Onam Security

CIEM finding types

Every CIEM finding type, what triggers it, and the clouds it runs on today. Severities shown are the defaults the detectors assign.

Privilege escalation

FindingTriggerSeverityCloud
Escalation via PassRoleiam:PassRole on *, with an admin role present in the accountCriticalAWS
Escalation via assume-role chainA chain of trust relationships — searched over many hops — leads from the identity to an admin roleHighAWS
Escalation via boundary bypassThe identity can delete or replace permission boundariesHighAWS
Escalation via service-linked roleThe identity can create service-linked rolesHighAWS
Escalation via RBAC owner, PIM activation, service principal owner rightsOwner-level or activatable privileged assignmentsHigh–CriticalAzure
Escalation via key creation, primitive role, workload identityService-account key creation, owner/editor bindings, broad workload identityHigh–CriticalGCP
Escalation via policy, group or user management; tenancy admin; secret access; broad dynamic groups; instance principalsOCI policy statements that let an identity widen its own accessHigh–CriticalOCI
Escalation via IAM identity admin, access-group management, API-key creation, secrets accessIBM Cloud policies that let an identity widen its own accessHigh–CriticalIBM Cloud
RBAC escalationService account bound to cluster-admin, able to write Roles or ClusterRoles, exec into pods, or read secrets cluster-wideHigh–CriticalKubernetes

Escalation findings are marked SCP-blocked and lowered to informational when an SCP deny statement blocks the action they rely on.

CDR-confirmed. When Onam's cloud detection and response has seen the same identity call escalation operations in the last month — AssumeRole, PassRole, CreatePolicyVersion, AttachRolePolicy, AttachUserPolicy, DeleteRolePermissionsBoundary, CreateServiceLinkedRole — the AWS finding is raised to critical and marked confirmed. This shows the identity has been exercising escalation operations. It does not prove every hop of the path was walked.

Shadow admins (AWS)

Identities that are not admins on paper but can make themselves one. Admin is recognised as AdministratorAccess, PowerUserAccess or IAMFullAccess.

PatternTriggerSeverity
Policy attachmentiam:AttachRolePolicy or iam:AttachUserPolicy on *Critical
Policy version rewriteiam:CreatePolicyVersion with iam:SetDefaultPolicyVersionCritical
Role creationiam:CreateRole with iam:AttachRolePolicyHigh
Group membershipiam:AddUserToGroup where a group holds an admin policyHigh

Trust and access

FindingTriggerCloud
Wildcard trust principalA role trust policy allows *AWS
Cross-account role without ExternalIdA foreign account can assume the role and there is no sts:ExternalId conditionAWS
User with admin accessA user has admin-equivalent effective accessAWS
Admin via group membershipAdmin access is inherited from a groupAWS
Policy allows what an SCP deniesA grant that an SCP deny statement blocksAWS
Cross-tenant access without conditional accessExternal identity-provider access without conditional accessAzure
Service principal or managed identity at broad scopeOwner, Contributor or User Access Administrator at subscription or management-group scopeAzure
Workload identity pool without attribute conditionAny token from the federated issuer can map inGCP
Trusted profile trusting another accountTrusted profile policy scoped to an external accountIBM Cloud
RAM role with wildcard trust, or assumable without MFABroad or unprotected RAM role trustAlibaba Cloud
Dynamic group matching a whole compartmentMatching rule wider than a specific resourceOCI

Usage-based (AWS)

FindingTrigger
Stale roleNo CloudTrail activity for the role in the recent activity window
Permission gapGranted actions the identity has not called; the high-risk unused ones — such as iam:PassRole, iam:CreatePolicyVersion, s3:PutBucketPolicy, kms:ScheduleKeyDeletion, sts:AssumeRole — are listed separately

Database identity activity

Detections from credentialed database connections (for example PostgreSQL, MySQL, SQL Server, Oracle, MongoDB, Snowflake): new superuser or admin role grants, failed-login spikes, logins from unexpected addresses, bulk reads and audit-configuration changes. They appear under the Database CIEM module in the CIEM findings table. This is activity detection, not an analysis of table-level grants.

Identity posture rules

CIEM findings sit alongside the identity rules in Onam's posture catalogue — 1,459 rules in the identity domain — which the IAM Security view covers: MFA, key age, password policy, root usage and wildcard policies.