Blog
Field notes on cloud access
Breach breakdowns, query walkthroughs, and the questions a permissions graph cannot answer — one path at a time.
"Conditional access" is not an answer
Graph-based scanners label condition-dependent access "conditional" because they evaluate at ingest time — before the source IP, MFA state, or object tag exists. Evaluate the conditions as parameters instead, and the label becomes an exact list.
Bedrock agents are non-human identities — can you say what yours can reach?
Amazon Bedrock supports no resource-based policies — whether a principal can invoke a model or rewrite an agent is decided entirely on the identity side. Three questions to ask about every agent role before it runs.
LexisNexis: one frontend role could read every secret in the account
A React app task role with account-wide Secrets Manager access turned one compromised container into 3.9 million leaked records. The blast radius was a standing fact you could have queried.
SCARLETEEL: 8 minutes to admin, and the path was visible the whole time
An AI-assisted attacker went from a leaked credential to full AWS admin in eight minutes. Every hop it used was a standing access path you could have queried the day before.
Know your real posture.
Not what your policies say on paper.
15 minutes to deploy. No agents. Read-only access. See your real IAM posture immediately.