🔶 When AWS invariants aren't [invariant]
Search CloudTrail for instances of AssumeRole with additionalEventData.explicitTrustGrant == false. These will yield results for role assumptions that aren't permitted by the trust policy and violate your invariants like role session names will always be an employee's email address.
https://awsteele.com/blog/2024/02/20/when-aws-invariants-are-not.html
#aws
Post #866
677

- 👍 3
- ❤ 1
- 🔥 1