Fighting Eventual Consistency-Based Persistence – An Analysis of notyet
ID: 4f4d675b-4846-5fad-8cba-f5c7a8ebae14
STIX ID: report--4f4d675b-4846-5fad-8cba-f5c7a8ebae14
Feed Name: Security Boulevard
This report analyzes 'notyet', an open-source adversarial tool that leverages AWS IAM eventual consistency to automatically escalate and persist administrator privileges. The author tested numerous containment techniques (inline and managed policies, permission boundaries, group membership, access key deactivation, role deletion, SSM runbooks, session policies, and trust manipulation) and found most ineffective; Service Control Policies (SCPs) and Sonrai Security’s Cloud Permissions Firewall were effective mitigations, and timing-based automated responses sometimes worked. The conclusion stresses adopting org-level SCP-based quarantines and testing IR playbooks against such automated persistence tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
