AWS abuse reference
abusethe.cloud
How legitimate AWS features become abuse paths.
A practical reference for reproducing, detecting, and defending against cloud abuse techniques.
Technique index
4 entriesGlue
Glue credential beaconing through scheduled Python jobs
Using scheduled AWS Glue Python shell jobs to collect temporary job-role credentials.
S3
S3 ransomware through SSE-C self-copy
Using in-place S3 CopyObject requests to encrypt current object versions with an attacker-controlled key that AWS cannot recover.
Lambda
Self-healing IAM administrator backdoor through Lambda
Using a scheduled Lambda function to recreate an IAM administrator user and beacon each replacement access key.
Lambda
Lambda credential beaconing through scheduled functions
Using recurring Lambda invocations to collect temporary AWS credentials.
No techniques match this filter.