Neutralize identity-based cloud takeovers. Audit AWS IAM policy documents against 20+ dangerous privilege escalation vectors (such as iam:PassRole combined with compute, backdoor iam:CreateAccessKey, or unrestricted sts:AssumeRole), enforce MFA and IP guardrails, and auto-harden your JSON policies with 1-click.
Test known privilege escalation vectors, overly broad wildcards, or audited CI/CD baselines.
Instantly resolve wildcards, scope resource ARNs, and inject mandatory MFA condition blocks into this policy.
Statement grants unconditional administrative access across every AWS service and resource in the account.
Permission to iam:PassRole allows passing privileged roles to newly launched instances, Lambda functions, or ECS tasks to extract administrative tokens.
Allows generating persistent API access keys for other IAM users without administrative approval.
Grants permission to attach AdministratorAccess or inject inline policies directly onto user identities.
Allows modifying existing IAM role definitions or escalating execution role privileges.
Allows creating a new version of an attached customer-managed policy granting full administrator permissions.
Allows assuming any role in the AWS account or cross-account without resource restriction.
Allows modifying S3 bucket access policies, enabling an adversary to expose private buckets to the public internet.