Storage is where the data lives, so it is the usual objective once a principal is held. AWS storage breaks into object storage (S3), block storage (EBS, exposed through its snapshots), shared file systems (EFS, FSx), the backup plane (AWS Backup), and the hybrid bridge (Storage Gateway). Most storage compromise is not an exploit but a permission or exposure problem: a world-readable bucket, a snapshot shared to all accounts, a mount target reachable from a subnet you control.
What folds in here#
- S3: bucket and object discovery, public access, and bucket-policy and ACL abuse.
- EBS snapshots: public or shared block-storage snapshots restored to read their volumes.
- EFS: exposed NFS file systems mounted through permissive security groups or file-system policy.
- Backup: recovery points read and restored out of AWS Backup vaults.
- FSx: Windows, Lustre, and NetApp file systems reached through share permissions.
- Storage Gateway: file shares and cached volumes bridging on-premises access to S3 and EBS.
Enumeration is folded into each page: finding the resource is the first half of reaching its data.