principalmapper
« Back to VersTracker
Description:
Quickly evaluate IAM permissions in AWS
Type: Formula  |  Tracked Since: Dec 28, 2025
Links: Homepage  |  formulae.brew.sh
Category: Security
Tags: aws iam security auditing pentesting
Install: brew install principalmapper
About:
Principalmapper (PMapper) is a tool that allows security professionals and developers to evaluate AWS Identity and Access Management (IAM) permissions. It can analyze policies to identify privilege escalation paths and resource access across an AWS account. This helps in auditing permissions and understanding the effective access of IAM principals.
Key Features:
  • Graph-based analysis of IAM relationships
  • Identifies privilege escalation paths
  • Supports multi-account and multi-region scanning
  • Includes a query engine for complex permission checks
Use Cases:
  • Auditing AWS account permissions for security compliance
  • Identifying potential privilege escalation vectors
  • Red teaming and penetration testing AWS environments
Alternatives:
  • Pacu – Pacu is an AWS exploitation framework focused on attacking, while PMapper focuses on analysis and mapping.
  • ScoutSuite – ScoutSuite provides a broader security audit of various AWS services, whereas PMapper specializes deeply in IAM relationships.
Version History
Detected Version Rev Change Commit
Jan 10, 2026 8:26am 7 REVISION_ONLY 041ac913
Oct 10, 2024 6:54pm 4 VERSION_BUMP f1f41394