CanWrite

Modify a resource's configuration. Produced by explicit normalization (write permissions) and derived rules (config-write attack paths).

resource_control CONTROL nature: both walkable weight 1
Identity  ── CanWrite ──▸  *

Source types

Identity

Target types

*

States

ACTIVE CONDITIONAL POTENTIAL BLOCKED UNKNOWN

Derivation

natureboth

Rules that emit CanWrite 6

Principal with cloudtrail:UpdateTrail can redirect S3 log delivery to an attacker-controlled bucket, enabling silent log exfiltration while the trail remains IsLogging=true. This is a log-redirect-to-attacker-bucket exfiltration capability, distinct from selector narrowing.
awsderived
Overwrite a parameter's value (ssm:PutParameter Overwrite) to poison consumers.
awsderived
datastore.databases.update allows changing cmekConfig.kmsKeyName on a Firestore database, swapping to an attacker-controlled KMS key. Future writes are then encrypted under the attacker's key, enabling offline decryption of all subsequently written data. This is a configuration mutation on a data resource, not code execution.
gcpderived
move · open · esc close