#27 Record AWS API calls to improve IAM Policies

the blog post Record AWS API calls to improve IAM Policies

Have you ever looked at an IAM policy and wondered: Is it really necessary to grant access to this specific action? Or do you need to know which API calls a legacy or 3rd party application is actually sending to come up with a secure IAM policy? CloudTrail can help here, but there is something better: Record API calls with the AWS SDKs and CLI (including the stuff that is not visible in CloudTrail).

In this episode, you learn to capture the data without touching source code. You also analyze the data and use the results to improve your IAM policies.

