SecurityService
GuardDuty/Defender/SCC.
class: ManagementService
Realizing resources
aws aws
| resource | scope | enumerate | required permissions |
|---|---|---|---|
aws:accessanalyzer:analyzer |
regional | access-analyzer:ListAnalyzers |
access-analyzer:ListAnalyzers |
aws:detective:graph |
regional | detective:ListGraphs |
detective:ListGraphs |
aws:firewallmanager:policy |
regional | firewallmanager:ListPolicies |
fms:ListPolicies |
aws:guardduty:detector |
regional | guardduty:ListDetectors |
guardduty:ListDetectors |
aws:inspector:finding |
regional | inspector:ListFindings |
inspector2:ListFindings |
aws:macie:classification-job |
regional | macie:ListClassificationJobs |
macie2:ListClassificationJobs |
aws:securityhub:standard |
regional | securityhub:GetEnabledStandards |
securityhub:GetEnabledStandards |
gcp gcp
| resource | scope | enumerate | required permissions |
|---|---|---|---|
gcp:securitycenter:source |
global | securitycenter.projects.sources.list |
securitycenter.sources.list |
As edge source
As edge target
Exposure sites
None.
Rules that touch SecurityService 77
Delete an Access Analyzer, removing all findings and disabling ongoing IAM access analysis for the zone of trust - a hard delete of a detective control that reduces detection fidelity without granting access (non-walkable edge).
aws
CanDeleteList findings on an Access Analyzer to map which account resources are externally or publicly accessible and which external principals hold access grants - recon that identifies targets for further attack-path traversal.
aws
CanReadDeleting the Detective behavior graph is a defense-evasion / cover-tracks primitive that reduces investigative coverage (ADMINISTRATOR ONLY). Emits CanModifyConfiguration on the SecurityService node.
A member account can remove itself from a Detective behavior graph (detective:DisassociateMembership). This is a self-removal action with reduced scope. Emits CONDITIONAL CanModifyConfiguration.
Forcibly removing a member account from a Detective behavior graph (detective:DeleteMembers) is a defense-evasion primitive (ADMINISTRATOR ONLY). Emits CanModifyConfiguration on the SecurityService node.
A principal with fms:DeleteNotificationChannel can permanently remove the SNS topic that receives FMS compliance notifications, creating an irreversible silent-running state for FMS enforcement.
aws
CanDeleteA principal with fms:DeletePolicy can permanently delete an existing Firewall Manager policy, eliminating org-wide enforcement of WAF/Shield/Security Group/ Network Firewall/DNS Firewall controls across all in-scope member accounts. This is an irreversible destructive action with maximum blast radius.
aws
CanDeleteA principal with fms:PutPolicy can overwrite an existing Firewall Manager policy with an empty or permissive rule set, or set RemediationEnabled=false, disabling org-wide enforcement of WAF/Shield/Security Group/Network Firewall/ DNS Firewall controls across all in-scope member accounts - a high-blast-radius defense-evasion / cover-tracks primitive. The policy object persists; enforcement is weakened but not destroyed.
A principal with fms:PutNotificationChannel can replace the SNS topic that receives FMS compliance notifications, redirecting or suppressing alerts about policy violations. This silences detective coverage without removing enforcement.
Delete the GuardDuty detector, permanently eliminating threat detection in the account/region.
aws
CanDeleteDisable the GuardDuty detector via UpdateDetector(Enable=false), pausing all finding generation.
Sever a member account's GuardDuty aggregation link to the Organizations delegated administrator, creating a central-monitoring blind spot.
Principal holds effective IAM permission to create GuardDuty filters.
aws
HasPermissionPrincipal holds effective IAM permission to create GuardDuty trusted-IP sets.
aws
HasPermissionPrincipal holds effective IAM permission to delete GuardDuty detector.
aws
HasPermissionPrincipal holds effective IAM permission to disassociate from GuardDuty delegated administrator (member account action).
aws
HasPermissionPrincipal holds effective IAM permission to disassociate member accounts from GuardDuty (admin account action).
aws
HasPermissionPrincipal holds effective IAM permission to retrieve GuardDuty findings details.
aws
HasPermissionPrincipal holds effective IAM permission to list GuardDuty findings.
aws
HasPermissionPrincipal holds effective IAM permission to update GuardDuty detector (including Enable=false).
aws
HasPermissionPrincipal holds effective IAM permission to update GuardDuty filters.
aws
HasPermissionPrincipal holds effective IAM permission to update GuardDuty findings feedback (mark as FALSE_POSITIVE).
aws
HasPermissionPrincipal holds effective IAM permission to update GuardDuty trusted-IP sets.
aws
HasPermissionPrincipal holds effective IAM permission to update GuardDuty publishing destination.
aws
HasPermissionRead GuardDuty findings to enumerate detected threats - useful for an attacker to confirm whether their activity was detected.
aws
CanReadCreate or update a GuardDuty filter to auto-archive (suppress) specific findings, enabling stealthy evasion while the detector appears operational.
Add attacker-controlled IPs to a GuardDuty trusted-IP set (IPSet), suppressing network-based findings for those addresses.
