InsightCloudSec Docs

Welcome to the InsightCloudSec Docs!

InsightCloudSec by Rapid7 (formerly DivvyCloud) is a Cloud-Native Security Platform that provides real-time analysis and automated remediation for continuous security and compliance for your multi-cloud environment.

For questions reach out to us through [email protected].

Take Me to the Docs!    Release Notes

Using Access Explorer - Feature Guide

Understanding the Access Explorer Interface

Overview

After completing the setup and configuration to launch Cloud IAM Governance - Access Explorer, you will be ready to take advantage of this feature!

To launch Access Explorer navigate to “Security → Access Explorer” on your InsightCloudSec platform.

Access Explorer Landing PageAccess Explorer Landing Page

Access Explorer Landing Page

General Viewing Options

Access Explorer consists of a title toolbar with the following:

  • "Application Group" selection drop-down menu
  • “IAM Data Last Updated” menu with cache options
  • Drop-down Settings menu

Check out Access Explorer - Configuration and Settings for more details on settings.

Just below this title toolbar users can “Search for a Subject” using a specific term or a key:value pair.

The main content display in Access Explorer has three key areas (tabs): Applications, Principals, and Resources.

Applications

Applications, as the name suggests, display a list of all applications that have been discovered and created using the Application Group feature.

Viewing Applications

From the “Security → Access Explorer” section of InsightCloudSec, selecting "Access Explorer" will open the main page, which defaults to the "Applications" tab, as shown below.

Note: Applications with zero resources will be disabled.

  • Modify Columns - Modifies the displayed list of applications using the “Column Options,” “Subjects per page” (20, 50, 100), and the pagination controls.
Applications View and OptionsApplications View and Options

Applications View and Options

By default your applications display by name alphabetically in descending order.

  • Column Options - Include any of the Application Property Customizations you have added under “Access Explorer → Settings → Application Property Customizations.” Refer to the configuration documentation for details on changing or using these application settings.

    • Note: Any changes you make to the columns display will apply to Applications, Principals, and Resources.
  • Context Menu - Clicking on the arrow to the right of the name of an individual application it enables you to explore that application in greater detail or download a list of resources/principals associated with the application. This includes a filtered list of associated resources and principals.

Principals

Principals are a person or machine making a request for an action or operation on a resource. Within Access Explorer this can be a federated user, IAM Role, or IAM User with access to cloud resources. Access Explorer uses principals to map the "who" to the "what."

Viewing Principals

From the “Security → Access Explorer” section of InsightCloudSec you can select the “Principals” tab in Access Explorer to view the list of Principals.

Principals ViewPrincipals View

Principals View

  • Modify Columns - Modifies the displayed list of principals using the “Column Options,” “Subjects per page” (20, 50, 100), and the pagination controls. By default your principals display by name alphabetically in descending order.
    • Note: Any changes you make to the columns display will apply to Applications, Principals, and Resources.

Viewing Individual Principal Details

Explore an Individual PrincipalExplore an Individual Principal

Explore an Individual Principal

Clicking on the arrow to the right of an individual Principal (under the name column) opens a submenu that includes:

  • Explore This Principal - Displays a list of associated resources and applications for the selected item.
  • Principal Explorer - Opens the Principal Explorer for this principal.
  • Show Details - Opens an overlay with expanded details for the selected item including the Resource ID, name, last used, etc.
    • Note: The details that display vary based on the type of resource selected.
  • Download Accessible Resources - Generates an .xlsx file with details of associated resources.
  • Download Accessible Applications - Generates an .xlsx file with details of associated applications.

Resources

Within Access Explorer any of the resource types that InsightCloudSec can harvest for AWS (S3 Bucket, EC2 instance, etc.) can also be viewed within the context of Cloud IAM Governance. Are you interested in knowing which EC2 instances can access a critical S3 Bucket, or which containers can access an SNS Topic? Access Explorer allows you to view information at a resource-to-resource level.

Viewing Resources

From the “Security → Access Explorer” section of InsightCloudSec, you can select the “Resources” tab in Access Explorer to view the list of Resources.

Resources ViewResources View

Resources View

  • Modify Columns - Modifies the displayed list of resources using the “Column Options,” “Subjects per page” (20, 50, 100), and the pagination controls. By default your resources display by name alphabetically in descending order.
    • Note: Any changes you make to the columns display will apply to Applications, Principals, and Resources.

Viewing Resource Details

  • Explore This Resource - Displays a list of associated principals and applications for the selected item.
  • Show Details - Opens an overlay with expanded details for the selected item including the Resource ID, name, last used, etc.
    • Note: The details that display vary based on the type of resource selected.
  • Download Principals That Have Access - Generates an .xlsx file that shows the principals that can access the target resource.
  • Download Applications Which Include This Resource - Generates an .xlsx file that shows the applications that include this resource.

Viewing Details

After selecting to display Applications, Principals, or Resources, users can explore the associated items for an individual Application, Principal, or Resource respectively.

  • For example, if a user explores an Application, they will be provided with a contextual list of associated Principals and Resources. Exploring Principals provides associated Resources and Applications, and exploring Resources provides associated Principals and Applications.

In the image below the Access Explorer navigation content bar has been updated to reflect the current view "Principals with access to Resources contained in Acceptor VPC," which lets the user know they are viewing the application "Acceptor VPC" and the list of associated Resources and Principals for that application.

  • Note: The relevant icon for an access type (Application, Principals, Resources) will appear in the breadcrumbs statement above the search bar.
Example: Viewing Principals Associated with an ApplicationExample: Viewing Principals Associated with an Application

Example: Viewing Principals Associated with an Application

Context Menus for Individual Items

Within the lists of Applications, Principals, or Resources you have the option to select a context menu by clicking on the arrow to the right of any item.

  • Note: This context menu is available for every item listed and will update dynamically based on the item selected.

By selecting "Explore this Principal", you can view the list of accessible resources and the view will update the context to help you identify the filtering context you have selected. (The example below shows "Resources accessible by admin" based on the selection.)

Example: Viewing Resources Accessible by a Specific PrincipalExample: Viewing Resources Accessible by a Specific Principal

Example: Viewing Resources Accessible by a Specific Principal

Permissions

Clicking on any of the individual permissions will provide details on both the specific policies, roles, and the effective access (see Using the Principal Explorer for more details).

  • Explore Policy Stack detail by clicking on the arrow(s) to expand upon specific details around policies. Click a policy to jump to the relevant JSON in the Policy Viewer.
  • Explore the Policy Viewer by clicking the magnifying glass ("Search") to filter through the JSON or clicking "Download" to download the policy JSON file.
  • Explore Effective Access details by clicking on any of the column headings (All, List, Read, etc.).
Example: Viewing Policies,  Roles and Effective AccessExample: Viewing Policies,  Roles and Effective Access

Example: Viewing Policies, Roles and Effective Access

What's Next?

We hope this page has covered the basics and enabled you to comfortably navigate Access Explorer and gain insight in to the rich contextual data it provides.

If you still have questions, we are here to help! Reach out to us at any time through [email protected].

Updated 24 days ago

Using Access Explorer - Feature Guide


Understanding the Access Explorer Interface

Suggested Edits are limited on API Reference Pages

You can only suggest edits to Markdown body content, but not to the API spec.