Godwit AI Labs Talk to us

Home › Free tools › Cloud permissions check

Could one leaked key open your whole cloud?

Drop in your cloud access policies: AWS IAM, Azure roles or Google Cloud IAM. It finds full administrator rights, grants that let someone make themselves administrator, anything open to the internet and trust that is too loose, then says what to fix first. Read in your browser.

Or paste a policy

No export to hand? See a sample:

  • The policy never leaves this browser
  • Account numbers masked in the report
  • Try it offline: it still works
HOW TO GET IT

Export the policies

One read-only command per cloud, run by someone with permission to view access settings. Or copy a single policy’s JSON from the console.

  1. The whole accountaws iam get-account-authorization-details --output json > iam.json in CloudShell. Read-only; needs iam:GetAccountAuthorizationDetails.
  2. Or one policyIn the IAM console, open the policy or role, choose the JSON tab, and copy it. Bucket policies are under the bucket’s Permissions tab.
  3. Drop the file in, or pasteUsers, groups, roles, trust policies and your own managed policies are all read.

What happens to it: it is read in your browser and dropped once the report is drawn. Nothing is uploaded, account numbers are masked in the report, and our copy of your details carries only the cloud and the counts.

QUESTIONS

Asked often

The questions people search for before they run the check.

How do I find over-privileged IAM users and roles?

Export the policies and look for full administrator grants, actions such as iam:PassRole, iam:CreatePolicyVersion or iam:Put*Policy on every resource, and Owner or Editor in Google Cloud. This check does that for AWS, Azure and Google Cloud exports, and says which grants to fix first.

What is IAM privilege escalation?

A right that lets its holder give themselves more rights: creating or attaching a policy, changing who may assume a role, creating keys for another user, or acting as a more powerful service account. One of these on a small account makes it an administrator.

How do I export my AWS IAM policies?

Run aws iam get-account-authorization-details --output json in CloudShell. It is read-only and lists every user, group, role, trust policy and your own managed policies. For Azure use az role definition list --custom-role-only true, and for Google Cloud gcloud projects get-iam-policy with --format=json.

Why is a GitHub Actions trust policy without a sub condition dangerous?

Without a condition on the token's sub claim, the role trusts sign-ins from any GitHub repository, including one an attacker creates. Name your organisation, repository and branch in the condition.

Is my policy uploaded?

No. It is read in your browser and dropped once the report is drawn, and account numbers are masked in the report. If you ask for the report, we keep your details and a one-line summary with the cloud and the counts.

One key should open one door

Administrator rights for the few who need them, through roles with MFA; every other account limited to what it uses; and an alert the day someone grants too much.