AWS

Amazon Web Services is driven entirely through its API, authenticated with IAM access keys or temporary role credentials. Nearly every attack is an IAM question: what principal do I hold, what can it do, what can it escalate to, and which resources can it reach. The surfaces below follow that shape, with privilege escalation living inside identity and data theft inside storage and data.

Enumeration#

Enumeration is not a separate surface: each surface below covers enumerating its own resources, and unauthenticated discovery (public buckets, exposed services, account IDs) lives in the surface it targets. What spans surfaces is the account-wide inventory, run first with ScoutSuite and Prowler, the IAM graph mapped with Pacu and PMapper, and the current principal's rights established with aws sts get-caller-identity and permission enumeration. Those feed every surface below.

Surfaces#

  • Identity: the IAM graph, role assumption and PassRole, policy abuse, federation, and the privilege-escalation paths, plus the Cognito, Identity Center, and Organizations identity layers.
  • Credentials: access keys, STS session tokens, instance metadata (IMDS), the secret stores, and the service credential brokers.
  • Compute: EC2 user data and instance profiles, SSM, containers and ECR, and the Beanstalk, Image Builder, App Runner, Batch, and Lightsail runtimes.
  • Storage: S3 bucket and object exposure, EBS and EFS recovery, FSx and Storage Gateway, and AWS Backup.
  • Serverless: Lambda execution roles and code, API Gateway, Function URLs, Step Functions, and EventBridge.
  • Data: RDS, DynamoDB, Redshift, SageMaker, Glue, Athena, Lake Formation, and the other managed data stores.
  • Networking: security groups and VPC reachability, Route53 and CloudFront, dangling-DNS takeover, and the edge services.
  • Logging and detection: disabling, diverting, and evading CloudTrail, GuardDuty, Config, and CloudWatch.
  • Messaging: SES mail sending and phishing, and SNS and SQS topic and queue abuse.

References#

Cookie Consent

We use cookies to enhance your experience. Learn more