Onam Security

CIEM per-cloud notes

What CIEM does on each cloud today. AWS has the deepest coverage; the other clouds are honest subsets, and this page is where we say which.

AWS

  • Identities: IAM users, roles, groups, instance profiles, managed and inline policies, trust policies.
  • Effective access: full chain — group expansion, condition classes, explicit-deny netting, SCP deny checks. See effective permissions for what is not modelled yet.
  • Escalation: PassRole, multi-hop assume-role chains, boundary bypass, service-linked role creation; shadow admins (four patterns); CDR confirmation.
  • Trust: foreign accounts, wildcard principals, missing ExternalId, SAML and OIDC federation — including GitHub, GitLab, GCP and Azure issuers.
  • Non-human identities: roles classified as service-linked, AWS service, execution (Lambda, ECS and similar), CI/CD over OIDC, EKS service account (IRSA), cross-account, user-assumable or wildcard.
  • Usage: CloudTrail-based permission gap and stale roles.
  • Scoring and reviews: risk score, blast radius and access reviews.
  • Needs: CloudTrail flowing into Onam's threat detection for the usage-based findings; read access to AWS Organizations for SCP checks.

Azure

  • Identities: role definitions and assignments, Entra service principals, managed identities (user- and system-assigned).
  • Effective access: assignments joined to role definitions, scope classified, ABAC conditions evaluated. Entra group membership is not expanded.
  • Escalation: RBAC Owner, PIM activation, service principal owner rights.
  • Trust and scope: cross-tenant access without conditional access; service principals and managed identities with Owner, Contributor or User Access Administrator at broad scope; guests with privileged roles.
  • Graph: VM → managed identity links.

Google Cloud

  • Identities: IAM bindings, service accounts, workload identity pools.
  • Effective access: bindings on projects, service accounts, buckets, BigQuery datasets and Pub/Sub topics, mapped onto the shared access levels.
  • Escalation: service-account key creation, primitive (owner/editor) roles, broad workload identity.
  • Findings: service accounts with Owner, keys past rotation age, public principals in bindings, workload identity pools without an attribute condition, service-account chaining.
  • Graph: compute instance → service account links.

Kubernetes

  • Identities: service accounts, Roles and ClusterRoles, RoleBindings and ClusterRoleBindings, pods.
  • Effective access: bindings resolved to service accounts and their rules.
  • Escalation: cluster-admin bindings, Role and ClusterRole write, pods/exec and pods/attach, cluster-wide secrets read, node access, cross-namespace escalation.
  • Graph: pod → service account links; workload-identity annotations to the cloud identity.

OCI

  • Identities: users, groups, policies, dynamic groups, API keys, auth tokens, customer secret keys.
  • Escalation: policy, group or user management; tenancy admin; secret access; broad dynamic-group matching rules; instance principals.
  • Hygiene: MFA, key and token rotation, Administrators group membership, inactive users with credentials.

Alibaba Cloud

  • Identities: RAM users, roles, groups, policies, access keys.
  • Findings: wildcard or admin policies, RAM roles with wildcard trust or assumable without MFA, broad OSS and KMS grants, access-key rotation, console MFA.

IBM Cloud

  • Identities: API keys, service IDs, trusted profiles, access groups, policies.
  • Escalation: IAM identity admin, access-group management, API-key creation for service IDs, secrets access.
  • Trust: trusted profiles that trust another account.
  • Hygiene: account MFA enforcement, API-key rotation.

Not yet on these clouds

Unused-permission analysis, shadow-admin detection, the risk score and automatic access reviews run on AWS identities today. Multi-hop assume-role chains are AWS-only.