CIEM finding types
Every CIEM finding type, what triggers it, and the clouds it runs on today. Severities shown are the defaults the detectors assign.
Privilege escalation
| Finding | Trigger | Severity | Cloud |
|---|---|---|---|
| Escalation via PassRole | iam:PassRole on *, with an admin role present in the account | Critical | AWS |
| Escalation via assume-role chain | A chain of trust relationships — searched over many hops — leads from the identity to an admin role | High | AWS |
| Escalation via boundary bypass | The identity can delete or replace permission boundaries | High | AWS |
| Escalation via service-linked role | The identity can create service-linked roles | High | AWS |
| Escalation via RBAC owner, PIM activation, service principal owner rights | Owner-level or activatable privileged assignments | High–Critical | Azure |
| Escalation via key creation, primitive role, workload identity | Service-account key creation, owner/editor bindings, broad workload identity | High–Critical | GCP |
| Escalation via policy, group or user management; tenancy admin; secret access; broad dynamic groups; instance principals | OCI policy statements that let an identity widen its own access | High–Critical | OCI |
| Escalation via IAM identity admin, access-group management, API-key creation, secrets access | IBM Cloud policies that let an identity widen its own access | High–Critical | IBM Cloud |
| RBAC escalation | Service account bound to cluster-admin, able to write Roles or ClusterRoles, exec into pods, or read secrets cluster-wide | High–Critical | Kubernetes |
Escalation findings are marked SCP-blocked and lowered to informational when an SCP deny statement blocks the action they rely on.
CDR-confirmed. When Onam's cloud detection and response has seen the same identity call escalation operations in the last month — AssumeRole, PassRole, CreatePolicyVersion, AttachRolePolicy, AttachUserPolicy, DeleteRolePermissionsBoundary, CreateServiceLinkedRole — the AWS finding is raised to critical and marked confirmed. This shows the identity has been exercising escalation operations. It does not prove every hop of the path was walked.
Shadow admins (AWS)
Identities that are not admins on paper but can make themselves one. Admin is recognised as AdministratorAccess, PowerUserAccess or IAMFullAccess.
| Pattern | Trigger | Severity |
|---|---|---|
| Policy attachment | iam:AttachRolePolicy or iam:AttachUserPolicy on * | Critical |
| Policy version rewrite | iam:CreatePolicyVersion with iam:SetDefaultPolicyVersion | Critical |
| Role creation | iam:CreateRole with iam:AttachRolePolicy | High |
| Group membership | iam:AddUserToGroup where a group holds an admin policy | High |
Trust and access
| Finding | Trigger | Cloud |
|---|---|---|
| Wildcard trust principal | A role trust policy allows * | AWS |
| Cross-account role without ExternalId | A foreign account can assume the role and there is no sts:ExternalId condition | AWS |
| User with admin access | A user has admin-equivalent effective access | AWS |
| Admin via group membership | Admin access is inherited from a group | AWS |
| Policy allows what an SCP denies | A grant that an SCP deny statement blocks | AWS |
| Cross-tenant access without conditional access | External identity-provider access without conditional access | Azure |
| Service principal or managed identity at broad scope | Owner, Contributor or User Access Administrator at subscription or management-group scope | Azure |
| Workload identity pool without attribute condition | Any token from the federated issuer can map in | GCP |
| Trusted profile trusting another account | Trusted profile policy scoped to an external account | IBM Cloud |
| RAM role with wildcard trust, or assumable without MFA | Broad or unprotected RAM role trust | Alibaba Cloud |
| Dynamic group matching a whole compartment | Matching rule wider than a specific resource | OCI |
Usage-based (AWS)
| Finding | Trigger |
|---|---|
| Stale role | No CloudTrail activity for the role in the recent activity window |
| Permission gap | Granted actions the identity has not called; the high-risk unused ones — such as iam:PassRole, iam:CreatePolicyVersion, s3:PutBucketPolicy, kms:ScheduleKeyDeletion, sts:AssumeRole — are listed separately |
Database identity activity
Detections from credentialed database connections (for example PostgreSQL, MySQL, SQL Server, Oracle, MongoDB, Snowflake): new superuser or admin role grants, failed-login spikes, logins from unexpected addresses, bulk reads and audit-configuration changes. They appear under the Database CIEM module in the CIEM findings table. This is activity detection, not an analysis of table-level grants.
Identity posture rules
CIEM findings sit alongside the identity rules in Onam's posture catalogue — 1,459 rules in the identity domain — which the IAM Security view covers: MFA, key age, password policy, root usage and wildcard policies.