pacu
Pacu is an open-source AWS exploitation framework built for penetration testers and red teamers. It provides modular tooling to enumerate, manipulate, and escalate within AWS environments by leveraging misconfigurations and overly permissive IAM policies. Imagine it like the cloud's Metasploit.
# Import an AWS profile from the get-go
pacu --import-keys iam_enum
# Import an AWS profile within pacu
Pacu (iam_enum:No Keys Set) > import_keys iam_enum
# Check user's details
Pacu (iam_enum:imported-iam_enum) > whoami
# Search for specific modules
Pacu (iam_enum:imported-iam_enum) > search iam
# Find more about the target module
Pacu (iam_enum:imported-iam_enum) > help iam__enum_users_roles_policies_groups
# List all IAM-related data found
Pacu (cybr:imported-iam_enum) > data iam
Last updated
Was this helpful?