GenericManagement
class: ManagementService
Realizing resources
aws aws
| resource | scope | enumerate | required permissions |
|---|---|---|---|
aws:controltower:landing_zone |
regional | controltower:ListLandingZones |
controltower:ListLandingZones |
aws:sagemaker:notebook-lifecycle-config |
regional | sagemaker:ListNotebookInstanceLifecycleConfigs |
sagemaker:ListNotebookInstanceLifecycleConfigs |
aws:sagemaker:studio-lifecycle-config |
regional | sagemaker:ListStudioLifecycleConfigs |
sagemaker:ListStudioLifecycleConfigs |
aws:sso:instance |
regional | sso:ListInstances |
sso:ListInstances |
As edge source
As edge target
Exposure sites
None.
Rules that touch GenericManagement 4
servicecatalog:CreateConstraint + iam:PassRole(servicecatalog.amazonaws.com): add a LaunchRole constraint to a product in a portfolio, binding a chosen privileged role. All subsequent ProvisionProduct calls then execute as that launch role. can-execute-as execute-as-via-config-identity-swap propagates with CanPassIdentity to derive CanExecuteAs.
servicecatalog:ExecuteProvisionedProductServiceAction on an associated SSM Automation service action executes the automation document as the service action's automation role. A principal who can trigger a provisioned product and execute its service actions runs arbitrary SSM Automation as the automation role.
aws
CanExecuteAsModify an IP Set to add attacker-controlled IPs to allow lists or remove blocking IPs (defense evasion with blast radius tied to referencing Web ACLs).
aws
CanModifyModify a Regex Pattern Set to remove blocking patterns or add permissive ones (defense evasion with blast radius tied to referencing Web ACLs).
aws
CanModify