What problem does it solve?
Privileged Access Management often fails in practice, leaving standing admin access, weak break-glass procedures, incomplete session monitoring, and improperly vaulted credentials that undermine least-privilege requirements.
Core Features & Use Cases
- Assess PAM coverage and effectiveness against CIS Controls v8 (5.4, 6.5) and NIST SP 800-53 Rev. 5 AC-6, including dedicated admin account separation, MFA requirements for admin paths, and least-privilege alignment.
- Evaluate privileged access patterns across privileged account inventory, just-in-time (JIT) design and enforcement, break-glass readiness, and PAM bypass/shadow access paths.
- Validate evidence-grade operational controls such as session recording, monitoring, auditability, and credential vaulting/rotation, producing findings with severity, framework mapping, and remediation guidance.
- Use Case Example: When auditing a cloud + on-prem environment for privileged credential risk, run this skill to identify where root/admin access is not controlled by PAM, where JIT does not revoke timely access, and where session recording is missing or not tamper-protected.
Quick Start
Run the privileged-access skill on your PAM configuration files and exports by invoking it with the target file or directory as an argument.