❔Query search
P0's environment query searches let you find specific IAM data across your cloud inventory.
Query searches are controlled using two parts:

show - controls which kind of data are displayed
where - controls which data to show
Show control
You can choose to "show" credentials (access keys or short-term authentication), identities (users, groups, machine identities, and so forth), entitlements (in Google Cloud, a role binding; in AWS, a policy attachment), or resources (projects, accounts, services, and individual resources such as storage buckets).
Where control
The "where" control is a free-form search box. You can enter any term here, and P0 will find the principals or grants that relate to your search term.
Example:
Searching for a permission (in this case compute.instances.create in a Google Cloud assessment) will show you all grants that provide that permission:

To see why a search result matches your query, you can click on that result's "view" link. The details page will show an "Explanation" section at the bottom, describing how that result satisfies your query:

Learn the query language
A free-form term gets you started, but you can be far more specific by writing query expressions. Two pages cover the full query language:
Query Language Basics: a beginner-friendly walkthrough of the core search terms (
identity,credential,entitlement,risk) and the operators that connect them. Start here if you're new to querying.Search Reference: the complete reference for every operator, search type, and attribute, with Cypher equivalents. Use it to look up specifics.
Query examples
One of the best resources for constructing queries is to view the search queries for P0's built-in assessment monitors.
For instance, here's the query for detecting unused service account keys:
show = credential
This returns all service-account keys that have not been used in the last 40 days. For the syntax behind each term, see the Search Reference.
Query links
You can also construct queries using tooltips in the displayed data. To do this, hover over an item you want to either include or exclude from your search:

Select the corresponding "show" or "hide" link to either include or exclude that item in your search results.
Last updated