In HackerOne 121461 a researcher created the missing bucket in their own AWS account and served files on a2.bime.io. The state that allowed it is a name sitting in the DNS zone with no matching bucket in the account.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+30
- Incentives85
- Confidence60
In HackerOne report #3022516 the trail was multi-region, the metric filter for unauthorised API calls existed and the alarm published to an SNS topic, while threat_detection.enabled read false. Turning it on costs one CLI call.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives65
- Confidence60
A policy that lets users read and manage their own IAM profile usually carries iam:AttachUserPolicy scoped to ${aws:username}. That scope is enough to attach AdministratorAccess to yourself in a single call.
Reality
- Evidence66
- Adoption
- Insufficient
- Hype gap+20
- Incentives70
- Confidence56
A security scanner now owns the create, update and retire lifecycle for cloud configuration items. That moves the accuracy of IT's record of record onto whatever the scanner can reach.
Reality
- Evidence30
- Adoption15
- Hype gap+40
- Incentives85
- Confidence55
A New Stack piece argues the new shadow IT gets provisioned inside your own cloud account by an agent working for a helpful engineer, which means the OAuth grants and expense reports your playbook watches never fire.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+24
- Incentives55
- Confidence55
All eleven issues score within half a point, so the ranking is useless for triage. One practitioner's decomposition puts 93 of 112 checkable properties inside a config snapshot, and 19 outside it.
Reality
- Evidence32
- Adoption
- Insufficient
- Hype gap+34
- Incentives86
- Confidence33