AWS attack techniques
abusethe.cloud
Understand cloud attacks and how to stop them.
Explore how AWS permissions and services can be misused, what evidence to look for, and which controls limit the damage.
Browse by objective
Cloud attack techniques
Credential Access
01Persistence
02Private connections after revocation
Maintain a network foothold for persistence after the environment's owner revokes the sharing permission that allowed it.
- AWS PrivateLink
- AWS Resource Access Manager
- Amazon VPC
- AWS Transit Gateway
Self-healing IAM privileges
Maintain privileged access through AWS automation that recreates an IAM user or restores its policy attachment after responders remove it.
- AWS Lambda
- Amazon EventBridge
- AWS Step Functions
- AWS Systems Manager
Exfiltration
02Passive cross-account traffic collection
Eavesdrop on workload communications by exporting packet copies or connection metadata to another account without an in-guest capture agent.
- Amazon VPC Traffic Mirroring
- AWS Gateway Load Balancer
- Amazon VPC Flow Logs
- AWS Resource Access Manager
S3 exfiltration through delegated access
Exfiltrate S3 data through an external principal authorized by delegated grants or access point policies, without a new bucket policy edit.
- Amazon S3 Access Grants
- Amazon S3 Access Points
- Amazon S3 Multi-Region Access Points
Stealth
02Service execution-role proxy
Obscure the origin of malicious API activity by running attacker-controlled code under a managed service's execution role.
- Amazon SageMaker AI
- AWS Glue
- AWS CodeBuild
SSH access through Session Manager
Evade Session Manager command recording by abusing existing Session Manager and SSH access to an EC2 instance.
- AWS Systems Manager
- Amazon EC2
Impact
02Cross-account VPC DNS hijacking
Hijack a target VPC's private DNS answers to redirect workloads or cause denial of service through DNS resources controlled by another account.
- Amazon Route 53
- Amazon Route 53 Profiles
- Amazon Route 53 Resolver
- AWS Resource Access Manager
S3 ransomware with SSE-C
Encrypt S3 objects with an attacker-held key to hold the data for ransom without downloading it.
- Amazon S3
No techniques match these filters.