daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

aws-enumeration.md (6260B)


      1 ---
      2 title: "AWS - Enumerate"
      3 section: "Cloud"
      4 sectionSlug: "cloud"
      5 sourcePath: "docs/cloud/aws/aws-enumeration.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/aws/aws-enumeration.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # AWS - Enumerate
     12 
     13 ## Collectors
     14 
     15 * [nccgroup/ScoutSuite](https://github.com/nccgroup/ScoutSuite/wiki) - Multi-Cloud Security Auditing Tool
     16 
     17     ```powershell
     18     $ python scout.py PROVIDER --help
     19     # The --session-token is optional and only used for temporary credentials (i.e. role assumption).
     20     $ python scout.py aws --access-keys --access-key-id <AKIAIOSFODNN7EXAMPLE> --secret-access-key <wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEY> --session-token <token>
     21     $ python scout.py azure --cli
     22     ```
     23 
     24 * [RhinoSecurityLabs/pacu](https://github.com/RhinoSecurityLabs/pacu) - Exploit configuration flaws within an AWS environment using an extensible collection of modules with a diverse feature-set
     25 
     26     ```powershell
     27     $ bash install.sh
     28     $ python3 pacu.py
     29     set_keys/swap_keys
     30     run <module_name> [--keyword-arguments]
     31     run <module_name> --regions eu-west-1,us-west-1
     32     ```
     33 
     34 * [salesforce/cloudsplaining](https://github.com/salesforce/cloudsplaining) - An AWS IAM Security Assessment tool that identifies violations of least privilege and generates a risk-prioritized report
     35 
     36     ```powershell
     37     pip3 install --user cloudsplaining
     38     cloudsplaining download --profile myawsprofile
     39     cloudsplaining scan --input-file default.json
     40     ```
     41 
     42 * [duo-labs/cloudmapper](https://github.com/duo-labs/cloudmapper) - CloudMapper helps you analyze your Amazon Web Services (AWS) environments
     43 
     44     ```powershell
     45     sudo apt-get install autoconf automake libtool python3.7-dev python3-tk jq awscli build-essential
     46     pipenv install --skip-lock
     47     pipenv shell
     48     report: Generate HTML report. Includes summary of the accounts and audit findings.
     49     iam_report: Generate HTML report for the IAM information of an account.
     50     audit: Check for potential misconfigurations.
     51     collect: Collect metadata about an account.
     52     find_admins: Look at IAM policies to identify admin users and roles, or principals with specific privileges
     53     ```
     54 
     55 * [cyberark/SkyArk](https://github.com/cyberark/SkyArk) - Discover the most privileged users in the scanned AWS environment, including the AWS Shadow Admins
     56 
     57     ```powershell
     58     $ powershell -ExecutionPolicy Bypass -NoProfile
     59     PS C> Import-Module .\SkyArk.ps1 -force
     60     PS C> Start-AWStealth
     61     PS C> Scan-AWShadowAdmins  
     62     ```
     63 
     64 * [BishopFox/CloudFox](https://github.com/BishopFox/CloudFox/) - Automating situational awareness for cloud penetration tests. Designed for white box enumeration (SecurityAudit/ReadOnly type permission), but can be used for black box (found credentials) as well.
     65 
     66     ```ps1
     67     cloudfox aws --profile [profile-name] all-checks
     68     ```
     69 
     70 * [toniblyx/Prowler](https://github.com/toniblyx/prowler) - AWS security best practices assessments, audits, incident response, continuous monitoring, hardening and forensics readiness. It follows guidelines of the CIS Amazon Web Services Foundations Benchmark and DOZENS of additional checks including GDPR and HIPAA (+100).
     71 
     72     ```powershell
     73     pip install awscli ansi2html detect-secrets
     74     sudo apt install jq
     75     ./prowler -E check42,check43
     76     ./prowler -p custom-profile -r us-east-1 -c check11
     77     ./prowler -A 123456789012 -R ProwlerRole
     78     ```
     79 
     80 * [nccgroup/PMapper](https://github.com/nccgroup/PMapper) - A tool for quickly evaluating IAM permissions in AWS
     81 
     82     ```powershell
     83     pip install principalmapper
     84     pmapper graph --create
     85     pmapper visualize --filetype png
     86     pmapper analysis --output-type text
     87 
     88     # Determine if PowerUser can escalate privileges
     89     pmapper query "preset privesc user/PowerUser"
     90     pmapper argquery --principal user/PowerUser --preset privesc
     91 
     92     # Find all principals that can escalate privileges
     93     pmapper query "preset privesc *"
     94     pmapper argquery --principal '*' --preset privesc
     95 
     96     # Find all principals that PowerUser can access
     97     pmapper query "preset connected user/PowerUser *"
     98     pmapper argquery --principal user/PowerUser --resource '*' --preset connected
     99 
    100     # Find all principals that can access PowerUser
    101     pmapper query "preset connected * user/PowerUser"
    102     pmapper argquery --principal '*' --resource user/PowerUser --preset connected
    103     ```
    104 
    105 ## AWS - Enumerate IAM permissions
    106 
    107 Enumerate the permissions associated with AWS credential set with [andresriancho/enumerate-iam](https://github.com/andresriancho/enumerate-iam)
    108 
    109 ```powershell
    110 git clone git@github.com:andresriancho/enumerate-iam.git
    111 pip install -r requirements.txt
    112 ./enumerate-iam.py --access-key AKIA... --secret-key StF0q...
    113 2019-05-10 15:57:58,447 - 21345 - [INFO] Starting permission enumeration for access-key-id "AKIA..."
    114 2019-05-10 15:58:01,532 - 21345 - [INFO] Run for the hills, get_account_authorization_details worked!
    115 2019-05-10 15:58:01,537 - 21345 - [INFO] -- {
    116     "RoleDetailList": [
    117         {
    118             "Tags": [],
    119             "AssumeRolePolicyDocument": {
    120                 "Version": "2008-10-17",
    121                 "Statement": [
    122                     {
    123 ...
    124 2019-05-10 15:58:26,709 - 21345 - [INFO] -- gamelift.list_builds() worked!
    125 2019-05-10 15:58:26,850 - 21345 - [INFO] -- cloudformation.list_stack_sets() worked!
    126 2019-05-10 15:58:26,982 - 21345 - [INFO] -- directconnect.describe_locations() worked!
    127 2019-05-10 15:58:27,021 - 21345 - [INFO] -- gamelift.describe_matchmaking_rule_sets() worked!
    128 2019-05-10 15:58:27,311 - 21345 - [INFO] -- sqs.list_queues() worked!
    129 ```
    130 
    131 ## References
    132 
    133 * [An introduction to penetration testing AWS - Akimbocore - HollyGraceful - 06 August 2021](https://akimbocore.com/article/introduction-to-penetration-testing-aws/)
    134 * [AWS CLI Cheatsheet - apolloclark](https://gist.github.com/apolloclark/b3f60c1f68aa972d324b)
    135 * [AWS - Cheatsheet - @Magnussen](https://www.magnussen.funcmylife.fr/article_35)
    136 * [Pacu Open source AWS Exploitation framework - RhinoSecurityLabs](https://rhinosecuritylabs.com/aws/pacu-open-source-aws-exploitation-framework/)
    137 * [PACU Spencer Gietzen - 30 juil. 2018](https://youtu.be/XfetW1Vqybw?list=PLBID4NiuWSmfdWCmYGDQtlPABFHN7HyD5)