Skip to content

Releases: zoph-io/IAMTrail

2026-04-02-00-00-update-5-policies

02 Apr 00:46

Choose a tag to compare

Files changed:
policies/AmazonEKSLoadBalancingPolicy
policies/AnthropicFullAccess
policies/AnthropicInferenceAccess
policies/AnthropicLimitedAccess
policies/AnthropicReadOnlyAccess

2026-04-01-20-00-update-1-policies

01 Apr 20:46

Choose a tag to compare

Files changed:
.github/workflows/main.yml
README.md
automation/lambdas/instant-notifier/index.py
automation/runbook-prod.sh
policies/AnthropicLimitedAccess
website/app/endpoints/page.tsx
website/app/feeds/page.tsx
website/app/guardduty/page.tsx
website/app/layout.tsx
website/app/policies/page.tsx
website/public/feeds/all.xml
website/public/feeds/endpoints.xml
website/public/feeds/guardduty.xml
website/public/feeds/iam-policies.xml
website/public/sitemap.xml
website/scripts/generate-data.js

2026-04-01-12-00-update-15-policies

01 Apr 12:46

Choose a tag to compare

Files changed:
Makefile
automation/lambdas/change-recorder/index.py
automation/lambdas/digest-sender/index.py
automation/lambdas/ecs-failure-notifier/index.py
automation/runbook-dev.sh
automation/runbook-prod.sh
automation/scripts/test_x_post.py
automation/scripts/x_poster.py
automation/tf-fargate/cloudwatch.tf
automation/tf-fargate/variables.tf
findings/AIDevOpsAgentAccessPolicy.json
findings/AWSEC2VssRestorePolicy.json
findings/AWSElementalMediaConnectCreateBridge.json
findings/AWSElementalMediaConnectCreateFlow.json
findings/AWSElementalMediaConnectDeleteBridge.json
findings/AWSElementalMediaConnectDeleteFlow.json
findings/AmazonEVSServiceRolePolicy.json
findings/DBModProvisioningAndMigration.json
findings/README.md
findings/SageMakerStudioAdminIAMDefaultExecutionPolicy.json
findings/SageMakerStudioAdminIAMPermissiveExecutionPolicy.json
findings/SageMakerStudioUserIAMDefaultExecutionPolicy.json
findings/SageMakerStudioUserIAMPermissiveExecutionPolicy.json
policies-list.json
policies/AWSCertificateManagerReadOnly
policies/AWSMarketplaceManageSubscriptions
policies/AWSMarketplaceRead-only
policies/AWSMarketplaceSellerFullAccess
policies/AWSMarketplaceSellerOfferManagement
policies/AWSObservabilityAdminTelemetryEnablementServiceRolePolicy
policies/AmazonPollyReadOnlyAccess
policies/AnthropicFullAccess
policies/AnthropicInferenceAccess
policies/AnthropicLimitedAccess
policies/AnthropicReadOnlyAccess
policies/CloudWatchSyntheticsFullAccess
policies/ReadOnlyAccess
policies/SageMakerStudioUserIAMConsolePolicy
policies/ViewOnlyAccess

