Data Exfiltration actions allow certain read-only IAM actions without resource constraints, such as s3:GetObject, ssm:GetParameter*, or secretsmanager:GetSecretValue.
- Unrestricted
s3:GetObjectpermissions has a long history of customer data leaks ssm:GetParameter*andsecretsmanager:GetSecretValueare both used to access secrets.rds:CopyDBSnapshotandrds:CreateDBSnapshotcan be used to exfiltrate RDS database contents.