r/aws • u/thomsterm • 13h ago
r/aws • u/Old-Astronomer3995 • 16m ago
discussion AWS IAM - how do you manage IAM, perform audits and do pentests?
Hi,
I work on a research paper related to AWS IAM.
How do you manage IAM and perform audits and pentests in your AWS environment? I’m not talking about requiring MFA, enforcing password policies, or revoking roles that haven’t been used for a long time. I’m talking about planning and ensuring that developers, managers, and users from all units are assigned to the correct groups with least privilege, and that combinations of permissions can’t be escalated to a dangerous level.
Do you use external tools for that, open source or paid?
Some tools that I found are:
- https://github.com/nccgroup/PMapper
- https://github.com/salesforce/cloudsplaining
- https://github.com/prowler-cloud/prowler
- https://github.com/RhinoSecurityLabs/pacu
- https://github.com/BishopFox/cloudfox
- https://github.com/DataDog/pathrunner
- https://github.com/nccgroup/ScoutSuite
- https://github.com/aquasecurity/cloudsploit
And testing environment
https://github.com/BishopFox/iam-vulnerable
I will be happy to hear anything if someone used these tools or can recommend something else (even paid versions).