AWS IAM
利用可能アイデンティティとアクセスAWS IAM コネクター — 読み取り専用、エージェントレス
Scans AWS IAM users, roles, groups, and policies to map effective permissions and find over-privileged or stale principals.
スキャン対象
- IAM users, roles, groups, and attached/inline policies (never resource data)
- Effective permission relationships for blast-radius analysis
読み取り専用での監視のため、自動修復を有効にして書き込みアクセスを別途付与しない限り、AWS IAM のデータが変更されることはありません。
セキュリティ検出結果
13件の検出ルールが、AWS IAMのスキャンごとに実行されます。各検出結果には、平易な言葉による説明、その根拠となる証拠、および修復手順が付属します。
- CRITICALMisconfig
AWS account root user has MFA disabled
- CRITICALMisconfig
AWS account root user has active access keys
- CRITICALPublic exposure
IAM role trust policy allows any principal to assume it
- HIGHMisconfig
IAM console user has no MFA device
- HIGHOver permission
IAM user holds a wildcard (Action:* Resource:*) policy
- HIGHOver permission
IAM user has AdministratorAccess attached
- MEDIUMStale access
IAM access key has not been rotated in over 90 days
- MEDIUMMisconfig
Account password policy allows short passwords
- LOWStale access
IAM console user has been inactive for over 90 days
- LOWMisconfig
Account password policy does not expire passwords
- LOWMisconfig
Account password policy allows password reuse
- LOWMisconfig
IAM user has an inline policy
- LOWMisconfig
IAM group has no members
AWS IAMを接続する方法
ステップ1
8200.devにサインアップまたはログインします
ステップ2
Connectors → AWS IAMに移動します
ステップ3
「Connect」をクリックし、AWS IAMの同意画面から承認します
ステップ4
8200.devが自動的にスキャンを実行します — 結果は数分以内に表示されます
最初のソースを数分で接続 — 無料・読み取り専用・営業担当への連絡不要。