2026-03-31-08-00-update-35-policies

31 Mar 08:45

Choose a tag to compare

Files changed:
.github/workflows/check-endpoints.yml
.github/workflows/deploy-cloudfront.yml
.github/workflows/dev.yml
.github/workflows/guardduty-sync.yml
.github/workflows/main.yml
.gitignore
LICENSE
README.md
assets/compagnion-website.png
assets/mamip_twitter.png
assets/screenshot.png
assets/social.png
assets/watching.gif
automation/Dockerfile
automation/README.md
automation/github-actions-iam-policy.json
automation/lambdas/digest-sender/index.py
automation/lambdas/guardduty-recorder/index.py
automation/lambdas/instant-notifier/index.py
automation/lambdas/subscription-api/index.py
automation/runbook-prod.sh
automation/scripts/check-endpoints.js
automation/scripts/x_poster.py
automation/tf-fargate/cloudwatch.tf
automation/tf-fargate/iam.tf
automation/tf-fargate/subscriptions.tf
automation/tf-fargate/variables.tf
data/endpoint-changes/.gitkeep
data/endpoint-changes/20211221-1252.json
data/endpoint-changes/20211221-1255.json
data/endpoint-changes/20211222-0101.json
data/endpoint-changes/20220104-0101.json
data/endpoint-changes/20220106-0107.json
data/endpoint-changes/20220114-0104.json
data/endpoint-changes/20220115-0101.json
data/endpoint-changes/20220126-0104.json
data/endpoint-changes/20220129-0054.json
data/endpoint-changes/20220204-0057.json
data/endpoint-changes/20220205-0051.json
data/endpoint-changes/20220211-0106.json
data/endpoint-changes/20220218-0108.json
data/endpoint-changes/20220222-0102.json
data/endpoint-changes/20220224-0108.json
data/endpoint-changes/20220226-0101.json
data/endpoint-changes/20220301-0120.json
data/endpoint-changes/20220302-0116.json
data/endpoint-changes/20220304-0116.json
data/endpoint-changes/20220309-0112.json
data/endpoint-changes/20220310-0115.json
data/endpoint-changes/20220315-0113.json
data/endpoint-changes/20220317-0112.json
data/endpoint-changes/20220324-0117.json
data/endpoint-changes/20220329-0120.json
data/endpoint-changes/20220401-0141.json
data/endpoint-changes/20220402-0120.json
data/endpoint-changes/20220407-0121.json
data/endpoint-changes/20220412-0123.json
data/endpoint-changes/20220415-0126.json
data/endpoint-changes/20220420-0149.json
data/endpoint-changes/20220421-0142.json
data/endpoint-changes/20220503-0149.json
data/endpoint-changes/20220504-0147.json
data/endpoint-changes/20220505-0142.json
data/endpoint-changes/20220506-0123.json
data/endpoint-changes/20220507-0123.json
data/endpoint-changes/20220510-0118.json
data/endpoint-changes/20220519-0151.json
data/endpoint-changes/20220520-0141.json
data/endpoint-changes/20220524-0147.json
data/endpoint-changes/20220525-0146.json
data/endpoint-changes/20220526-0148.json
data/endpoint-changes/20220527-0144.json
data/endpoint-changes/20220528-0140.json
data/endpoint-changes/20220601-0200.json
data/endpoint-changes/20220607-0138.json
data/endpoint-changes/20220608-0140.json
data/endpoint-changes/20220609-0140.json
data/endpoint-changes/20220611-0141.json
data/endpoint-changes/20220617-0144.json
data/endpoint-changes/20220618-0146.json
data/endpoint-changes/20220630-0152.json
data/endpoint-changes/20220706-0202.json
data/endpoint-changes/20220712-0200.json
data/endpoint-changes/20220713-0152.json
data/endpoint-changes/20220715-0206.json
data/endpoint-changes/20220716-0152.json
data/endpoint-changes/20220719-0206.json
