Cloud IAM Privilege Escalation Analyzer

Map toxic credential combinations, privilege escalation loops, and cross-account trust boundaries across AWS, GCP, and Azure footprints.

Active Attack Vectors:
AWSEscalation Path

AWS Role Chaining to Full Admin Takeover

An attacker compromises a routine background metrics collector script in a dev account and uses misconfigured role-switching to gain full root-level control over all production databases and servers.

Risk Score
94/100
CRITICAL SEVERITY
Execution Path
STEP 01

lambda-metrics-collector

Low-Privilege Dev Script
Dangerous Action:sts:AssumeRole

The attacker breaks into a simple metrics script. This script has been mistakenly granted permission to switch into the company deployment role in the production account.

STEP 02

cross-account-deployer

Production Deployment Role
Dangerous Action:iam:AttachRolePolicy

Once inside the deployment role, the attacker discovers it has permission to attach security policies to any role in the entire cloud account.

STEP 03

AdministratorAccess

Root Cloud Administrator
Dangerous Action:*:* (Full Control)

The attacker attaches the AWS AdministratorAccess policy to their own role. They now have complete control over all servers, databases, and encryption keys.

Blast Radius If Exploited:

Complete takeover of 6 AWS production accounts, 142 private customer S3 storage buckets, and 28 core SQL/RDS databases.

Recommended Security Fix (Least-Privilege Policy)

Add an explicit Deny rule to block non-emergency roles from attaching policies to Administrator roles. Use the policy below.

{
  "Version": "2012-10-17",
  "Statement": [
    {
      "Sid": "BlockAdminEscalation",
      "Effect": "Deny",
      "Action": ["iam:AttachRolePolicy", "iam:PutRolePolicy"],
      "Resource": "arn:aws:iam::*:role/AdministratorAccess",
      "Condition": {
        "StringNotEquals": { "aws:PrincipalArn": "arn:aws:iam::123456789012:role/EmergencyAdmin" }
      }
    }
  ]
}

Interactive Cloud Permission Safety Checker

Enter any cloud permission (e.g. iam:PassRole or sts:AssumeRole) to evaluate its privilege escalation risk.

iam:AttachRolePolicyRisk Level: CRITICAL

Security Evaluation: Allows an identity to attach any policy to any role. An attacker can grant themselves full administrator rights.