Offensive AWS Security
Offensive AWS Security
Identify assets & define AWS boundaries WeirdAAL AWS Attack Library
Identify, review & evaluate risks Governance A simple file-based scanner to look for
potential AWS access and secret keys in
Documentation and Inventory Cred Scanner files
• Analyze code and configuration for Cloud Container Attack Tool (CCAT) is a
sensitive information disclosure tool for testing security of container
CCAT environments
https://www.linkedin.com/in/joas-
• Privilege Escalation through Lambda IAM
Roles and SDK’s Lambda antonio-dos-santos Dufflebag Search exposed EBS volumes for secrets