data/endpoint-changes/20220721-0154.json
data/endpoint-changes/20220723-0153.json
data/endpoint-changes/20220729-0202.json
data/endpoint-changes/20220730-0152.json
data/endpoint-changes/20220803-0155.json
data/endpoint-changes/20220805-0153.json
data/endpoint-changes/20220809-0159.json
data/endpoint-changes/20220812-0149.json
data/endpoint-changes/20220813-0143.json
data/endpoint-changes/20220817-0207.json
data/endpoint-changes/20220820-0158.json
data/endpoint-changes/20220823-0207.json
data/endpoint-changes/20220826-0208.json
data/endpoint-changes/20220830-0219.json
data/endpoint-changes/20220831-0225.json
data/endpoint-changes/20220902-0205.json
data/endpoint-changes/20220903-0208.json
data/endpoint-changes/20220910-0211.json
data/endpoint-changes/20220914-0209.json
data/endpoint-changes/20220915-0222.json
data/endpoint-changes/20220916-0224.json
data/endpoint-changes/20220920-0211.json
data/endpoint-changes/20220922-0209.json
data/endpoint-changes/20220923-0218.json
data/endpoint-changes/20220924-0219.json
data/endpoint-changes/20220927-0208.json
data/endpoint-changes/20220928-0209.json
data/endpoint-changes/20220930-0235.json
data/endpoint-changes/20221001-0229.json
data/endpoint-changes/20221005-0202.json
data/endpoint-changes/20221007-0209.json
data/endpoint-changes/20221008-0151.json
data/endpoint-changes/20221014-0226.json
data/endpoint-changes/20221015-0220.json
data/endpoint-changes/20221019-0211.json
data/endpoint-changes/20221020-0212.json
data/endpoint-changes/20221021-0152.json
data/endpoint-changes/20221025-0223.json
data/endpoint-changes/20221026-0158.json
data/endpoint-changes/20221028-0204.json
data/endpoint-changes/20221029-0148.json
data/endpoint-changes/20221101-0214.json
data/endpoint-changes/20221103-0151.json
data/endpoint-changes/20221105-0149.json
data/endpoint-changes/20221108-0147.json
data/endpoint-changes/20221109-0157.json
data/endpoint-changes/20221111-0150.json
data/endpoint-changes/20221112-0146.json
data/endpoint-changes/20221116-0145.json
data/endpoint-changes/20221117-0143.json
data/endpoint-changes/20221118-0147.json
data/endpoint-changes/20221119-0142.json
data/endpoint-changes/20221123-0127.json
data/endpoint-changes/20221128-0623.json
data/endpoint-changes/20221129-0622.json
data/endpoint-changes/20221130-0127.json
data/endpoint-changes/20221201-0144.json
data/endpoint-changes/20221202-0121.json
data/endpoint-changes/20221206-0119.json
data/endpoint-changes/20221207-0123.json
data/endpoint-changes/20221208-0120.json
data/endpoint-changes/20221209-0122.json
data/endpoint-changes/20221213-0125.json
data/endpoint-changes/20221214-0121.json
data/endpoint-changes/20221215-0123.json
data/endpoint-changes/20221216-0116.json
data/endpoint-changes/20221217-0114.json
data/endpoint-changes/20221220-0118.json
data/endpoint-changes/20221221-0114.json
data/endpoint-changes/20221222-0117.json
data/endpoint-changes/20221223-0115.json
data/endpoint-changes/20221227-0747.json
data/endpoint-changes/20221231-0116.json
data/endpoint-changes/20230104-0119.json
data/endpoint-changes/20230110-0122.json
data/endpoint-changes/20230111-0120.json
data/endpoint-changes/20230113-0122.json
data/endpoint-changes/20230114-0116.json
data/endpoint-changes/20230118-0122.json
data/endpoint-changes/20230119-0122.json
data/endpoint-changes/20230120-0121.json
data/endpoint-changes/20230121-0119.json
