Over-Privileged Service Account

Tool simulation

Risk Ranking

iam sim lab

Trust-boundary workflow

Rank the riskiest finding first.

1.Inspect the caller, privilege path, and policy boundary.
2.Simulate how the unsafe trust edge grants access or increases blast radius.
3.Submit the risky role, control gap, or containment keyword.
AWSIAMS3EC2LambdaCloudTrailus-east-1 · lab
Security finding: user ci-deployer@acme-cloud.iam has an over-permissive identity. Inspect the highlighted principal below.
IdentityRole / groupMFAKey age
ci-deployer@acme-cloud.iamfindingroles/ownerNot enabled2 days
admin-userAdminsEnabled180 days
ci-deployCINot enabled90 days

Principal / input

{
  "serviceAccount": "ci-deployer@acme-cloud.iam",
  "roles": ["roles/owner"]
}

Policy / boundary

scope: unknown
Tool consolehelp · inspect · simulate <subject> · scope <control> · submit

Iam Sim Lab ready.

Type help for commands: help · inspect · simulate <subject> · scope <control> · submit

Quick start: inspect, simulate, scope, policy, submit.

Focus on where privilege crosses the trust boundary.

>
SecMissions: Cybersecurity training through practice missions