Mark GuardDuty findings as FALSE_POSITIVE to bypass SOAR automation, poison the ML model, and reduce SOC visibility.
Redirect GuardDuty findings export to an attacker-controlled S3 bucket, exfiltrating security telemetry and severing central SOC visibility.
Delegated-administrator account principal with inspector2:Disable can disable scanning for any/all organization member accounts simultaneously, stopping CVE detection across the entire AWS Organization from a single API call.
Principal with inspector2:Disable can stop vulnerability scanning in the account (or designated member accounts from delegated-admin), removing continuous CVE and network-exposure detection - a defense-evasion primitive.
Principal with inspector2:UpdateConfiguration can modify scan settings (e.g., Lambda deep scan, ECR scanning toggle), affecting detection depth but not service enablement.
Disabling Macie (macie2:DisableMacie) permanently disables the service, deletes all configurations and findings, and removes sensitive-data classification from the account - a weaken-defenses / cover-tracks / destructive primitive.
aws
CanDeleteReading Macie findings (macie2:GetFindings) reveals the precise S3 objects and locations where sensitive data - credentials, API keys, PII - was detected. This is a recon / targeting primitive.
aws
CanReadPausing Macie (macie2:UpdateMacieSession with status=PAUSED) temporarily stops sensitive-data classification and finding generation from the account without deleting configurations or findings - a weaken-defenses / cover-tracks primitive.
Principal can disable Security Hub security controls, compliance standards, or the entire service (securityhub:UpdateStandardsControl / securityhub:BatchDisableStandards / securityhub:DisableSecurityHub), permanently preventing Security Hub from generating findings for those checks or disabling all detection - a persistent defense-evasion action that does not grant resource access.
Principal can fully disable AWS Security Hub (securityhub:DisableSecurityHub), eliminating all detection from GuardDuty, Inspector, Macie, Config, and IAM Access Analyzer integrations - the highest-impact defense-evasion primitive that does not grant resource access.
Principal can enumerate Security Hub findings (securityhub:GetFindings), yielding a detailed inventory of every resource with a known vulnerability or misconfiguration - useful recon for target selection in lateral movement.
aws
CanReadPrincipal can suppress Security Hub findings (securityhub:BatchUpdateFindings), setting workflow state to SUPPRESSED or RESOLVED to hide attacker activity from dashboards and automated response - a defense-evasion primitive that does not grant access to any resource.
Remove Shield Advanced DDoS protection from a resource (defense evasion, reduces DDoS coverage).
aws
CanModifyModify a customer-managed Rule Group to corrupt all Web ACLs that reference it (defense evasion with potentially multi-ACL blast radius).
aws
CanModifyPermanently delete a customer-managed Rule Group, breaking all Web ACLs that reference it (requires prior removal of all associations).
aws
CanDeletePermanently delete a Web ACL, removing WAF protection from all previously associated resources (requires prior disassociation).
aws
CanDeleteDisable WAF logging by deleting or disabling logging configuration, removing event coverage and aiding evasion.
aws
CanModifyDiscover WAF logging configuration (destination Firehose/S3/CloudWatch Logs), aiding recon into the logging pipeline.
aws
CanReadReplace a Web ACL with an attacker-controlled permissive one to weaken HTTP-layer filtering (requires owning a substitute Web ACL).
aws
CanModifyUpdate or disassociate a Web ACL to weaken or remove HTTP-layer filtering from protected resources (defense evasion, not access grant).
aws
CanModifyWrite the Defender pricing tier for a subscription (Microsoft.Security/pricings/write); setting any plan to 'Free' disables threat-detection for that resource type subscription-wide. This blinds Defender without altering any resource access controls.
azure
CanModifyWrite Defender for Cloud security contacts (Microsoft.Security/securityContacts/write); removing or replacing email/phone recipients silences external alert notification delivery out-of-band from the Azure portal, reducing off-portal incident-response triggers.
azure
CanModifyCreate or modify a Defender for Cloud alert suppression rule (Microsoft.Security/ alertsSuppressionRules/write); suppressed alert types are auto-dismissed before analysts see them, reducing SOC visibility into the suppressed attack patterns.
azure
CanModifyDelete an action group, silencing the response actions (email, SMS, webhook, Azure Function, Logic App, Automation Runbook) for ALL alert rules that reference it - a high-blast-radius evasion against automated incident response.
azure
CanDeleteDelete an activity log alert rule, silencing automated detection triggered by Azure Resource Manager (ARM) control-plane events (resource creation, deletion, policy changes, role assignments). Activity log alerts are distinct from scheduled-query and metric alerts, on their own ARM resource type.
azure
CanDeleteDelete a metric alert rule, silencing automated detection triggered by metric thresholds (CPU, memory, network, custom metrics). Metric alerts fire independently of log-search alerts and are on distinct ARM resource types.
azure
CanDeleteDelete a scheduled query (log search) alert rule, silencing automated detection based on KQL log queries - disables alerting on specific threat patterns or compliance baselines.
azure
CanDeleteDelete Sentinel analytics rules to silence specific threat detections (defense evasion - disable alerting for attack techniques).
azure
CanModifyConfigurationShowing 60. Filter all rules for SecurityService.