BadBadger InfoSec
Menu
  • Home
  • About
  • Blog
Menu

Month: April 2024

Close-up of stacked binders filled with documents for office or educational use.

How to Detect IAM Policy Shadowing in AWS Using Native Tools

Posted on April 16, 2024February 24, 2025 by Dave Brock

In December 2022, security researchers at Sysdig uncovered real-world cases of privilege escalation via IAM misconfiguration. An attacker exploited an overlooked permission in an AWS environment, allowing them to modify IAM policies. By leveraging the ability to create new policy versions, they granted themselves full administrative access—bypassing intended security controls. This type of shadow IAM…

Read more

Recent Posts

  • Stopping an AWS Attack in Real Time – Walking through an Incident
  • Writing Secure IAM Policies to Prevent Shadowing and Conflicts
  • How to Detect IAM Policy Shadowing in AWS Using Native Tools
  • What Lurks in the Shadows of IAM? The Hidden Risk of Shadow Permissions
  • Becoming a Clear Communicator

Archives

  • December 2024
  • July 2024
  • April 2024
  • March 2024
  • November 2023
  • June 2023
  • March 2023
  • February 2023

Categories

  • InfoSec Career
  • Leadership
  • OSINT
  • Techniques
  • Tools
© 2025 BadBadger InfoSec | Powered by Minimalist Blog WordPress Theme