TGViewer
CloudSec Wine CloudSec Wine @cloud_sec · 2.27K subscribers
Post #866 677
🔶 When AWS invariants aren't [invariant]

Search CloudTrail for instances of AssumeRole with additionalEventData.explicitTrustGrant == false. These will yield results for role assumptions that aren't permitted by the trust policy and violate your invariants like role session names will always be an employee's email address.

https://awsteele.com/blog/2024/02/20/when-aws-invariants-are-not.html

#aws
  • 👍 3
  • ❤ 1
  • 🔥 1
More from @cloud_sec
  1. Oct 2, 2026🔴 Strengthen your CI/CD pipeline with new Secure Source Manager capabilities Google Cloud…
  2. Oct 1, 2026🔶 Exploring the new AWS Sign Up experience This post will explore what this new concept d…
  3. Sep 30, 2026🤖 Hacking OpenAI Researchers chained a libheif heap buffer overflow (via Discourse/ImageM…
  4. Sep 29, 2026👩‍💻 How to secure edge AI in customer-owned environments Edge AI shifts trust responsibi…
  5. Sep 28, 2026🤖 Containers Are No Longer a Security Boundary AI-accelerated kernel vuln discovery (5,97…
  6. Sep 25, 2026🔶 Introducing Amazon EBS Volume Clones across AWS account AWS introduces Amazon EBS Volum…
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →