Cloudflare API token creation and scope management
Looks up permission group ids by name and mints or rescopes an account API token from them; builds least-privilege tokens without hardcoding UUIDs.
Looks up permission group ids by name and mints or rescopes an account API token from them; builds least-privilege tokens without hardcoding UUIDs.
Returns Cloudflare's published IPv4 and IPv6 edge ranges as one CIDR per row; the source list for origin firewall allowlists.
Reads the rate limiting rules on a zone's http_ratelimit phase, and sets or clears them; the entrypoint ruleset pattern used for edge throttling.
Lists the principals assigned to a Databricks workspace with their permission level, resolving users, groups and service principals into one view.
Lists IAM service accounts in one project with email, display name and unique id; the workload principal inventory for a privilege audit.
Lists a user's access keys with their age in days; keys older than the rotation window are the finding.
Assesses the IAM account password policy against CIS AWS Foundations Benchmark password controls, returning raw values and per-control PASS/FAIL verdicts.
Inventories the SAML and OIDC identity providers registered in the account; the trusted federation surface behind assumable roles.
Lists IAM roles whose trust policy admits principals from other AWS accounts, flagging external id and federation use; the cross-account exposure surface.
Enumerates IAM users in the account; IAM is global and always served from us-east-1, so the query takes no parameters.
Lists IAM users alongside whether they have a virtual MFA device registered; console-capable users without MFA are the finding.
Reads a Lambda function's resource policy and flags statements granting invoke rights to a wildcard principal; the public-invoke exposure check.
Reports the four block-public-access settings plus object ownership for a bucket; any flag returning 0 leaves a public exposure path open.
Full security configuration for one bucket: public access block, encryption, versioning, ownership controls and logging.