Permiso creates a single pane of glass for your identities across IdPs, IaaS, SaaS and CI/CD pipelines to find the riskiest actors in your environments.| permiso.io
SkyScalpel is an open-source tool that obfuscates, deobfuscates and detects obfuscated JSON documents with an additional focus on IAM policies used to control permissions in AWS cloud environments..| permiso.io
Permiso uncovered a subtle yet critical logging evasion vulnerability within AWS environments - mainly the differing size limitations of individual AWS CloudTrail logs versus the actual content being logged. By exploiting whitespace and other syntactic quirks, an attacker can create valid IAM policies that effectively bypass CloudTrail logging.| permiso.io