A leaked Bedrock or Claude API key, or live AWS credentials for an account scan.
How It Works
The key is decoded offline. If credentials are present, the account is checked for IAM users that key minted.
Also writes a detection pack and a dry-run cleanup plan.
Results
Phantom users, a decoded key, sample SCPs, and report.json.
Overview
Bedrock and Claude API keys that outlive the role or account that minted them are a quiet cloud identity problem. Operators need a path that finds phantom Bedrock IAM, decodes a leaked ABSK offline for IR, and ships prevention and cleanup artifacts you can review before anything mutates AWS.
This is a standing check for exposure management. You run an org or account Bedrock phantom scan when AWS credentials are present, decode a demo or seized ABSK without calling the cloud, and correlate scan evidence with SCP, detection, and dry-run cleanup packs. Without AWS credentials the scan path reports that creds are required instead of inventing an empty clean bill.
It sits next to cloud exposure graphs such as Cloud Bucket Finder. This Collection unit is the Arsenal Bedrock identity path: inventory and IR first, then prevention packs you can take into change review.
Pipeline
Discover · Org/Account phantom scan inventories Bedrock phantom IAM when org mode and AWS credentials are set.
IR · Decode leaked ABSK/AEAA runs offline key decode on a demo or seized key material.