data/endpoint-changes/20230124-0121.json
data/endpoint-changes/20230125-0117.json
data/endpoint-changes/20230126-0119.json
data/endpoint-changes/20230127-0123.json
data/endpoint-changes/20230201-0138.json
data/endpoint-changes/20230202-0122.json
data/endpoint-changes/20230203-0124.json
data/endpoint-changes/20230207-0120.json
data/endpoint-changes/20230209-0121.json
data/endpoint-changes/20230210-0125.json
data/endpoint-changes/20230211-0117.json
data/endpoint-changes/20230214-0124.json
data/endpoint-changes/20230216-0124.json
data/endpoint-changes/20230217-0126.json
data/endpoint-changes/20230218-0121.json
data/endpoint-changes/20230222-0121.json
data/endpoint-changes/20230224-0122.json
data/endpoint-changes/20230228-0123.json
data/endpoint-changes/20230301-0138.json
data/endpoint-changes/20230302-0136.json
data/endpoint-changes/20230303-0319.json
data/endpoint-changes/20230304-0122.json
data/endpoint-changes/20230308-0128.json
data/endpoint-changes/20230309-0127.json
data/endpoint-changes/20230310-0127.json
data/endpoint-changes/20230311-0115.json
data/endpoint-changes/20230314-0110.json
data/endpoint-changes/20230315-0119.json
data/endpoint-changes/20230316-0120.json
data/endpoint-changes/20230318-0118.json
data/endpoint-changes/20230321-0115.json
data/endpoint-changes/20230322-0115.json
data/endpoint-changes/20230323-0115.json
data/endpoint-changes/20230324-0115.json
data/endpoint-changes/20230325-0113.json
data/endpoint-changes/20230329-0122.json
data/endpoint-changes/20230330-0118.json
data/endpoint-changes/20230331-0117.json
data/endpoint-changes/20230401-0116.json
data/endpoint-changes/20230404-0118.json
data/endpoint-changes/20230405-0102.json
data/endpoint-changes/20230406-0111.json
data/endpoint-changes/20230407-0108.json
data/endpoint-changes/20230411-0112.json
data/endpoint-changes/20230412-0113.json
data/endpoint-changes/20230413-0111.json
data/endpoint-changes/20230414-0113.json
data/endpoint-changes/20230415-0115.json
data/endpoint-changes/20230418-0112.json
data/endpoint-changes/20230420-0112.json
data/endpoint-changes/20230421-0112.json
data/endpoint-changes/20230422-0114.json
data/endpoint-changes/20230425-0117.json
data/endpoint-changes/20230426-0113.json
data/endpoint-changes/20230427-0115.json
data/endpoint-changes/20230429-0113.json
data/endpoint-changes/20230502-0114.json
data/endpoint-changes/20230503-0115.json
data/endpoint-changes/20230509-0115.json
data/endpoint-changes/20230510-0113.json
data/endpoint-changes/20230517-0116.json
data/endpoint-changes/20230519-0115.json
data/endpoint-changes/20230520-0112.json
data/endpoint-changes/20230524-0118.json
data/endpoint-changes/20230525-0115.json
data/endpoint-changes/20230526-0115.json
data/endpoint-changes/20230527-0115.json
data/endpoint-changes/20230531-0019.json
data/endpoint-changes/20230602-0019.json
data/endpoint-changes/20230607-0019.json
data/endpoint-changes/20230609-0020.json
data/endpoint-changes/20230613-0019.json
data/endpoint-changes/20230616-0018.json
data/endpoint-changes/20230621-0018.json
data/endpoint-changes/20230704-0020.json
data/endpoint-changes/20230707-0021.json
data/endpoint-changes/20230708-0021.json
data/endpoint-changes/20230714-0021.json
data/endpoint-changes/20230718-0605.json
data/endpoint-changes/20230719-0031.json
data/endpoint-changes/20230725-0019.json
data/endpoint-changes/20230727-0017.js...

