Recon / Initial Access / Enum

AWS - Initial Recon

ko-fi

Recon - AWS Eye

Found an account ID:

AWS Extender - Burp Extension

Credz in git repos

Credentials in git repos

Credz on Host - Hardcoded Secrets

Spray AWS Console IAM Logins

IAM User enumeration

Or see IAM part

GoAWSConsoleSpray

To get the ACCOUNTID , run aws sts get-caller-identity with a known account

AWeSomeUserFinder

Subdomain Takeover

AWS Elastic Beanstalk

DNS (53)

CloudTap

AWS Enumerator

Credentials found

Cloudfox

Security Groups - Segmentation

AWS Attack Path Management Tool

Authenticated Recon

ScoutSuite

Prowler

White Box Recon

You must have the following privileges (these grant various read access of metadata):

  • arn:aws:iam::aws:policy/SecurityAudit

  • arn:aws:iam::aws:policy/job-function/ViewOnlyAccess

Interesting Book

Interesting Books

Disclaimer: As an Amazon Associate, I earn from qualifying purchases. This helps support this GitBook project at no extra cost to you.

Last updated