SSM Parameter Store holds configuration and secrets as named parameters, SecureString values KMS-encrypted and the rest in plaintext. ssm:GetParameter with --with-decryption (plus kms:Decrypt on the key) returns the cleartext, so applications and attackers read it the same way.
Listing and reading#
aws ssm describe-parameters --query 'Parameters[].Name' --output text
aws ssm get-parameter --name <name> --with-decryption \
--query Parameter.Value --output text
# recurse a path prefix, decrypting as you go
aws ssm get-parameters-by-path --path / --recursive --with-decryption \
--query 'Parameters[].[Name,Value]' --output text
Exploitation notes#
--with-decryptionneedskms:Decrypton the backing key as well as the SSM read; a denial there means you hold SSM but not the KMS grant, see KMS.- Plaintext (
String) parameters need no KMS permission at all and often still hold credentials put there carelessly. get-parameters-by-path --recursiveover/is the fastest full sweep when the naming is hierarchical.
Tools#
- AWS CLI (
ssm get-parameters-by-path --with-decryption). - Pacu (
secrets__enum): bulk extraction.