AWS secret stores exist to hand credentials to applications, which makes them a direct source for an attacker who holds the read permission. A principal that can call secretsmanager:GetSecretValue or ssm:GetParameter with decryption is reading database passwords, API keys, and other credentials straight out of the account.
What folds in here#
- Secrets Manager:
GetSecretValueacross stored secrets. - Parameter Store:
GetParameter/GetParametersover SecureString and plaintext values. - KMS:
Decryptand permissive key policies over envelope-encrypted data.
Sweeping the stores#
aws secretsmanager list-secrets --query 'SecretList[].Name'
aws ssm describe-parameters --query 'Parameters[].Name'