aws-penetration-testing
Fail
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: HIGHDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: Provides instructions for disabling and deleting AWS CloudTrail logs to conceal activities from security monitors.
- [DATA_EXFILTRATION]: Describes methods to extract temporary security credentials from EC2 (IMDSv1/v2) and Fargate metadata services using SSRF techniques.
- [REMOTE_CODE_EXECUTION]: Includes workflows for injecting malicious Python code into Lambda functions to achieve privilege escalation.
- [REMOTE_CODE_EXECUTION]: Details how to use AWS Systems Manager (SSM) to execute arbitrary shell commands on managed EC2 instances.
- [DATA_EXFILTRATION]: Outlines procedures for exfiltrating sensitive data from S3 buckets and mounting snapshots to extract Windows domain credentials (NTDS.dit).
- [EXTERNAL_DOWNLOADS]: Downloads various security frameworks and tools from public repositories, such as Pacu (Rhino Security Labs), SkyArk, and ScoutSuite.
- [COMMAND_EXECUTION]: Provides a comprehensive set of CLI commands for enumerating IAM identities, permissions, and cloud resources to identify attack surfaces.
Recommendations
- AI detected serious security threats
Audit Metadata