aws console data.md

Cross-Account Access via Console

There are multiple ways to deploy AWS roles to provide Dropzone visibility into your environment. See the AWS documentation for more info.

The following steps walk you through creating a role and granting it to the Dropzone-provided role in the AWS console. This also has the information you'd need to create your own Infrastructure-as-Code configuration if you choose.

Find the Dropzone IAM Role Information

Create the Role

Next you'll create a role in the AWS account you want monitored and available.

You'll need the following information:

Value Used In Source
Dropzone-provided ARN AWS Role Custom Trust Policy JSON ARN value from the AWS Data Source "Connection" section
Dropzone-provided External ID AWS Role Custom Trust Policy JSON External ID value from the AWS Data Source "Connection" section
AWS Account ID Custom Permissions Policy JSON Find this in the user/role dropdown in the upper right of the AWS console
{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Effect": "Allow",
            "Principal": {
                "AWS": "<Dropzone-provided User ARN>"
            },
            "Action": "sts:AssumeRole",
            "Condition": {
                "StringEquals": {
                    "sts:ExternalId": "<Dropzone-provided External ID>"
                }
            }
        }
    ]
}
Service Integration Policy Required
CloudTrail AWSCloudTrail_ReadOnlyAccess Required
EC2 AmazonEC2ReadOnlyAccess Required
EKS eks:ListClusters, eks:DescribeCluster Optional
GuardDuty AmazonGuardDutyReadOnlyAccess Optional
IAM IAMReadOnlyAccess Optional
Route53 AmazonRoute53ReadOnlyAccess Optional
S3 AmazonS3ReadOnlyAccess Optional
S3 (Outposts) AmazonS3OutpostsReadOnlyAccess Optional
Systems Manager AmazonSSMReadOnlyAccess Optional

CloudTrail Permissions: Required (Minimum): AWSCloudTrail_ReadOnlyAccess managed policy. This provides the minimum permissions needed for CloudTrail integration. The integration will use the lookup_events API for querying CloudTrail logs. Optional (Recommended): cloudtrail:StartQuery permission on event datastores. This enables CloudTrail Lake SQL queries, which provide more powerful querying capabilities. If this permission is not available, the integration will automatically fall back to the lookup_events API. To add this permission, attach a custom policy with:

{
  "Effect": "Allow",
  "Action": "cloudtrail:StartQuery",
  "Resource": "arn:aws:cloudtrail:*:*:eventdatastore/*"
}

EKS Note: AWS does not provide a managed EKS policy. Create a custom policy with eks:ListClusters, eks:DescribeCluster, and other read-only EKS permissions (eks:Describe*, eks:List*) as needed.

Permissions Policy
AWSCloudTrail_ReadOnlyAccess
AmazonEC2ReadOnlyAccess
AmazonGuardDutyReadOnlyAccess
AmazonRoute53ReadOnlyAccess
AmazonS3OutpostsReadOnlyAccess
AmazonS3ReadOnlyAccess
AmazonSSMReadOnlyAccess
IAMReadOnlyAccess

Add a custom permission policy

{
    "Version": "2012-10-17",
    "Statement": [
        {
            "Sid": "CloudTrailStartQuery",
            "Effect": "Allow",
            "Action": [
                "kms:Decrypt",
                "kms:GenerateDataKey",
                "cloudtrail:StartQuery"
            ],
            "Resource": [
                "arn:aws:kms:*:<your_accountnumber>:key/*",
                "arn:aws:cloudtrail:*:<your_accountnumber>:eventdatastore/*"
            ]
        },
        {
         "Sid": "EKSReadOnly",
         "Effect": "Allow",
         "Action": [
             "eks:Describe*",
             "eks:List*"
         ],
         "Resource": "*"
        }

]
}

You should be returned to the Dropzone_AI role page and see the policies you've added, including the custom policy.

Repeat For Additional AWS Accounts

Repeat the steps taken in the "Create the Role" section for all other AWS accounts you want visible to Dropzone.

Once done, you may move onto configuring the Dropzone Data and Alert Sources described in the AWS documentation