Structs§
- Learned
Policy - Result of learning: observed API calls mapped to IAM actions.
Functions§
- event_
source_ to_ service - Maps CloudTrail eventSource (e.g. “s3.amazonaws.com”) to IAM service prefix.
Public so
watch.rscan reuse the same mapping table. - lookup_
events - Query CloudTrail for API calls made by a specific access key within a time window.
- poll_
cloudtrail - Poll CloudTrail until events appear or timeout is reached. CloudTrail typically has a 5-15 minute delay.