AWS Pentesting
AWS is the most widespread cloud provider, and its pentest revolves around credentials and IAM permissions (see IAM Abuse and Privilege Escalation) plus specific misconfigured services. This card walks the AWS-specific flow: from getting credentials and enumerating, to exploiting the most common services (EC2, S3, Lambda, IAM) and escalating to account control.
AWS credentials (formats)
Section titled “AWS credentials (formats)”AKIA... IAM user Access Key ID (long-lived)ASIA... temporary Access Key (with session token) -> from roles/STS/IMDS# configureaws configure # interactiveexport AWS_ACCESS_KEY_ID=... AWS_SECRET_ACCESS_KEY=... AWS_SESSION_TOKEN=... # temporaryWhere they come from: leaked (Code Repository OSINT), stolen via SSRF→IMDS (Metadata Service (IMDS)), from buckets, or from a compromised host (~/.aws/credentials).
Initial enumeration
Section titled “Initial enumeration”aws sts get-caller-identity # who am I? (ARN, Account ID)aws iam list-users / list-roles # if permittedenumerate-iam # what permissions I actually have# full auditScoutSuite / Prowler aws # security posture of the whole accountpacu # exploitation framework (enum + exploit)Key services and their attack
Section titled “Key services and their attack”aws ec2 describe-instances # instances, IPs, security groupsaws ec2 describe-security-groups # rules (0.0.0.0/0?)# steal the role's credentials via IMDS if SSRF/RCE (cloud-metadata)# public or shared snapshots/AMIs -> dataaws ec2 describe-snapshots --owner-ids <id>aws s3 ls # account's bucketsaws s3 ls s3://<bucket> # contents# public buckets, write access, secrets insideLambda
Section titled “Lambda”aws lambda list-functions # functionsaws lambda get-function --function-name X # code and environment variables (secrets!)# PassRole: create/modify a function with an admin role -> escalation (cloud-iam, cloud-serverless)Secrets Manager / SSM / RDS
Section titled “Secrets Manager / SSM / RDS”aws secretsmanager list-secrets ; aws secretsmanager get-secret-value --secret-id Xaws ssm get-parameters-by-path --path / --recursive --with-decryption # SecureStringaws rds describe-db-instances ; public RDS snapshotsIAM (escalation, see IAM Abuse and Privilege Escalation)
Section titled “IAM (escalation, see IAM Abuse and Privilege Escalation)”# look for escalation permissions (AttachPolicy, PassRole, CreateAccessKey...)pacu -> iam__privesc_scan modulesPersistence in AWS
Section titled “Persistence in AWS”# create an access key for a user (backdoor)aws iam create-access-key --user-name victim# new user/role with permissions; modified trust policy (AssumeRole)# Lambda backdoor triggered by an event; modify trust policiesFor the defense
Section titled “For the defense”- IAM least privilege + IAM Access Analyzer; no static keys (roles, IAM Identity Center).
- IMDSv2 forced, security groups without unnecessary
0.0.0.0/0, S3 Block Public Access. - CloudTrail in all regions + GuardDuty (detection); Config/Security Hub (posture).
- Secrets Manager for secrets (not in environment variables/code); KMS encryption.
- SCPs (Organizations) to cap the maximum reach; MFA on privileged users.
Testing checklist
Section titled “Testing checklist”- Get and configure credentials (AKIA/ASIA)
-
sts get-caller-identity+ enumerate-iam - ScoutSuite/Prowler for general posture
- EC2: security groups, IMDS, public snapshots/AMIs
- S3: public/write/secret buckets (Buckets and Public Storage)
- Lambda: code and environment variables (secrets)
- Secrets Manager/SSM/RDS: secrets and snapshots
- IAM: escalation permissions → admin (IAM Abuse and Privilege Escalation)