Misconfig, privilege paths and the command that proves it

A cloud review is a walk through IAM, public buckets, and the one role that can assume the other role. You want the check, the CLI, and the blast radius, not a reminder to enable MFA.

Cloud security engineers and assessors working in accounts they own or are contracted to review.

Why the mainstream APIs fail here

Asking how to escalate from this role to that role is refused as hacking AWS. You are in the account. The role is yours. The question is the assessment.

How Redline is used for this

Paste sanitized policy JSON, ask for the path, ask for the proof command. Run the command in the account. Cap the assessment key per project.

A working loop

  1. Work in accounts you control.
  2. Sanitize account ids if your policy says so; we do not keep the prompt either way.
  3. Prove the finding in the CLI, not in the chat.

Prompts are not stored. A signed receipt of the hash comes back on every call, so you can prove later what Redline logged. Details are on the privacy page. Per-model prices are on /models and the pricing model is on /pricing.

Related