v0.3.0 - k9 risks command for over-accessible-resources & over-permissioned-principals
This release of k9 CLI adds two new risks queries:
over-accessible-resourcesover-permissioned-principals
These similar commands process resource access summary reports and principal access summary reports respectively. Each uses three specialty flags:
- A list of strings called
services - An int
max-admin - Another int
max-rwd
These queries will filter and report resources or principals that match the service qualifier, and violate the specified admin or read-write-delete limit.
k9 query risks over-accessible-resources \
--customer_id C10001 \
--account 720226181253 \
--analysis-date 2022-06-14 \
--format json \
--service S3 \
--max-admin 1 \
| jq '.[].resource_arn'k9 query risks over-permissioned-principals \
--customer_id C10001 \
--account 720226181253 \
--analysis-date 2022-06-14 \
--format json \
--service S3 \
--max-admin 2 \
| jq '.[].principal_arn'