Read more

2026-03-16-20-00-AWSCompromisedKeyQuarantineV3

16 Mar 21:25

Choose a tag to compare

Files changed:
.github/workflows/deploy-cloudfront.yml
.github/workflows/dev.yml
.github/workflows/main.yml
.gitignore
Makefile
automation/Dockerfile
automation/lambdas/change-recorder/index.py
automation/lambdas/digest-sender/index.py
automation/lambdas/instant-notifier/index.py
automation/lambdas/shared/discord_notifier.py
automation/lambdas/subscription-api/index.py
automation/runbook-dev.sh
automation/runbook-prod.sh
automation/tf-fargate/.terraform-version
automation/tf-fargate/.terraform.lock.hcl
automation/tf-fargate/ecr.tf
automation/tf-fargate/ecs.tf
automation/tf-fargate/iam.tf
automation/tf-fargate/subscriptions.tf
policies/AWSCompromisedKeyQuarantineV3
website/app/about/page.tsx
website/app/accounts/layout.tsx
website/app/accounts/page.tsx
website/app/apple-icon.svg
website/app/brand-new/page.tsx
website/app/deprecated/page.tsx
website/app/findings/layout.tsx
website/app/findings/page.tsx
website/app/globals.css
website/app/icon.svg
website/app/largest-policies/page.tsx
website/app/layout.tsx
website/app/manage/page.tsx
website/app/most-active/page.tsx
website/app/page.tsx
website/app/policies/[name]/PolicyDetailClient.tsx
website/app/policies/[name]/page.tsx
website/app/policies/layout.tsx
website/app/policies/page.tsx
website/app/service-growth/page.tsx
website/app/subscribe/page.tsx
website/components/NavBar.tsx
website/components/PolicyAgeChart.tsx
website/components/PolicyList.tsx
website/components/ReinventPulseChart.tsx
website/components/SeasonalityChart.tsx
website/components/StatsCard.tsx
website/components/VelocityChart.tsx
website/components/VersionDistributionChart.tsx
website/next.config.js
website/package-lock.json
website/package.json
website/public/robots.txt
website/public/sitemap.xml
website/scripts/generate-data.js
website/tailwind.config.ts

