logo

Fighting Eventual Consistency-Based Persistence – An Analysis of notyet

ID: 4f4d675b-4846-5fad-8cba-f5c7a8ebae14

STIX ID: report--4f4d675b-4846-5fad-8cba-f5c7a8ebae14

Feed Name: Security Boulevard

Threat Score
70/100

Date Published: 2026-04-08

Date Updated: 2026-04-22

Author: Nigel Sood

...
...

This report analyzes 'notyet', an open-source adversarial tool that leverages AWS IAM eventual consistency to automatically escalate and persist administrator privileges. The author tested numerous containment techniques (inline and managed policies, permission boundaries, group membership, access key deactivation, role deletion, SSM runbooks, session policies, and trust manipulation) and found most ineffective; Service Control Policies (SCPs) and Sonrai Security’s Cloud Permissions Firewall were effective mitigations, and timing-based automated responses sometimes worked. The conclusion stresses adopting org-level SCP-based quarantines and testing IR playbooks against such automated persistence tools.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.