Dmytro Sonko

Results 6 comments of Dmytro Sonko

I propose do not trigger the check for AWS services: Lambda, API gateway, EC2, Backup, Glue On Thu, Sep 7, 2023 at 10:33 AM Nacho Rivera ***@***.***> wrote: > @D592...

OK it's correct for **non-service-linked** roles but the role with trust police like below is **service role** - however aws:SourceArn and aws:SourceAccount condition do not make sense here. The same...

OK - my point is true for trust entities of the **service** roles According for AWS Support: There is no public documentation which lists all the services which supports the...

![Support1](https://github.com/prowler-cloud/prowler/assets/84527010/a44cd01b-a40d-4e44-981d-461b6e4f09f2) ![Support2](https://github.com/prowler-cloud/prowler/assets/84527010/61d3c3a1-48d4-4461-ac05-98aba48eb381) ![Support3](https://github.com/prowler-cloud/prowler/assets/84527010/1bbb8007-2cd8-41c0-ac98-c303c443469f) ![Support-Data-LifeCycleManager](https://github.com/prowler-cloud/prowler/assets/84527010/32cf04b3-ce69-456b-a595-a2343cf762c5) ![Support-Redshift](https://github.com/prowler-cloud/prowler/assets/84527010/23dc40f4-097c-4206-aba7-aaa3897426b6) ![Support-Sagemaker](https://github.com/prowler-cloud/prowler/assets/84527010/6885308f-b4d4-4bfb-af92-b2224f0c487e) ![Support-Note](https://github.com/prowler-cloud/prowler/assets/84527010/4855d75c-7c7d-4c16-bd4a-15df3f4c8a61) ========== References : ========== [1] https://docs.aws.amazon.com/sagemaker/latest/dg/security-confused-deputy-prevention.html [2] https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/service-role.html#custom-role [3] https://docs.aws.amazon.com/machine-learning/latest/dg/redshift-parameters.html [4] https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_terms-and-concepts.html [5] https://repost.aws/knowledge-center/iam-role-chaining-limit

Despite the fact that it is stated that the Lambda service doesn't support aws:SourceAccount and aws:SourceArn condition keys, I have tested the policy, which works." { "Version": "2012-10-17", "Statement": [...

I would say that there is a certain logic in such access settings behavior. A role is generated that defines the lambda execution parameters. Changes to network settings are not...