Version: '2012-10-17' Statement: - Sid: RequiredForMarketplaceEC2andAmiImportScoped Effect: Allow Action: - ec2:DeleteSnapshot - ec2:DeleteTags - ec2:TerminateInstances - ec2:StopInstances - ec2:StartInstances - ec2:DescribeAddresses - ec2:AssociateAddress Resource: '*' Condition: StringLike: aws:ResourceTag/Name: CadoResponse* - Sid: RequiredToCheckPolicy Action: - iam:ListRolePolicies - iam:GetPolicy - iam:GetRolePolicy - iam:GetPolicyVersion - iam:SimulatePrincipalPolicy Resource: '*' Effect: Allow - Sid: RequiredForMemoryForensics Effect: Allow Action: - ssm:SendCommand - ssm:DescribeInstanceInformation Resource: - arn:aws:ec2:*:*:instance/* - arn:aws:ssm:*::document/AWS-RunShellScript - arn:aws:ssm:*::document/AWS-RunPowerShellScript - Sid: RequiredForS3Import Effect: Allow Action: - s3:ListAllMyBuckets - s3:GetObject - s3:RestoreObject - s3:ListBucket - s3:GetBucketLocation Resource: '*' - Sid: RequiredForLambdaImport Effect: Allow Action: - lambda:GetFunction - lambda:ListFunctions - logs:FilterLogEvents - ecr:GetAuthorizationToken - ecr:GetDownloadURLForLayer - ecr:BatchGetImage Resource: '*' - Sid: RequiredForEcsImport Effect: Allow Action: - ecs:ListClusters - ecs:DescribeClusters - ecs:ListServices - ecs:DescribeServices - ecs:ListTasks - ecs:DescribeTasks - ecs:ExecuteCommand Resource: '*' - Sid: RequiredForEKSImport Effect: Allow Action: - eks:ListClusters - eks:DescribeCluster Resource: '*' - Sid: RequiredForEc2ImportAndAmiImportScoped Effect: Allow Action: - cloudtrail:LookupEvents - ec2:DescribeVolumesModifications - ec2:CopyImage - ec2:DescribeFlowLogs - ec2:DescribeSnapshots - ec2:CreateSnapshot - ec2:CreateTags - ssm:DescribeInstanceInformation - ec2:DescribeInstances - ec2:DescribeVolumes - ec2:DescribeImages - ssm:StartSession - ssm:TerminateSession - ssm:GetCommandInvocation - iam:GetInstanceProfile - ebs:ListSnapshotBlocks - ebs:ListChangedBlocks - ebs:GetSnapshotBlock Resource: '*' - Sid: RequiredForEc2ImportAndAmiImport2 Effect: Allow Action: - ec2:ModifyInstanceAttribute Resource: '*' Condition: StringLike: aws:ResourceTag/Name: CadoResponse* StringEquals: ec2:Attribute: BlockDeviceMapping - Sid: RequiredForAmiImports Effect: Allow Action: - ec2:DeregisterImage Resource: '*' Condition: StringLike: aws:ResourceTag/Name: CadoResponse*