Summit Route updates

I want to summarize the public AWS work I've been up to in the past month.

I've expanded the AWS network visualization tool CloudMapper to help with all sorts of AWS auditing needs. It can now collect much of the metadata in an account, storing these as json files to allow you to get point-in-time snapshots of your IAM policies, S3 bucket policies, and much more. This is then used to support new features:

  • stats to count the resources used by each AWS service
  • sg_ips to perform geoip lookups on all Security Group IPs and map these.
  • find_admins to identify IAM users that have admin privileges or can obtain them through privilege escalations.
  • public to list all of the network resources that are publicly accessible and what ports they have exposed.
  • wot to visualize the "web of trust" of trusted AWS accounts.

The new commands work with multiple accounts (they've been run in environments with over 100 accounts).

I've also posted new AWS related articles:

I'll be in NYC July 17 at the AWS Summit if you'd like to meet up and if you'd like help with your AWS security reach out to me at [email protected]

要查看或添加评论,请登录

Scott Piper的更多文章

  • Downclimb: January 1, 2017

    Downclimb: January 1, 2017

    https://summitroute.com/blog/2017/01/01/downclimb/

  • Introducing Serene

    Introducing Serene

    https://summitroute.com/blog/2016/12/22/introducing_serene/

  • Downclimb December 18, 2016

    Downclimb December 18, 2016

    Infosec news summary for the week. Read Downclimb! https://summitroute.

  • Summary of the week's #infosec news.

    Summary of the week's #infosec news.

    Read Downclimb to catch up on what's happened this week in infosec! https://summitroute.com/blog/2016/12/11/downclimb/

社区洞察

其他会员也浏览了