Added BypassesNetworkControls risk category and detection logic - #523
Added BypassesNetworkControls risk category and detection logic#523sar9ho wants to merge 1 commit into
Conversation
|
Thanks for the contribution! Before we can merge this, we need @sar9ho to sign the Salesforce Inc. Contributor License Agreement. |
|
Hi team, continuing on this thread on some findings i face in production findings, i couldn't rmb the exact permission,
|
What does this PR do?
This PR implements the “Bypasses Network Controls” risk category mentioned in #454.
As mentioned in the original issue, some IAM permissions can access resources through AWS managed control planes or service APIs (for example, redshift:GetClusterCredentials via the Redshift Query Editor), bypassing the need for direct network access. In these cases, security groups and NACLs are effectively bypassed.
Changes:
(This essentially gives these permissions a dedicated place instead of forcing them into existing categories like data exfiltration/privilege escalation)
What gif best describes this PR or how it makes you feel?
Completion checklist
make test,make lint,make security-test,make test-js)