EC2 is the richest compute surface in AWS because an instance ties together a role (the instance profile), a boot script (user data), and persistent disks (EBS volumes and the AMIs and snapshots they come from). Each is a separate way in: steal the role from the metadata service, read secrets left in user data, or recover another instance's data from a snapshot you can mount.
What folds in here#
- User data: reading boot scripts for secrets, or setting user data to run code on the next boot.
- Instance profile: harvesting the attached role's credentials from the metadata service.
- Snapshots: creating, sharing, and mounting EBS snapshots to read volumes offline.
- AMI: secrets baked into shared or public machine images, and launching from them.
Launching a new instance with a passed role is a privilege-escalation path and lives under identity PassRole; the pages here cover instances that already exist.