AWS Network Firewall inspects VPC traffic against stateless and stateful rule groups bound to a firewall policy. Reading those rules shows exactly what is filtered and what is not, so you can route exfiltration or command-and-control through an allowed destination; write access lets you weaken the policy or drop inspection entirely.
Enumerating rules and policy#
aws network-firewall list-firewalls
aws network-firewall describe-firewall --firewall-name <name>
aws network-firewall describe-firewall-policy --firewall-policy-name <policy>
aws network-firewall describe-rule-group --rule-group-name <rg> --type STATEFUL
Exploitation notes#
- The default action for uninspected traffic and any allow-listed FQDNs or CIDRs are the gaps: send exfiltration to an allowed destination rather than fighting the rules.
- A stateful rule group evaluated in the wrong order, or a missing TLS SNI rule, lets traffic through that the operator believes is blocked.
- With write access, disassociating a rule group or setting the policy default to allow removes inspection without deleting the firewall, which looks benign in an inventory.
Tools#
- AWS CLI (
network-firewall describe-*): rule-group and policy disclosure. - ScoutSuite / Prowler: inventory firewalls and default actions.