Video: AWS Query Access Permissions within an IAM Policy

circle
circle

This is one in a series of short, simple J1 queries that will help you interrogate your AWS environments. The JupiterOne platform used to run these queries is free.

A common use case in AWS is to determine “who” has “which” permissions assigned to them in their policy. In this example, Akash shows how to query on a specific action such as, “Does this person have EC2* access?”. Access to this type of information is non-trivial. We address that request in this query example.

Cut-and-Paste Query

Here’s the query you can use to cut-and-paste into your J1 instance. Watch JupiterOne technical expert, Akash Ganapathi, walk through the example query and then display the results in real time. If you find this useful, give us some contact info at the bottom of this page and we’ll send you twice a month updates as we continue to explore various environments with JupiterOne.

FIND (aws_iam_role|aws_iam_user|aws_iam_group)
   THAT ASSIGNED AccessPolicy
   THAT ALLOWS AS rule *
   WHERE rule.actions~='ec2:*'

 

 

Contribute your J1 Query to the Community

We will frequently be adding cut-and-paste J1 queries to our gallery. Join the community and every two weeks we’ll send you a list of new queries. You can contribute your own queries for inclusion and examination in an upcoming article. Use the form below to join us.

avatar

Posted By Akash Ganapathi

Akash Ganapathi comes from an enterprise security, data privacy, and data analysis background, working exclusively in the B2B software solutions space throughout his career. He is currently a Principal Security Solutions Architect at JupiterOne.

To hear more from Akash, get our newsletter. No spam, just the good stuff once or twice a month. Sign up below.

PREVIOUS ARTICLE

cyber-security 1

Ad Title Placeholder

Lorem ipsum dolor sit amet, consectetur adipiscing elit.