2026-03-16-16-00-AWSCompromisedKeyQuarantineV3

16 Mar 17:28

Choose a tag to compare

Files changed:
findings/README.md
policies/AWSCompromisedKeyQuarantineV3

2026-03-16-00-00-AWSElasticBeanstalkManagedUpdatesServiceRolePolicy

16 Mar 01:27

Choose a tag to compare

Files changed:
DEPRECATED.json
README.md
findings/AmazonRoute53RecoveryControlConfigReadOnlyAccess.json
findings/README.md
policies-list.json
policies/AWSElasticBeanstalkManagedUpdatesServiceRolePolicy

2026-03-13-16-00-AWSElasticBeanstalkManagedUpdatesServiceRolePolicy

13 Mar 17:25

Choose a tag to compare

Files changed:
findings/AIOpsAssistantPolicy.json
findings/AWSAuditManagerAdministratorAccess.json
findings/AWSAuditManagerServiceRolePolicy.json
findings/AWSBackupGuardDutyRolePolicyForScans.json
findings/AWSBatchFullAccess.json
findings/AWSCloud9Administrator.json
findings/AWSCloud9EnvironmentMember.json
findings/AWSCloud9User.json
findings/AWSCodePipeline_FullAccess.json
findings/AWSCodePipeline_ReadOnlyAccess.json
findings/AWSCodeStarFullAccess.json
findings/AWSDeepLensLambdaFunctionAccessPolicy.json
findings/AWSDeepRacerFullAccess.json
findings/AWSEC2VssSnapshotPolicy.json
findings/AWSElasticBeanstalkCustomPlatformforEC2Role.json
findings/AWSElasticBeanstalkRoleCore.json
findings/AWSElasticBeanstalkService.json
findings/AWSElasticBeanstalkWebTier.json
findings/AWSElasticBeanstalkWorkerTier.json
findings/AWSGlueConsoleFullAccess.json
findings/AWSGlueDataBrewServiceRole.json
findings/AWSIAMIdentityCenterAllowListForIdentityContext.json
findings/AWSMarketplaceFullAccess.json
findings/AWSMcpServiceActionsFullAccess.json
findings/AWSMigrationHubOrchestratorConsoleFullAccess.json
findings/AWSMigrationHubOrchestratorServiceRolePolicy.json
findings/AWSMigrationHubRefactorSpaces-EnvironmentsWithoutBridgesFullAccess.json
findings/AWSMigrationHubRefactorSpacesFullAccess.json
findings/AWSObservabilityAdminTelemetryEnablementServiceRolePolicy.json
findings/AWSOrganizationsServiceTrustPolicy.json
findings/AWSProtonCodeBuildProvisioningServiceRolePolicy.json
findings/AWSQuickSetupDeploymentRolePolicy.json
findings/AWSQuickSetupDistributorPermissionsBoundary.json
findings/AWSQuickSetupPatchPolicyDeploymentRolePolicy.json
findings/AWSQuickSetupPatchPolicyPermissionsBoundary.json
findings/AWSQuickSetupSSMDeploymentRolePolicy.json
findings/AWSQuickSetupSSMHostMgmtPermissionsBoundary.json
findings/AWSResourceExplorerServiceRolePolicy.json
findings/AWSSSODirectoryAdministrator.json
findings/AWSSSODirectoryReadOnly.json
findings/AWSSSOMasterAccountAdministrator.json
findings/AWSSSOMemberAccountAdministrator.json
findings/AWSSSOReadOnly.json
findings/AWSServiceRoleForAmazonEKSNodegroup.json
findings/AWSSupplyChainFederationAdminAccess.json
findings/AWSTransformApplicationDeploymentPolicy.json
findings/AWSTransformApplicationECSDeploymentPolicy.json
findings/AdministratorAccess-Amplify.json
findings/AdministratorAccess.json
findings/AlexaForBusinessFullAccess.json
findings/AmazonCodeGuruReviewerServiceRolePolicy.json
findings/AmazonConnectServiceLinkedRolePolicy.json
findings/AmazonDataZoneEnvironmentRolePermissionsBoundary.json
findings/AmazonDataZoneGlueManageAccessRolePolicy.json
findings/AmazonDataZoneSageMakerEnvironmentRolePermissionsBoundary.json
findings/AmazonDocDBElasticFullAccess.json
findings/AmazonDynamoDBFullAccesswithDataPipeline.json
findings/AmazonECSServiceRolePolicy.json
findings/AmazonEKSComputePolicy.json
findings/AmazonEKSNetworkingPolicy.json
findings/AmazonElasticMapReduceFullAccess.json
findings/AmazonElasticMapReduceRole.json
findings/AmazonGuardDutyMalwareProtectionServiceRolePolicy.json
findings/AmazonGuardDutyServiceRolePolicy.json
findings/AmazonInspector2AgentlessServiceRolePolicy.json
findings/AmazonLaunchWizardFullAccessV2.json
findings/AmazonMSKFullAccess.json
findings/AmazonRedshiftAllCommandsFullAccess.json
findings/AmazonRedshiftDataFullAccess.json
findings/AmazonRedshiftFullAccess.json
findings/AmazonSageMakerAdmin-ServiceCatalogProductsServiceRolePolicy.json
findings/AmazonSageMakerFullAccess.json
findings/AmazonSageMakerNotebooksServiceRolePolicy.json
findings/AmazonSageMakerServiceCatalogProductsCodeBuildServiceRolePolicy.json
findings/AmazonSageMakerServiceCatalogProductsLambdaServiceRolePolicy.json
findings/AmazonSecurityLakeAdministrator.json
findings/AmazonSecurityLakeMetastoreManager.json
findings/AppRunnerNetworkingServiceRolePolicy.json
findings/BatchServiceRolePolicy.json
findings/CloudTrailEventContext.json
findings/CloudWatchApplicationSignalsFullAccess.json
findings/CloudWatchApplicationSignalsReadOnlyAccess.json
findings/EC2FastLaunchServiceRolePolicy.json
findings/FMSServiceRolePolicy.json
findings/IAMFullAccess.json
findings/KafkaServiceRolePolicy.json
findings/MemoryDBServiceRolePolicy.json
findings/NeptuneConsoleFullAccess.json
findings/PowerUserAccess.json
findings/RDSCloudHsmAuthorizationRole.json
findings/README.md
findings/ResourceGroupsTaggingAPITagUntagSupportedResources.json
findings/S3UnlockBucketPolicy.json
findings/SQSUnlockQueuePolicy.json
findings/SageMakerStudioProjectRoleMachineLearningPolicy.json
findings/SecurityAudit.json
findings/SystemAdministrator.json
findings/ViewOnlyAccess.json
policies-list.json
policies/AWSElasticBeanstalkManagedUpdatesServiceRolePolicy

2026-03-12-00-00-AmazonDataZoneSageMakerEnvironmentRolePermissionsBoundary

12 Mar 01:02

Choose a tag to compare

2026-03-12-00-00-AWSObservabilityAdminTelemetryEnablementServiceRolePolicy

12 Mar 01:02

Choose a tag to compare

Files changed:
policies/AmazonDataZoneSageMakerEnvironmentRolePermissionsBoundary