CanWrite
Modify a resource's configuration. Produced by explicit normalization (write permissions) and derived rules (config-write attack paths).
Identity
── CanWrite ──▸
*
Source types
IdentityTarget types
*States
ACTIVE
CONDITIONAL
POTENTIAL
BLOCKED
UNKNOWN
Derivation
| nature | both |
|---|
Rules that emit CanWrite 6
Principal with cloudtrail:UpdateTrail can redirect S3 log delivery to an attacker-controlled bucket, enabling silent log exfiltration while the trail remains IsLogging=true. This is a log-redirect-to-attacker-bucket exfiltration capability, distinct from selector narrowing.
awsderived
Overwrite a parameter's value (ssm:PutParameter Overwrite) to poison consumers.
awsderived
datastore.databases.update allows changing cmekConfig.kmsKeyName on a Firestore database, swapping to an attacker-controlled KMS key. Future writes are then encrypted under the attacker's key, enabling offline decryption of all subsequently written data. This is a configuration mutation on a data resource, not code execution.
gcpderived
awsexplicit
awsexplicit
awsexplicit