GenericData
class: Data
Realizing resources
aws aws
| resource | scope | enumerate | required permissions |
|---|---|---|---|
aws:qldb:ledger |
regional | qldb:ListLedgers |
qldb:ListLedgers |
aws:timestream:database |
regional | timestream:ListDatabases |
timestream:ListDatabases |
As edge source
As edge target
AuthenticatesToCanAdministerCanAttachIdentityCanControlCanCreateCanDeleteCanDeleteDataCanExfiltrateCanModifyCanModifyConfigurationCanModifyPolicyCanNetworkReachCanReachPortCanReadCanReadDataCanReplaceCanTakeOwnershipCanWriteCanWriteDataContainsContainsResourceReferenceControlsCredentialsForHasPermissionPrivateReachabilityExposure sites
aws-accessanalyzer-finding-details-metadataaws-appflow-flow-data-destinationaws-athena-query-result-rowsaws-backup-recovery-point-restored-contentaws-bedrock-runtime-prompt-response-payloadaws-cloudfront-key-value-store-valueaws-cloudtrail-event-data-store-query-resultsaws-cloudtrail-event-request-response-payload
Rules that touch GenericData 13
An attacker who can modify QuickSight's configuration (UpdateAccountSettings) and pass an IAM role to it gains execution as that role for all data queries.
aws
CanExecuteAsA QuickSight data source that stores database credentials (CredentialPair / API key) exposes those credentials - readable by the QuickSight service and potentially exfiltrable by updating the data source endpoint.
quicksight:CreateDataSource (relational types) with an attacker-controlled endpoint causes QuickSight to transmit credentials to that host on connection test/ingestion - SSRF-style credential exfiltration.
quicksight:UpdateDataSource on a data source with stored credentials lets an attacker overwrite those credentials or change the endpoint, triggering credential exfiltration or database takeover.
aws
CanModifyGetRecord / BatchGetRecord reads ML feature data from a SageMaker Feature Store online store.
aws
CanReadDatastates:GetExecutionHistory returns the full event history of a Standard workflow execution including state input/output, which may contain sensitive data from the execution's data context.
aws
CanReadDataAn AML datastore configured with accountKey/SAS/servicePrincipal credential exposes that credential to principals with listsecrets.
azure
ExposesCredentialA principal holding the domain access key can publish events to ALL topics within the Event Grid domain, triggering all subscribers across the domain.
azure
CanWriteDataA principal with the EventGrid Data Sender role (events/send/action) on a custom topic can publish events via Entra token, triggering all bound consumers.
azure
CanWriteDataA principal that holds the topic access key (retrieved via listKeys/action) can publish arbitrary events to the topic over HTTPS, triggering all bound consumers.
azure
CanWriteDatalistKeys or regenerateKey on an Azure OpenAI account retrieves symmetric API keys that authenticate to all model deployments.
azure
CanReadSecret