Every escalation and pivot in AWS starts from one question: what can the principal I hold actually do, and what can it reach. IAM answers are not local, so enumeration is a set of API calls against the IAM service and a graph analysis on the result.
Who am I#
aws sts get-caller-identity # account id, principal ARN, user vs assumed-role
aws iam get-user # if a user; fails for role sessions
Reading the IAM graph#
With iam:List*/iam:Get*, pull the whole policy picture:
aws iam list-users ; aws iam list-roles ; aws iam list-groups
aws iam list-attached-user-policies --user-name <u>
aws iam get-account-authorization-details > iam.json # the whole graph in one call
get-account-authorization-details is the prize: every principal, inline and attached policy, and trust document in a single response, which is exactly what graph tools consume.
Resolving effective permissions without read rights#
Permissions are often not readable even when they are usable. Two approaches:
# Brute the API surface with harmless calls and record what is allowed
enumerate-iam --access-key AKIA... --secret-key ...
# Pacu's permission enumeration and privesc scan
pacu > run iam__enum_permissions ; run iam__privesc_scan
# where your own policies are readable, confirm what they grant without calling the actions
aws iam simulate-principal-policy --policy-source-arn <your-arn> \
--action-names iam:CreateAccessKey sts:AssumeRole s3:GetObject
Graphing paths to admin#
# PMapper: build the graph, then query for escalation paths
pmapper graph create
pmapper query 'preset privesc *'
pmapper visualize
Exploitation notes#
- Prefer
get-account-authorization-detailsfirst; it collapses dozens of calls and feeds PMapper directly. - A denied
iam:Get*does not mean the action is denied: useenumerate-iamto learn the usable surface by probing. - Role sessions have no user; pivot your identity questions to the assumed-role ARN and its session policies.
Tools#
- Pacu (
iam__enum_permissions,iam__privesc_scan): session-based enumeration and privesc detection. - PMapper: IAM graph construction and path queries to administrator.
- CloudFox: fast attacker-focused inventory of principals, roles, secrets, and reachable resources.
- Cloudsplaining: IAM policy analysis for privilege-escalation and resource-exposure findings.
- enumerate-iam: probe-based discovery of the allowed API surface.
- ScoutSuite / Prowler: account-wide posture and principal inventory.
- weirdAAL / SkyArk: unauthenticated-to-low-privilege API discovery and shadow-admin hunting.