aws-penetration-testing

Fail

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: HIGHDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: Provides instructions for disabling and deleting AWS CloudTrail logs to conceal activities from security monitors.
  • [DATA_EXFILTRATION]: Describes methods to extract temporary security credentials from EC2 (IMDSv1/v2) and Fargate metadata services using SSRF techniques.
  • [REMOTE_CODE_EXECUTION]: Includes workflows for injecting malicious Python code into Lambda functions to achieve privilege escalation.
  • [REMOTE_CODE_EXECUTION]: Details how to use AWS Systems Manager (SSM) to execute arbitrary shell commands on managed EC2 instances.
  • [DATA_EXFILTRATION]: Outlines procedures for exfiltrating sensitive data from S3 buckets and mounting snapshots to extract Windows domain credentials (NTDS.dit).
  • [EXTERNAL_DOWNLOADS]: Downloads various security frameworks and tools from public repositories, such as Pacu (Rhino Security Labs), SkyArk, and ScoutSuite.
  • [COMMAND_EXECUTION]: Provides a comprehensive set of CLI commands for enumerating IAM identities, permissions, and cloud resources to identify attack surfaces.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jun 26, 2026, 07:22 PM
Security Audit — agent-trust-hub — aws-penetration-testing