Timestream

Timestream is AWS's time-series database, accessed entirely through IAM with no network surface. A principal holding timestream:Select queries any database and table the policy allows, which is frequently broader than intended because Timestream permissions are often granted at the service level. The data, operational and IoT telemetry, can reveal infrastructure, behaviour, and volumes useful for the wider engagement.

Querying#

bash
aws timestream-write list-databases
aws timestream-write list-tables --database-name <db>
aws timestream-query query \
  --query-string 'SELECT * FROM "db"."table" LIMIT 100'

Exploitation notes#

  • Query endpoints are discovered with timestream-query describe-endpoints; the SDK handles this, but note it when calling the API directly.
  • Service-level timestream:* grants are common and give read across every database in the account.
  • The data is append-only telemetry, so the value is intelligence rather than tampering.

Tools#

  • AWS CLI (timestream-query query, timestream-write list-databases).

References#

Cookie Consent

We use cookies to enhance your experience. Learn more