GenericManagement

class: ManagementService

Realizing resources

aws aws

resourcescopeenumeraterequired permissions
aws:controltower:landing_zone regional controltower:ListLandingZones controltower:ListLandingZones
aws:sagemaker:notebook-lifecycle-config regional sagemaker:ListNotebookInstanceLifecycleConfigs sagemaker:ListNotebookInstanceLifecycleConfigs
aws:sagemaker:studio-lifecycle-config regional sagemaker:ListStudioLifecycleConfigs sagemaker:ListStudioLifecycleConfigs
aws:sso:instance regional sso:ListInstances sso:ListInstances

Exposure sites

None.

Rules that touch GenericManagement 4

servicecatalog:CreateConstraint + iam:PassRole(servicecatalog.amazonaws.com): add a LaunchRole constraint to a product in a portfolio, binding a chosen privileged role. All subsequent ProvisionProduct calls then execute as that launch role. can-execute-as execute-as-via-config-identity-swap propagates with CanPassIdentity to derive CanExecuteAs.
servicecatalog:ExecuteProvisionedProductServiceAction on an associated SSM Automation service action executes the automation document as the service action's automation role. A principal who can trigger a provisioned product and execute its service actions runs arbitrary SSM Automation as the automation role.
Modify an IP Set to add attacker-controlled IPs to allow lists or remove blocking IPs (defense evasion with blast radius tied to referencing Web ACLs).
Modify a Regex Pattern Set to remove blocking patterns or add permissive ones (defense evasion with blast radius tied to referencing Web ACLs).
move · open · esc close