aws-enumeration.md (6260B)
1 --- 2 title: "AWS - Enumerate" 3 section: "Cloud" 4 sectionSlug: "cloud" 5 sourcePath: "docs/cloud/aws/aws-enumeration.md" 6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/aws/aws-enumeration.md" 7 sha: "203bb0c0b290" 8 isIndex: false 9 --- 10 11 # AWS - Enumerate 12 13 ## Collectors 14 15 * [nccgroup/ScoutSuite](https://github.com/nccgroup/ScoutSuite/wiki) - Multi-Cloud Security Auditing Tool 16 17 ```powershell 18 $ python scout.py PROVIDER --help 19 # The --session-token is optional and only used for temporary credentials (i.e. role assumption). 20 $ python scout.py aws --access-keys --access-key-id <AKIAIOSFODNN7EXAMPLE> --secret-access-key <wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY> --session-token <token> 21 $ python scout.py azure --cli 22 ``` 23 24 * [RhinoSecurityLabs/pacu](https://github.com/RhinoSecurityLabs/pacu) - Exploit configuration flaws within an AWS environment using an extensible collection of modules with a diverse feature-set 25 26 ```powershell 27 $ bash install.sh 28 $ python3 pacu.py 29 set_keys/swap_keys 30 run <module_name> [--keyword-arguments] 31 run <module_name> --regions eu-west-1,us-west-1 32 ``` 33 34 * [salesforce/cloudsplaining](https://github.com/salesforce/cloudsplaining) - An AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report 35 36 ```powershell 37 pip3 install --user cloudsplaining 38 cloudsplaining download --profile myawsprofile 39 cloudsplaining scan --input-file default.json 40 ``` 41 42 * [duo-labs/cloudmapper](https://github.com/duo-labs/cloudmapper) - CloudMapper helps you analyze your Amazon Web Services (AWS) environments 43 44 ```powershell 45 sudo apt-get install autoconf automake libtool python3.7-dev python3-tk jq awscli build-essential 46 pipenv install --skip-lock 47 pipenv shell 48 report: Generate HTML report. Includes summary of the accounts and audit findings. 49 iam_report: Generate HTML report for the IAM information of an account. 50 audit: Check for potential misconfigurations. 51 collect: Collect metadata about an account. 52 find_admins: Look at IAM policies to identify admin users and roles, or principals with specific privileges 53 ``` 54 55 * [cyberark/SkyArk](https://github.com/cyberark/SkyArk) - Discover the most privileged users in the scanned AWS environment, including the AWS Shadow Admins 56 57 ```powershell 58 $ powershell -ExecutionPolicy Bypass -NoProfile 59 PS C> Import-Module .\SkyArk.ps1 -force 60 PS C> Start-AWStealth 61 PS C> Scan-AWShadowAdmins 62 ``` 63 64 * [BishopFox/CloudFox](https://github.com/BishopFox/CloudFox/) - Automating situational awareness for cloud penetration tests. Designed for white box enumeration (SecurityAudit/ReadOnly type permission), but can be used for black box (found credentials) as well. 65 66 ```ps1 67 cloudfox aws --profile [profile-name] all-checks 68 ``` 69 70 * [toniblyx/Prowler](https://github.com/toniblyx/prowler) - AWS security best practices assessments, audits, incident response, continuous monitoring, hardening and forensics readiness. It follows guidelines of the CIS Amazon Web Services Foundations Benchmark and DOZENS of additional checks including GDPR and HIPAA (+100). 71 72 ```powershell 73 pip install awscli ansi2html detect-secrets 74 sudo apt install jq 75 ./prowler -E check42,check43 76 ./prowler -p custom-profile -r us-east-1 -c check11 77 ./prowler -A 123456789012 -R ProwlerRole 78 ``` 79 80 * [nccgroup/PMapper](https://github.com/nccgroup/PMapper) - A tool for quickly evaluating IAM permissions in AWS 81 82 ```powershell 83 pip install principalmapper 84 pmapper graph --create 85 pmapper visualize --filetype png 86 pmapper analysis --output-type text 87 88 # Determine if PowerUser can escalate privileges 89 pmapper query "preset privesc user/PowerUser" 90 pmapper argquery --principal user/PowerUser --preset privesc 91 92 # Find all principals that can escalate privileges 93 pmapper query "preset privesc *" 94 pmapper argquery --principal '*' --preset privesc 95 96 # Find all principals that PowerUser can access 97 pmapper query "preset connected user/PowerUser *" 98 pmapper argquery --principal user/PowerUser --resource '*' --preset connected 99 100 # Find all principals that can access PowerUser 101 pmapper query "preset connected * user/PowerUser" 102 pmapper argquery --principal '*' --resource user/PowerUser --preset connected 103 ``` 104 105 ## AWS - Enumerate IAM permissions 106 107 Enumerate the permissions associated with AWS credential set with [andresriancho/enumerate-iam](https://github.com/andresriancho/enumerate-iam) 108 109 ```powershell 110 git clone git@github.com:andresriancho/enumerate-iam.git 111 pip install -r requirements.txt 112 ./enumerate-iam.py --access-key AKIA... --secret-key StF0q... 113 2019-05-10 15:57:58,447 - 21345 - [INFO] Starting permission enumeration for access-key-id "AKIA..." 114 2019-05-10 15:58:01,532 - 21345 - [INFO] Run for the hills, get_account_authorization_details worked! 115 2019-05-10 15:58:01,537 - 21345 - [INFO] -- { 116 "RoleDetailList": [ 117 { 118 "Tags": [], 119 "AssumeRolePolicyDocument": { 120 "Version": "2008-10-17", 121 "Statement": [ 122 { 123 ... 124 2019-05-10 15:58:26,709 - 21345 - [INFO] -- gamelift.list_builds() worked! 125 2019-05-10 15:58:26,850 - 21345 - [INFO] -- cloudformation.list_stack_sets() worked! 126 2019-05-10 15:58:26,982 - 21345 - [INFO] -- directconnect.describe_locations() worked! 127 2019-05-10 15:58:27,021 - 21345 - [INFO] -- gamelift.describe_matchmaking_rule_sets() worked! 128 2019-05-10 15:58:27,311 - 21345 - [INFO] -- sqs.list_queues() worked! 129 ``` 130 131 ## References 132 133 * [An introduction to penetration testing AWS - Akimbocore - HollyGraceful - 06 August 2021](https://akimbocore.com/article/introduction-to-penetration-testing-aws/) 134 * [AWS CLI Cheatsheet - apolloclark](https://gist.github.com/apolloclark/b3f60c1f68aa972d324b) 135 * [AWS - Cheatsheet - @Magnussen](https://www.magnussen.funcmylife.fr/article_35) 136 * [Pacu Open source AWS Exploitation framework - RhinoSecurityLabs](https://rhinosecuritylabs.com/aws/pacu-open-source-aws-exploitation-framework/) 137 * [PACU Spencer Gietzen - 30 juil. 2018](https://youtu.be/XfetW1Vqybw?list=PLBID4NiuWSmfdWCmYGDQtlPABFHN7HyD5)