Skip to content

Added BypassesNetworkControls risk category and detection logic - #523

Open
sar9ho wants to merge 1 commit into
salesforce:masterfrom
sar9ho:feature/bypass-network-controls-risk
Open

Added BypassesNetworkControls risk category and detection logic#523
sar9ho wants to merge 1 commit into
salesforce:masterfrom
sar9ho:feature/bypass-network-controls-risk

Conversation

@sar9ho

@sar9ho sar9ho commented Jan 10, 2026

Copy link
Copy Markdown

What does this PR do?

This PR implements the “Bypasses Network Controls” risk category mentioned in #454.

As mentioned in the original issue, some IAM permissions can access resources through AWS managed control planes or service APIs (for example, redshift:GetClusterCredentials via the Redshift Query Editor), bypassing the need for direct network access. In these cases, security groups and NACLs are effectively bypassed.

Changes:

  • added a new BypassesNetworkControls risk category with its own severity + description
  • added a list of IAM actions that enable these control-plane/out-of-band access paths
  • surfaced these findings in PolicyFinding results + included them in ServicesAffected
  • added unit tests covering both PolicyFinding & scan_policy behavior to make sure detection is correct

(This essentially gives these permissions a dedicated place instead of forcing them into existing categories like data exfiltration/privilege escalation)

What gif best describes this PR or how it makes you feel?

1357840561_truck_blind_spot

Completion checklist

  • Additions and changes have unit tests
  • The pull request has been appropriately labeled using the provided PR labels
  • GitHub actions automation is passing (make test, make lint, make security-test, make test-js)
  • [N/A] If the UI contents or JavaScript files have been modified, generate a new example report:
# Generate the updated Javascript bundle
make build-js

# Generate the example report
make generate-report

@salesforce-cla

Copy link
Copy Markdown

Thanks for the contribution! Before we can merge this, we need @sar9ho to sign the Salesforce Inc. Contributor License Agreement.

@hackerone99

Copy link
Copy Markdown

Hi team, continuing on this thread on some findings i face in production findings, i couldn't rmb the exact permission,

  1. Granted RDS.Read permission to Team (Developers), however, RDS has this feature to view logs from the console that expose raw SQL statement. The sensitive database raw logs should only be accessed by DBA from this bastion host protected by strict security groups. Because of this AWS permission, some of the data is accessed not only by DBA.

  2. RDS OracleDB (only this type) data exfiltration. One AWS permission in OracleDB allows exfiltration to other accounts S3 even if we lockdown no outbound connection of the RDS in isolated subnet (ingress from app, no egress). DBA who have access to OracleDB, can exfiltrate oracle db data via AWS control plane to their own S3.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants