Get the latest tech news
An AWS IAM Security Tooling Reference
A guide to tools for auditing AWS IAM.
Principal Mapper (PMapper) is a script from my former NCC Group coworker Erik Steringer that answers a couple of the most pressing questions about IAM Security: Check out the example query Daniel put together to show how you can use the underlying neo4j database to identify cognito vulenerable roles, as per research by Nick Frichette. WithSecure’s Mohit Gupta has created an opensource varient on Zelkova, using the Z3 prover (an SMT solver) formally prove whether an action by a given IAM entity is possible against a particular resource.
Or read this on Hacker News