Skip to content

AWS Pentesting

AWS is the most widespread cloud provider, and its pentest revolves around credentials and IAM permissions (see IAM Abuse and Privilege Escalation) plus specific misconfigured services. This card walks the AWS-specific flow: from getting credentials and enumerating, to exploiting the most common services (EC2, S3, Lambda, IAM) and escalating to account control.

AKIA... IAM user Access Key ID (long-lived)
ASIA... temporary Access Key (with session token) -> from roles/STS/IMDS
# configure
aws configure # interactive
export AWS_ACCESS_KEY_ID=... AWS_SECRET_ACCESS_KEY=... AWS_SESSION_TOKEN=... # temporary

Where they come from: leaked (Code Repository OSINT), stolen via SSRF→IMDS (Metadata Service (IMDS)), from buckets, or from a compromised host (~/.aws/credentials).

aws sts get-caller-identity # who am I? (ARN, Account ID)
aws iam list-users / list-roles # if permitted
enumerate-iam # what permissions I actually have
# full audit
ScoutSuite / Prowler aws # security posture of the whole account
pacu # exploitation framework (enum + exploit)
aws ec2 describe-instances # instances, IPs, security groups
aws ec2 describe-security-groups # rules (0.0.0.0/0?)
# steal the role's credentials via IMDS if SSRF/RCE (cloud-metadata)
# public or shared snapshots/AMIs -> data
aws ec2 describe-snapshots --owner-ids <id>
aws s3 ls # account's buckets
aws s3 ls s3://<bucket> # contents
# public buckets, write access, secrets inside
aws lambda list-functions # functions
aws lambda get-function --function-name X # code and environment variables (secrets!)
# PassRole: create/modify a function with an admin role -> escalation (cloud-iam, cloud-serverless)
aws secretsmanager list-secrets ; aws secretsmanager get-secret-value --secret-id X
aws ssm get-parameters-by-path --path / --recursive --with-decryption # SecureString
aws rds describe-db-instances ; public RDS snapshots
# look for escalation permissions (AttachPolicy, PassRole, CreateAccessKey...)
pacu -> iam__privesc_scan modules
# create an access key for a user (backdoor)
aws iam create-access-key --user-name victim
# new user/role with permissions; modified trust policy (AssumeRole)
# Lambda backdoor triggered by an event; modify trust policies
  • IAM least privilege + IAM Access Analyzer; no static keys (roles, IAM Identity Center).
  • IMDSv2 forced, security groups without unnecessary 0.0.0.0/0, S3 Block Public Access.
  • CloudTrail in all regions + GuardDuty (detection); Config/Security Hub (posture).
  • Secrets Manager for secrets (not in environment variables/code); KMS encryption.
  • SCPs (Organizations) to cap the maximum reach; MFA on privileged users.
  • Get and configure credentials (AKIA/ASIA)
  • sts get-caller-identity + enumerate-iam
  • ScoutSuite/Prowler for general posture
  • EC2: security groups, IMDS, public snapshots/AMIs
  • S3: public/write/secret buckets (Buckets and Public Storage)
  • Lambda: code and environment variables (secrets)
  • Secrets Manager/SSM/RDS: secrets and snapshots
  • IAM: escalation permissions → admin (IAM Abuse and Privilege Escalation)