publicly accessible and which external principals hold access grants - recon that identifies targets for further attack-path traversal.
awsderived
Principal with cloudtrail:LookupEvents can query 90 days of account-wide management-event history without S3 access, exposing IAM principal names, access-key IDs, resource ARNs, and error codes - useful for recon and lateral movement planning.
awsderived
logs:GetLogEvents, logs:FilterLogEvents, or logs:StartQuery + logs:GetQueryResults on a log group enables reading raw log events from the LoggingService node; application logs frequently embed secrets, tokens, or credentials usable for credential harvest.
awsderived
config:ListAggregateDiscoveredResources or config:BatchGetAggregateResourceConfig on a Config Aggregator exposes cross-account resource inventory and configurations - recon primitive.
awsderived
Read GuardDuty findings to enumerate detected threats - useful for an attacker to confirm whether their activity was detected.
awsderived
Reading Macie findings (macie2:GetFindings) reveals the precise S3 objects and locations where sensitive data - credentials, API keys, PII - was detected. This is a recon / targeting primitive.
awsderived
Principal can enumerate Security Hub findings (securityhub:GetFindings), yielding a detailed inventory of every resource with a known vulnerability or misconfiguration - useful recon for target selection in lateral movement.
awsderived
Discover WAF logging configuration (destination Firehose/S3/CloudWatch Logs), aiding recon into the logging pipeline.
awsderived
Execute KQL queries against a Log Analytics workspace, reading ingested log data that may contain tokens, connection strings, API keys, or session credentials. Modeled as CanRead (target: LoggingService) - CanReadData target set is restricted to Storage/Data/Messaging and does not include ManagementService subtypes.
azurederived
artifactregistry.repositories.downloadArtifacts grants pull/read access to images and packages in the repo - required for consumers and useful for recon.
gcpderived
Search, list, or export all GCP assets and IAM policy bindings at org/folder/project scope via Cloud Asset Inventory - the same enumeration the reference collector performs, giving an attacker a pre-built map of the environment.
gcpderived
storage.objects.get on the GCR artifacts bucket = pull container image layers for inspection (embedded credential exfil / code recon) without push capability.
gcpderived
container.clusters.getCredentials yields a kubeconfig (endpoint + CA) authenticated with the caller's GCP token; k8s RBAC then governs what actions are permitted.
gcpderived
Principal with securitycenter.findings.list can enumerate all SCC findings across their scope, revealing exploitable misconfigurations.
gcpderived
Principal with both securitycenter.findings.list and securitycenter.assets.list can enumerate all SCC findings and the full GCP asset inventory, providing complete org-wide resource reconnaissance.
gcpderived
source.repos.get (clone/read) grants read access to the full repository content, including any secrets committed to history and build-spec files that reveal SA references and deployment targets.
gcpderived
Principal with read permission on the MI ARM resource can enumerate its metadata (clientId, principalId, tenantId) - recon aiding IMDS multi-MI token requests.
azureexplicit
A principal holding Purview Data Reader (or higher-privilege roles: Data Curator, Data Source Administrator, Collection Admin) with network reachability to the Purview account can enumerate all catalog assets, classifications, scan results, and data lineage via the Purview REST API, enabling reconnaissance of sensitive data sources and classifications across the organization.
azureexplicit
move · open · esc close