How to Shrink Your AWS Blast Radius When Attackers Move at Machine Speed
AI-assisted attackers can escalate in AWS within minutes. Shrinking your blast radius — what any single credential can reach — matters more than ever. Here is a practical plan.
Step 1: Remove the easy starting points
- Enable account-level S3 Block Public Access everywhere and search buckets for stored credentials.
- Delete or deactivate IAM user access keys, starting with test and unused users. Use IAM Identity Center for people and roles for workloads.
- Turn on GitHub secret scanning and equivalent tools to keep keys out of code.
Step 2: Close common escalation paths
Review identities that can:
- Create or update Lambda functions (
lambda:CreateFunction,lambda:UpdateFunctionCode) combined withiam:PassRoleon privileged roles. - Pass roles to EC2, ECS, Glue, SageMaker or other compute.
- Create access keys or login profiles for other users.
- Attach or put policies on users and roles.
- Assume roles with broader permissions.
IAM Access Analyzer, Prowler and similar tools can identify privilege escalation paths.
Step 3: Constrain AI services
- Limit who can invoke Amazon Bedrock models and which models are enabled.
- Use SCPs to restrict Bedrock and GPU instance types to approved accounts.
- Set AWS Budgets and Cost Anomaly Detection alerts on Bedrock and compute.
Step 4: Use permission boundaries and SCPs
- Apply permission boundaries to roles that developers can create.
- Use SCPs to deny high-risk actions (creating IAM users, disabling CloudTrail/GuardDuty) outside approved roles.
Step 5: Automate containment
Use EventBridge rules on GuardDuty findings to trigger automatic actions, such as attaching a deny-all policy to a compromised principal or quarantining access keys, for high-confidence findings.
Verify
Simulate: "This test user's key leaked." What can it reach? The answer should be "almost nothing."